<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=therapy+children%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 13:17:27 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 13:17:27 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=therapy+children%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=therapy+children%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Children and chatbots: What parents should know]]></title>
<description><![CDATA[As children turn to AI chatbots for answers, advice, and companionship, questions emerge about their safety, privacy, and emotional development]]></description>
<link>https://tsecurity.de/de/3694656/malware-trojaner-viren/children-and-chatbots-what-parents-should-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694656/malware-trojaner-viren/children-and-chatbots-what-parents-should-know/</guid>
<pubDate>Sat, 25 Jul 2026 19:04:42 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As children turn to AI chatbots for answers, advice, and companionship, questions emerge about their safety, privacy, and emotional development]]></content:encoded>
</item>
<item>
<title><![CDATA[Lessons for life: Why children’s data is a long-term identity risk]]></title>
<description><![CDATA[Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.]]></description>
<link>https://tsecurity.de/de/3694646/malware-trojaner-viren/lessons-for-life-why-childrens-data-is-a-long-term-identity-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694646/malware-trojaner-viren/lessons-for-life-why-childrens-data-is-a-long-term-identity-risk/</guid>
<pubDate>Sat, 25 Jul 2026 19:04:33 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.]]></content:encoded>
</item>
<item>
<title><![CDATA[Agent Kim Reactivated Finale Preview: Will Agent Kim Fight His Closest Friends?]]></title>
<description><![CDATA[Agent Kim Reactivated Episode 10 will place Manager Kim and his closest allies inside their most personal and dangerous battle yet. With their children being used as hostages, the three fathers must find a way to defeat Ju Gang-chan without turning against each other.




Release date: July 25, 2...]]></description>
<link>https://tsecurity.de/de/3693923/ios-mac-os/agent-kim-reactivated-finale-preview-will-agent-kim-fight-his-closest-friends/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693923/ios-mac-os/agent-kim-reactivated-finale-preview-will-agent-kim-fight-his-closest-friends/</guid>
<pubDate>Sat, 25 Jul 2026 14:45:18 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Episode 10 will place Manager Kim and his closest allies inside their most personal and dangerous battle yet. With their children being used as hostages, the three fathers must find a way to defeat Ju Gang-chan without turning against each other.




Release date: July 25, 2026



Release time: 9:45 p.m. KST on SBS




Spoiler warning for Episode 9



Episode 9 followed Manager Kim, Seong Han-su and Park Jin-cheol as they entered another heavily guarded location and fought through Gang-chan’s men. Han-su and Jin-cheol handled several attackers together, while Manager Kim used his old operational skills to clear the remaining guards.



However, Gang-chan had already prepared a cruel backup plan. He arranged the kidnapping of Han-su and Jin-cheol’s children, giving him complete control over the fathers before the final confrontation.



The story began with Manager Kim leaving his secret past behind and raising his daughter Min-ji as an ordinary single father. Her disappearance forced him to reactivate his black-ops skills and reconnect with former operatives Han-su and Jin-cheol. Since then, each man’s family has become connected to Manager Kim’s unfinished conflicts.



Will the three agents fight each other?



The Episode 10 preview suggests that Gang-chan will force the three men into a cage and demand that Han-su and Jin-cheol kill Manager Kim. Their children’s survival appears to depend on whether they follow his instructions.



This creates a painful choice for both fathers. Manager Kim previously risked everything to protect their families, but Han-su and Jin-cheol cannot ignore an immediate threat against their children.



Still, the three agents know each other’s abilities well. Their apparent conflict could become part of a plan to distract Gang-chan, escape the cage and reach the hostages before his men can act.



Will all the families survive?



The finale’s official description says the three men become enemies while trying to protect the people they love. This confirms that every family will remain in danger until the final moments.



Manager Kim will likely take the greatest risk because he understands Gang-chan’s methods and refuses to let another child suffer because of his past. Min-ji could also play an important role, especially after repeatedly showing courage during earlier threats.



Episode 10 should end the conflict between Manager Kim and Gang-chan while revealing whether the three fathers can save every hostage. Do you think all the agent families will survive the finale? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Agent Kim Reactivated’ Episode 10 Finale Release Date and What to Expect]]></title>
<description><![CDATA[Agent Kim Reactivated Episode 10 will release on Saturday, July 25, 2026, bringing the Korean action drama’s first season to an end. The finale will air on SBS in South Korea before becoming available to international viewers on Netflix.



The final episode will begin at 9:45 p.m. KST, which is ...]]></description>
<link>https://tsecurity.de/de/3693855/ios-mac-os/agent-kim-reactivated-episode-10-finale-release-date-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693855/ios-mac-os/agent-kim-reactivated-episode-10-finale-release-date-and-what-to-expect/</guid>
<pubDate>Sat, 25 Jul 2026 13:19:44 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Episode 10 will release on Saturday, July 25, 2026, bringing the Korean action drama’s first season to an end. The finale will air on SBS in South Korea before becoming available to international viewers on Netflix.



The final episode will begin at 9:45 p.m. KST, which is five minutes earlier than the show’s usual 9:50 p.m. slot. SBS has also confirmed that Episode 10 will have a slightly extended runtime, giving the series more time to resolve its remaining conflicts.



Agent Kim Reactivated Episode 10 release details




Episode: 10



Release date: Saturday, July 25, 2026



SBS broadcast time: 9:45 p.m. KST



Streaming platform: Netflix



Total episodes: 10



Genre: Action, crime, comedy and thriller




Netflix normally adds new episodes after their Korean television broadcast, although the exact arrival time can differ by country.



Where is the story heading in the finale?



Spoilers for Episode 9 follow.



Episode 9 placed Manager Kim and his allies in the middle of a dangerous extraction operation. Kim attempted to rescue Ri Eung-ryeong from North Korean agents while Han-su, Jin-cheol and Sang-a helped him enter a heavily guarded hotel.



The operation quickly fell apart after communications were cut and the building lost power. Kim and Ri Eung-ryeong were surrounded by armed agents near the loading area, leaving their escape uncertain.



Meanwhile, Ju Gang-chan’s assistant kidnapped the children of Han-su and Jin-cheol. The episode ended with both fathers learning that their families were being used against them, setting up another personal rescue mission for the finale.



Episode 10 should therefore focus on Kim escaping the hotel, protecting Min-ji and helping his friends save their children. The finale must also settle Ju Gang-chan’s fate and reveal whether Kim can finally leave his violent past behind.



How did Agent Kim’s story begin?



The series started with Kim living quietly as an office worker and raising his teenage daughter, Min-ji, after his wife’s death. His ordinary life collapsed when Min-ji disappeared, forcing him to reveal the black-ops abilities he had kept hidden for years.



As Kim searched for his daughter, the mission exposed old enemies, secret government operations and unresolved connections to North Korea. His former life gradually placed everyone around him in danger.



Agent Kim Reactivated Episode 10 now has several major storylines to complete during its extended finale. Do you expect Manager Kim and Min-ji to receive a happy ending? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Colorado Names First Principal Director of AI Architecture]]></title>
<description><![CDATA[Jane Yang has joined the state Office of Information Technology in the newly created role. She was previously chief AI officer for the U.S. Administration for Children and Families.]]></description>
<link>https://tsecurity.de/de/3692646/ai-nachrichten/colorado-names-first-principal-director-of-ai-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692646/ai-nachrichten/colorado-names-first-principal-director-of-ai-architecture/</guid>
<pubDate>Sat, 25 Jul 2026 00:03:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jane Yang has joined the state Office of Information Technology in the newly created role. She was previously chief AI officer for the U.S. Administration for Children and Families.]]></content:encoded>
</item>
<item>
<title><![CDATA[It's Been A REALLY Long Time!!!]]></title>
<description><![CDATA[Author: Tech Talk America - Bewertung: 13x - Views:101 It has now been over 700 days since my last YouTube video so I thought I'd take a moment to share a few life updates and just generally check-in with you guys. 

With Gardyn, you can grow fresh, healthy food at home all year round. Plus, enjo...]]></description>
<link>https://tsecurity.de/de/3692276/ios-mac-os/its-been-a-really-long-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692276/ios-mac-os/its-been-a-really-long-time/</guid>
<pubDate>Fri, 24 Jul 2026 20:20:33 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Tech Talk America - Bewertung: 13x - Views:101 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yieHFRQmXs8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>It has now been over 700 days since my last YouTube video so I thought I'd take a moment to share a few life updates and just generally check-in with you guys. <br />
<br />
With Gardyn, you can grow fresh, healthy food at home all year round. Plus, enjoy $100 off your Gardyn when you click the link below! 🌿 https://bit.ly/4fRyQsa<br />
<br />
👉 BOOK A TECH THERAPY SESSION WITH DAVID https://techtalkamerica.com/techtherapy 👈<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU warns TikTok on child safety defaults]]></title>
<description><![CDATA[The European Commission has issued preliminary findings against TikTok under the Digital Services Act, identifying significant gaps in how the platform protects children. This article has been indexed from CyberMaterial Read the original article: EU warns TikTok on child safety…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3691705/it-security-nachrichten/eu-warns-tiktok-on-child-safety-defaults/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691705/it-security-nachrichten/eu-warns-tiktok-on-child-safety-defaults/</guid>
<pubDate>Fri, 24 Jul 2026 15:39:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The European Commission has issued preliminary findings against TikTok under the Digital Services Act, identifying significant gaps in how the platform protects children. This article has been indexed from CyberMaterial Read the original article: EU warns TikTok on child safety…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/eu-warns-tiktok-on-child-safety-defaults/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/eu-warns-tiktok-on-child-safety-defaults/">EU warns TikTok on child safety defaults</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TikTok’s protection of minors should not be opt-in, warns EU]]></title>
<description><![CDATA[TikTok has attracted the ire of the European Union over its protection of children who use the video sharing platform. The European Commission announced preliminary findings today under the Digital Services Act (DSA) that offer specific issues to address. The Commission suggests that TikTok shoul...]]></description>
<link>https://tsecurity.de/de/3691456/it-nachrichten/tiktoks-protection-of-minors-should-not-be-opt-in-warns-eu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691456/it-nachrichten/tiktoks-protection-of-minors-should-not-be-opt-in-warns-eu/</guid>
<pubDate>Fri, 24 Jul 2026 14:04:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[TikTok has attracted the ire of the European Union over its protection of children who use the video sharing platform. The European Commission announced preliminary findings today under the Digital Services Act (DSA) that offer specific issues to address. The Commission suggests that TikTok should adjust the default settings of minors' "public" accounts so the […]]]></content:encoded>
</item>
<item>
<title><![CDATA[BioLife Solutions to be acquired by Repligen in $1.5B cell therapy deal]]></title>
<description><![CDATA[BioLife Solutions, a Bothell, Wash.-based company developing tools for cell and gene therapy, is being acquired for $1.5 billion by the life sciences corporation Repligen.  Read More]]></description>
<link>https://tsecurity.de/de/3689757/it-nachrichten/biolife-solutions-to-be-acquired-by-repligen-in-15b-cell-therapy-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689757/it-nachrichten/biolife-solutions-to-be-acquired-by-repligen-in-15b-cell-therapy-deal/</guid>
<pubDate>Thu, 23 Jul 2026 18:53:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img fetchpriority="high" loading="eager" width="500" height="400" src="https://cdn.geekwire.com/wp-content/uploads/2026/07/Profile-Rod-de-Greef.webp" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/07/Profile-Rod-de-Greef.webp 500w, https://cdn.geekwire.com/wp-content/uploads/2026/07/Profile-Rod-de-Greef-300x240.webp 300w, https://cdn.geekwire.com/wp-content/uploads/2026/07/Profile-Rod-de-Greef-200x160.webp 200w, https://cdn.geekwire.com/wp-content/uploads/2026/07/Profile-Rod-de-Greef-125x100.webp 125w" sizes="(max-width: 500px) 100vw, 500px"><br>BioLife Solutions, a Bothell, Wash.-based company developing tools for cell and gene therapy, is being acquired for $1.5 billion by the life sciences corporation Repligen.  <a href="https://www.geekwire.com/2026/biolife-solutions-to-be-acquired-by-repligen-in-1-5b-cell-therapy-deal/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: digital education for everyone]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:3 Kaspersky explains why different vulnerable groups need different approaches to digital education — from children to elderly people, from non-profit organizations to people with disabilities. Watch to see how we build confidence and resilience in a rapi...]]></description>
<link>https://tsecurity.de/de/3689341/malware-trojaner-viren/kasperskys-sustainability-report-2024-2025-digital-education-for-everyone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689341/malware-trojaner-viren/kasperskys-sustainability-report-2024-2025-digital-education-for-everyone/</guid>
<pubDate>Thu, 23 Jul 2026 16:20:47 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Gihx6_apVPA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Kaspersky explains why different vulnerable groups need different approaches to digital education — from children to elderly people, from non-profit organizations to people with disabilities. Watch to see how we build confidence and resilience in a rapidly changing digital world.<br />
<br />
Find more details in the report: https://kas.pr/7jar<br />
<br />
#kaspersky #esg #sustainability #cybersecurity #inclusion<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Banning Social Media for Kids Is a Bad Idea]]></title>
<description><![CDATA[The risks are real. But banning children from the internet could create new problems without solving the ones that really matter.]]></description>
<link>https://tsecurity.de/de/3688630/it-nachrichten/banning-social-media-for-kids-is-a-bad-idea/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688630/it-nachrichten/banning-social-media-for-kids-is-a-bad-idea/</guid>
<pubDate>Thu, 23 Jul 2026 12:04:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The risks are real. But banning children from the internet could create new problems without solving the ones that really matter.]]></content:encoded>
</item>
<item>
<title><![CDATA[India Tightens Social Media Rules to Protect Children Online]]></title>
<description><![CDATA[India online safety rules are being strengthened as the government steps up measures to protect children and other users from harmful digital content, cyber risks and emerging threats linked to artificial intelligence. The government said its policies are aimed at ensuring an open, safe, trusted ...]]></description>
<link>https://tsecurity.de/de/3688433/it-security-nachrichten/india-tightens-social-media-rules-to-protect-children-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688433/it-security-nachrichten/india-tightens-social-media-rules-to-protect-children-online/</guid>
<pubDate>Thu, 23 Jul 2026 10:56:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="India online safety rules" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules.webp 1536w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules.webp 1536w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/India-online-safety-rules-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="India Tightens Social Media Rules to Protect Children Online 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="257" data-end="713">India online safety rules are being strengthened as the government steps up measures to protect children and other users from harmful digital content, cyber risks and emerging threats linked to <a href="https://thecyberexpress.com/?s=artificial+intelligence" target="_blank" rel="noopener">artificial intelligence</a>. The government said its policies are aimed at ensuring an open, safe, trusted and accountable internet, with recent measures focusing on child safety, privacy protection, faster content removal and stronger platform responsibilities.</p>
<p data-start="715" data-end="1123">The Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, form the core legal framework governing online safety and intermediary responsibilities in India. The government has also <a href="https://www.pib.gov.in/PressReleasePage.aspx?PRID=2287579&amp;reg=48&amp;lang=1" target="_blank" rel="nofollow noopener">highlighted</a> the <a href="https://thecyberexpress.com/dpdp-and-cybersecurity-rethinking-data-risk/" target="_blank" rel="noopener">Digital Personal Data Protection Act</a>, 2023, and recent amendments to the IT Rules as part of its broader approach to digital safety.</p>

<h3 class="" data-section-id="1o0spuj" data-start="1125" data-end="1192"><span role="text"><strong data-start="1129" data-end="1192">India Online Safety Rules Tighten Platform Responsibilities</strong></span></h3>
<p data-start="1194" data-end="1433">Under the IT Rules, intermediaries are required to observe due diligence and inform users that they must not host, display, upload, modify, publish, transmit, update or share content that is harmful to children or violates applicable laws.</p>
<p data-start="1435" data-end="1671">Recent amendments require <a href="https://thecyberexpress.com/child-safety-online-eu-weighs-social-media-age/" target="_blank" rel="noopener">social media platforms</a> and other intermediaries to remove unlawful content within three hours of receiving an order from a competent court or a reasoned intimation from the appropriate government or its agency.</p>
<p data-start="1673" data-end="2054">The government has also o<a href="https://www.pib.gov.in/PressReleasePage.aspx?PRID=2287646&amp;reg=48&amp;lang=1" target="_blank" rel="nofollow noopener">utlined specific obligations</a> related to content involving nudity, impersonation and other sensitive material. In cases involving certain complaints about content featuring full or partial nudity, exposed private areas or artificially morphed images, intermediaries must take reasonable and practicable measures to remove or disable access within two hours.</p>

<h3 data-section-id="1g47dy1" data-start="2056" data-end="2116"><span role="text"><strong data-start="2060" data-end="2116">Government Targets Harmful Content and OTT Platforms</strong></span></h3>
<p data-start="2118" data-end="2530">The government said it has taken action against online platforms and OTT services over unlawful and obscene content. In the last two years, 50 OTT platforms have been disabled for public access in India for displaying obscene content and violating provisions including Sections 67 and 67A of the IT Act, Section 294 of the Bharatiya Nyaya Sanhita and the Indecent Representation of Women (Prohibition) Act, 1986.</p>
<p data-start="2532" data-end="2874">The government also said it has taken note of reports alleging the dissemination of advertisements linked to <a href="https://thecyberexpress.com/ai-child-safety-in-india/" target="_blank" rel="noopener">child sexual abuse material</a> (CSAM) on social media platforms and sought a detailed report from the concerned intermediary. The National Commission for Protection of Child Rights has also issued notices to the concerned platforms.</p>

<h3 data-section-id="cy5duc" data-start="2876" data-end="2933"><span role="text"><strong data-start="2880" data-end="2933">India Strengthens AI-Generated Content Safeguards</strong></span></h3>
<p data-start="2935" data-end="3279">The government has also expanded its regulatory focus to address risks associated with <a href="https://thecyberexpress.com/ai-content-generation-systems/" target="_blank" rel="noopener">AI-generated content</a> and synthetically generated information. Amendments to the IT Rules introduce requirements for clear labelling and traceable metadata for permissible AI-generated content, allowing users to identify synthetically generated material.</p>
<p data-start="3281" data-end="3547">The framework also strengthens platform accountability and requires greater user awareness about the legal consequences of unlawful AI-generated content. The rules specifically cover harmful material including CSAM, non-consensual intimate imagery and impersonation.</p>
<p data-start="3549" data-end="3807">Platforms are required to deploy reasonable and appropriate technical measures, including automated tools or other mechanisms, to prevent users from creating, modifying, publishing or sharing synthetically generated information that violates applicable laws.</p>
<p data-start="3809" data-end="4065">Significant Social Media Intermediaries are also required to make reasonable efforts to deploy technical measures to proactively identify content depicting rape, child sexual abuse or conduct, as well as content identical to information previously removed.</p>

<h3 data-section-id="1iex218" data-start="4067" data-end="4130"><span role="text"><strong data-start="4071" data-end="4130">Child Privacy and Digital Addiction Remain Key Concerns</strong></span></h3>
<p data-start="4132" data-end="4474">The Digital Personal <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="Data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29094">Data</a> Protection Act, 2023, provides a framework for protecting children's privacy online. It mandates parental consent for processing children's personal data and prohibits practices considered detrimental to children's well-being, including tracking, behavioural monitoring and targeted advertising directed at children.</p>
<p data-start="4476" data-end="4847">The government has also highlighted digital addiction as a serious challenge affecting children and young people. The Economic Survey 2025-26 noted potential impacts on cognitive development, academic performance, workplace productivity, social connectedness and mental health, alongside <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="29095">risks</a> linked to cyberbullying, compulsive gaming, social media and online gambling.</p>

<h3 data-section-id="pzt1k1" data-start="4849" data-end="4904"><span role="text"><strong data-start="4853" data-end="4904">Cyber Awareness Reaches 11.37 Lakh Participants</strong></span></h3>
<p data-start="4906" data-end="5315">Alongside regulatory measures, the government is expanding <a href="https://thecyberexpress.com/cybersecurity-skill-gap-awareness-education/" target="_blank" rel="noopener">cyber awareness </a>initiatives through the Information Security Education and Awareness project. So far, 6,650 awareness workshops have been conducted nationwide, reaching more than 11.37 lakh participants, including students, teachers, law enforcement officials, government personnel and members of the public.</p>
<p data-start="5317" data-end="5663">The government has also highlighted digital safety initiatives in education. The PRAGYATA Guidelines provide a framework for safe online learning and responsible use of social media and electronic devices. CBSE has introduced digital etiquette and <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29093">cybersecurity</a> training initiatives, while NCERT has incorporated cyber safety into its curriculum.</p>
<p data-start="5665" data-end="5951" data-is-last-node="" data-is-only-node="">The measures were outlined by Union Minister for Electronics and Information Technology Ashwini Vaishnaw in the Lok Sabha on July 22, 2026, as the government continues to strengthen its approach to c child protection and accountability across India's digital ecosystem.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US teen drops Meta lawsuit on social media addiction days before trial]]></title>
<description><![CDATA[Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claimsA Florida teen whose lawsuit claimed Meta’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in Los Angeles ...]]></description>
<link>https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</guid>
<pubDate>Thu, 23 Jul 2026 10:36:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claims</p><p>A <a href="https://www.theguardian.com/us-news/florida">Florida</a> teen whose lawsuit claimed <a href="https://www.theguardian.com/technology/meta">Meta</a>’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in <a href="https://www.theguardian.com/us-news/los-angeles">Los Angeles</a> was ⁠set to start, his attorneys said on Wednesday. It was the latest in a massive series of high-stakes lawsuits against social media companies for allegedly designing addictive products that lead to the harm of children.</p><p>The lawsuit, brought by a 15-year-old boy known as ⁠RKC, originally named four defendants, Google’s YouTube, Meta’s Instagram, Snap Inc’s ​Snapchat and ByteDance’s <a href="https://www.theguardian.com/us-news/2026/jun/15/florida-sues-tiktok-teen-social-media-access-law">TikTok</a><strong>. </strong>YouTube and TikTok ‌settled in June<strong> </strong>and<strong> </strong>Snap reached a tentative settlement in the case, Bloomberg ‌<a href="https://www.bloomberg.com/news/articles/2026-07-20/snap-nears-settlement-of-addiction-case-ahead-of-jury-trial">reported</a> on Monday. The terms of those settlements were confidential.</p> <a href="https://www.theguardian.com/technology/2026/jul/22/florida-teen-drops-meta-lawsuit">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[France Passes Social Media Ban For Under-15s]]></title>
<description><![CDATA[French parliament overwhelmingly approves fast-tracked law barring children under 15 from social platforms starting in September This article has been indexed from Silicon UK Read the original article: France Passes Social Media Ban For Under-15s
Read more →
The post France Passes Social Media Ba...]]></description>
<link>https://tsecurity.de/de/3688180/it-security-nachrichten/france-passes-social-media-ban-for-under-15s/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688180/it-security-nachrichten/france-passes-social-media-ban-for-under-15s/</guid>
<pubDate>Thu, 23 Jul 2026 08:54:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>French parliament overwhelmingly approves fast-tracked law barring children under 15 from social platforms starting in September This article has been indexed from Silicon UK Read the original article: France Passes Social Media Ban For Under-15s</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/france-passes-social-media-ban-for-under-15s/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/france-passes-social-media-ban-for-under-15s/">France Passes Social Media Ban For Under-15s</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top Red-Light Therapy Deals at Nordstrom’s Anniversary Sale (2026)]]></title>
<description><![CDATA[Save on WIRED-tested LED therapy devices from TheraFace, HigherDose, and more.]]></description>
<link>https://tsecurity.de/de/3687577/it-nachrichten/top-red-light-therapy-deals-at-nordstroms-anniversary-sale-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687577/it-nachrichten/top-red-light-therapy-deals-at-nordstroms-anniversary-sale-2026/</guid>
<pubDate>Wed, 22 Jul 2026 22:58:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Save on WIRED-tested LED therapy devices from TheraFace, HigherDose, and more.]]></content:encoded>
</item>
<item>
<title><![CDATA[France Bans Social Media for Under-15s, Requires Age Checks]]></title>
<description><![CDATA[France will ban social media for children under 15, requiring nationwide age checks and raising privacy and platform compliance concerns. The post France Bans Social Media for Under-15s, Requires Age Checks appeared first on TechRepublic. This article has been indexed…
Read more →
The post France...]]></description>
<link>https://tsecurity.de/de/3686902/it-security-nachrichten/france-bans-social-media-for-under-15s-requires-age-checks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686902/it-security-nachrichten/france-bans-social-media-for-under-15s-requires-age-checks/</guid>
<pubDate>Wed, 22 Jul 2026 17:46:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>France will ban social media for children under 15, requiring nationwide age checks and raising privacy and platform compliance concerns. The post France Bans Social Media for Under-15s, Requires Age Checks appeared first on TechRepublic. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/france-bans-social-media-for-under-15s-requires-age-checks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/france-bans-social-media-for-under-15s-requires-age-checks/">France Bans Social Media for Under-15s, Requires Age Checks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Watch Saves Mountain Biker After Serious Crash With Fall Detection]]></title>
<description><![CDATA[Apple has shared a new real-life story showing how Apple Watch Fall Detection and Emergency SOS helped rescue an injured cyclist after a serious mountain bike crash.




https://www.youtube.com/watch?v=l40eAWni8yw




In the video, Phil explains that he was riding with his two young children when...]]></description>
<link>https://tsecurity.de/de/3686885/ios-mac-os/apple-watch-saves-mountain-biker-after-serious-crash-with-fall-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686885/ios-mac-os/apple-watch-saves-mountain-biker-after-serious-crash-with-fall-detection/</guid>
<pubDate>Wed, 22 Jul 2026 17:33:16 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has shared a new real-life story showing how Apple Watch Fall Detection and Emergency SOS helped rescue an injured cyclist after a serious mountain bike crash.




https://www.youtube.com/watch?v=l40eAWni8yw




In the video, Phil explains that he was riding with his two young children when he misjudged a jump and crashed heavily. The impact broke his collarbone and seven ribs, while also knocking him unconscious at the scene.



His Apple Watch detected the fall and automatically contacted emergency services because he could not respond. The device also shared his location, which helped firefighters find him quickly and take him to the hospital for treatment.



Phil spent one week in the hospital recovering from his injuries, and he later said he felt grateful that he had been wearing his Apple Watch during the accident. His wife also received an alert, which helped his family understand what had happened.



How Apple Watch Emergency Features Work



Apple Watch can detect serious falls and vehicle crashes, then contact emergency services when the wearer remains unresponsive. It can also share the user’s location and notify selected emergency contacts.



Apple has highlighted similar stories in previous campaigns, showing how Fall Detection, Crash Detection, heart rate alerts, and Emergency SOS have helped users during accidents and medical emergencies.]]></content:encoded>
</item>
<item>
<title><![CDATA[France Bans Social Media for Under-15s, Requires Age Checks]]></title>
<description><![CDATA[France will ban social media for children under 15, requiring nationwide age checks and raising privacy and platform compliance concerns.
The post France Bans Social Media for Under-15s, Requires Age Checks appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3686789/it-nachrichten/france-bans-social-media-for-under-15s-requires-age-checks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686789/it-nachrichten/france-bans-social-media-for-under-15s-requires-age-checks/</guid>
<pubDate>Wed, 22 Jul 2026 17:10:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>France will ban social media for children under 15, requiring nationwide age checks and raising privacy and platform compliance concerns.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-france-social-media-ban-age-verification-emea/">France Bans Social Media for Under-15s, Requires Age Checks</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Pokémon Go encouraged me to find wonder in the world]]></title>
<description><![CDATA[These days, I ‘collect’ birdsong and wild flowers, but it all started when my sons and I first set out to find Pikachu and pals• Don’t get Pushing Buttons delivered to your inbox? Sign up hereBelieve it or not, Pokémon Go is 10 years old this month. The wildly successful smartphone game, which al...]]></description>
<link>https://tsecurity.de/de/3686641/it-nachrichten/how-pokmon-go-encouraged-me-to-find-wonder-in-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686641/it-nachrichten/how-pokmon-go-encouraged-me-to-find-wonder-in-the-world/</guid>
<pubDate>Wed, 22 Jul 2026 16:22:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>These days, I ‘collect’ birdsong and wild flowers, but it all started when my sons and I first set out to find Pikachu and pals</p><p><strong>• </strong><a href="https://www.theguardian.com/info/ng-interactive/2021/nov/24/sign-up-for-pushing-buttons-keza-macdonalds-weekly-look-at-the-world-of-gaming"><strong>Don’t get Pushing Buttons delivered to your inbox? Sign up here</strong></a></p><p>Believe it or not, Pokémon Go is <a href="https://www.theguardian.com/games/video/2026/jul/10/pokemon-go-fans-times-square-celebrate-10-years-game-video">10 years old this month</a>. The wildly successful smartphone game, which allows you to track down lovable creatures in the real world using GPS and augmented-reality technologies, has reportedly been downloaded 800m times across 150 countries and regions. A trillion Pokémon have been caught so far – and I have been responsible for a modest percentage of that figure.</p><p>When the game was first released, my sons and I spent many happy hours wandering the streets and parks of Frome searching for Jigglypuffs and Charizards, and the game’s social element, which lets you take on gym battles with other players in your vicinity, offered my autistic son a route to communicate with other children in a way he’d never been able to before.</p> <a href="https://www.theguardian.com/games/2026/jul/21/ten-years-after-its-release-pokemon-go-still-encourages-me-to-find-wonder-in-the-world-around-me">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV’s The Dink Debuts This Week, Here’s What Critics Are Saying]]></title>
<description><![CDATA[Apple TV’s new sports comedy from producer Ben Stiller is almost here, and the first reviews suggest that The Dink delivers a light, funny, and familiar underdog story.



When Does The Dink Premiere on Apple TV?



The Dink will premiere globally on Apple TV on Friday, July 24, 2026. The movie r...]]></description>
<link>https://tsecurity.de/de/3685502/ios-mac-os/apple-tvs-the-dink-debuts-this-week-heres-what-critics-are-saying/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685502/ios-mac-os/apple-tvs-the-dink-debuts-this-week-heres-what-critics-are-saying/</guid>
<pubDate>Wed, 22 Jul 2026 09:18:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV’s new sports comedy from producer Ben Stiller is almost here, and the first reviews suggest that The Dink delivers a light, funny, and familiar underdog story.



When Does The Dink Premiere on Apple TV?



The Dink will premiere globally on Apple TV on Friday, July 24, 2026. The movie runs for 1 hour and 42 minutes and combines sports, comedy, family tension, and an unlikely journey into competitive pickleball.



Jake Johnson leads the cast as Dusty Boyd, a former tennis prodigy who now coaches children at a country club managed by his demanding father, Chuck, played by Ed Harris.



Dusty strongly dislikes pickleball and supports his father’s campaign against the increasingly popular sport. However, an old wrist injury forces him to stop playing tennis and use pickleball as part of his recovery. His decision soon places him in the middle of a battle that could decide the future of the struggling club.



Mary Steenburgen plays Candace, an experienced pickleball player who helps Dusty understand the sport. The supporting cast includes Aaron Chen, Patton Oswalt, Chloe Fineman, Chris Parnell, Christine Taylor and Martin Kove. Tennis stars Andy Roddick and John McEnroe also appear in supporting roles.



What Are Critics Saying About The Dink?



Early reviews describe The Dink as a playful return to the exaggerated sports comedies that became popular during the 2000s. Several critics have compared its tone and underdog structure to movies such as Dodgeball and Talladega Nights.



Jake Johnson’s performance has received particular praise. Reviewers say his dry delivery works well for Dusty, a bitter former athlete who slowly begins to reconsider his opinions about pickleball and his relationship with his father.



Mary Steenburgen and Ed Harris also bring warmth to the story, while the appearances from Ben Stiller, John McEnroe and Andy Roddick add more humor to the tournament scenes.



Some reviews note that the plot follows a predictable sports-movie structure and leaves a few supporting storylines underdeveloped. Still, the overall response points to an entertaining comedy with silly jokes, likable performances and enough heart to support its familiar storyline.



The Dink arrives on Apple TV on July 24 and looks suited to viewers searching for a relaxed summer comedy with an unusual sporting twist.




https://www.youtube.com/watch?v=YyVNFzx5Pl8]]></content:encoded>
</item>
<item>
<title><![CDATA[France Becomes First European Country To Ban Social Media Access For Under-15s]]></title>
<description><![CDATA[An anonymous reader quotes a report from The Guardian: France's parliament has approved a bill banning social media access for children under 15, making it the first European country to bar children from apps such as TikTok. The president, Emmanuel Macron, has championed the ban as a key reform o...]]></description>
<link>https://tsecurity.de/de/3685189/it-security-nachrichten/france-becomes-first-european-country-to-ban-social-media-access-for-under-15s/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685189/it-security-nachrichten/france-becomes-first-european-country-to-ban-social-media-access-for-under-15s/</guid>
<pubDate>Wed, 22 Jul 2026 05:40:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from The Guardian: France's parliament has approved a bill banning social media access for children under 15, making it the first European country to bar children from apps such as TikTok. The president, Emmanuel Macron, has championed the ban as a key reform of his final term in office and pledged to enforce it by September. "France is leading the way in Europe when it comes to protecting our children and teenagers," Macron said in a video posted on social media, hailing "a major step forward."
 
He thanked members of parliament for backing the legislation on Tuesday. "The Constitutional Council must now rule on it, and then it will be time to take action to make this measure a reality and protect our children online," he added on X. After approval by the Senate earlier on Tuesday, members of the National Assembly passed the bill by 279 votes to 81. A growing number of countries are taking steps to restrict social media access amid multiplying warnings over its harmful effects on children.
 
The ban was to be introduced in two stages, with under-15s blocked from creating new accounts from September 1. The ban would apply to existing accounts from January 2027, according to the legislation. The digital minister, Anne Le Henanff, said before the vote that the timeline was realistic, "because age-verification tools already exist" and others are still in the works, and the onus was on the platforms to impose the rule. "For four months, all of us in France will have to prove our age," she told journalists. "If someone is under 15, the account will be closed." The minister also gave assurances that users' personal data would be protected.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=France+Becomes+First+European+Country+To+Ban+Social+Media+Access+For+Under-15s%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F21%2F216206%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F21%2F216206%2Ffrance-becomes-first-european-country-to-ban-social-media-access-for-under-15s%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/21/216206/france-becomes-first-european-country-to-ban-social-media-access-for-under-15s?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[France will ban social media for children under 15]]></title>
<description><![CDATA[The country's new law also bans the use of mobile phones in schools.]]></description>
<link>https://tsecurity.de/de/3684904/it-nachrichten/france-will-ban-social-media-for-children-under-15/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684904/it-nachrichten/france-will-ban-social-media-for-children-under-15/</guid>
<pubDate>Tue, 21 Jul 2026 23:49:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The country's new law also bans the use of mobile phones in schools.]]></content:encoded>
</item>
<item>
<title><![CDATA[Immorality? Palantir Maven Fails the Gödel Test]]></title>
<description><![CDATA[On the first day of the war on Iran, February 28, Palantir’s Maven Smart System steered the U.S. military to strike at more than 1,000 targets. One was a primary school in Minab, where more than 160 people were killed, most of them children. Al Jazeera examined that strike this week under the que...]]></description>
<link>https://tsecurity.de/de/3684835/it-security-nachrichten/immorality-palantir-maven-fails-the-goedel-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684835/it-security-nachrichten/immorality-palantir-maven-fails-the-goedel-test/</guid>
<pubDate>Tue, 21 Jul 2026 23:04:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On the first day of the war on Iran, February 28, Palantir’s Maven Smart System steered the U.S. military to strike at more than 1,000 targets. One was a primary school in Minab, where more than 160 people were killed, most of them children. Al Jazeera examined that strike this week under the question of … <a href="https://www.flyingpenguin.com/immorality-palantir-maven-fails-the-godel-test/" class="more-link">Continue reading <span class="screen-reader-text">Immorality? Palantir Maven Fails the Gödel Test</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Immorality? Palantir Maven Fails the Gödel Test]]></title>
<description><![CDATA[On the first day of the war on Iran, February 28, Palantir’s Maven Smart System steered the U.S. military to strike at more than 1,000 targets. One was a primary school in Minab, where more than 160 people were killed, most of them children. Al Jazeera examined that strike this week under the que...]]></description>
<link>https://tsecurity.de/de/3684836/it-security-nachrichten/immorality-palantir-maven-fails-the-goedel-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684836/it-security-nachrichten/immorality-palantir-maven-fails-the-goedel-test/</guid>
<pubDate>Tue, 21 Jul 2026 23:04:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On the first day of the war on Iran, February 28, Palantir’s Maven Smart System steered the U.S. military to strike at more than 1,000 targets. One was a primary school in Minab, where more than 160 people were killed, most of them children. Al Jazeera examined that strike this week under the question of … <a href="https://www.flyingpenguin.com/immorality-palantir-maven-fails-the-godel-test/" class="more-link">Continue reading <span class="screen-reader-text">Immorality? Palantir Maven Fails the Gödel Test</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-59140 | EGOR Data::SortedSet::Shared up to 0.02 sortedset.h rank/min/max children[] out-of-bounds]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in EGOR Data::SortedSet::Shared up to 0.02. This issue affects the function rank/min/max of the file sortedset.h. Executing a manipulation of the argument children[] can lead to out-of-bounds read.

This vulnerability is tracked as CVE-...]]></description>
<link>https://tsecurity.de/de/3684818/sicherheitsluecken/cve-2026-59140-egor-datasortedsetshared-up-to-002-sortedseth-rankminmax-children-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684818/sicherheitsluecken/cve-2026-59140-egor-datasortedsetshared-up-to-002-sortedseth-rankminmax-children-out-of-bounds/</guid>
<pubDate>Tue, 21 Jul 2026 23:00:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/egor:data_sortedset_shared">EGOR Data::SortedSet::Shared up to 0.02</a>. This issue affects the function <code>rank/min/max</code> of the file <em>sortedset.h</em>. Executing a manipulation of the argument <em>children[]</em> can lead to out-of-bounds read.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-59140">CVE-2026-59140</a>. The attack is restricted to local execution. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[These are the countries moving to ban social media for children]]></title>
<description><![CDATA[Australia was the first country to issue a ban in late 2025, aiming to reduce the pressures and risks that young users may face on social media, including cyberbullying, social media addiction, and exposure to predators.]]></description>
<link>https://tsecurity.de/de/3684801/it-nachrichten/these-are-the-countries-moving-to-ban-social-media-for-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684801/it-nachrichten/these-are-the-countries-moving-to-ban-social-media-for-children/</guid>
<pubDate>Tue, 21 Jul 2026 22:58:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Australia was the first country to issue a ban in late 2025, aiming to reduce the pressures and risks that young users may face on social media, including cyberbullying, social media addiction, and exposure to predators.]]></content:encoded>
</item>
<item>
<title><![CDATA[Twitch will let parents stop their teens going live]]></title>
<description><![CDATA[Twitch is giving parents more control over how their children are using the streaming platform, including the ability to block them from broadcasting entirely. Parental controls are now available that allow guardians to link Twitch accounts with their 13- to 17-year-old children, providing accoun...]]></description>
<link>https://tsecurity.de/de/3684440/it-nachrichten/twitch-will-let-parents-stop-their-teens-going-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684440/it-nachrichten/twitch-will-let-parents-stop-their-teens-going-live/</guid>
<pubDate>Tue, 21 Jul 2026 19:05:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Twitch is giving parents more control over how their children are using the streaming platform, including the ability to block them from broadcasting entirely. Parental controls are now available that allow guardians to link Twitch accounts with their 13- to 17-year-old children, providing account management features and a weekly email summarizing their teen's activity, including […]]]></content:encoded>
</item>
<item>
<title><![CDATA[After TikTok, Snap settles social media addiction case]]></title>
<description><![CDATA[Snap is the latest big tech company to settle a lawsuit that claimed social media platforms are harmful to children and young adults. The company has reached a “tentative” agreement in a case that was set to go to trial later this month. TikTok recently settled its portion of the case with the pl...]]></description>
<link>https://tsecurity.de/de/3684115/it-nachrichten/after-tiktok-snap-settles-social-media-addiction-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684115/it-nachrichten/after-tiktok-snap-settles-social-media-addiction-case/</guid>
<pubDate>Tue, 21 Jul 2026 17:03:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Snap is the latest big tech company to settle a lawsuit that claimed social media platforms are harmful to children and young adults. The company has reached a “tentative” agreement in a case that was set to go to trial later this month. TikTok recently settled its portion of the case with the plaintiff, known […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside the horrifying online network where children extort others to commit violence and self-harm]]></title>
<description><![CDATA[The 764 network is just one part of a growing online ecosystem that pushes young members into brutal and degrading acts. It has perpetrators and victims in dozens of countriesIn late 2024, in a quiet suburb of Stockholm, a 14-year-old boy approached a man in his 80s who was using a walker. He sta...]]></description>
<link>https://tsecurity.de/de/3683036/it-nachrichten/inside-the-horrifying-online-network-where-children-extort-others-to-commit-violence-and-self-harm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683036/it-nachrichten/inside-the-horrifying-online-network-where-children-extort-others-to-commit-violence-and-self-harm/</guid>
<pubDate>Tue, 21 Jul 2026 10:33:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The 764 network is just one part of a growing online ecosystem that pushes young members into brutal and degrading acts. It has perpetrators and victims in dozens of countries</p><p>In late 2024, in a quiet suburb of Stockholm, a 14-year-old boy approached a man in his 80s who was using a walker. He stabbed the man three times in the back.</p><p>The video of the attack in Hässelby was streamed and spread quickly. It fed a global online ecosystem that actively encourages and glorifies acts of violence and degradation – the “gamification of harm”, as the researcher Marc-André Argentino puts it.</p> <a href="https://www.theguardian.com/technology/ng-interactive/2026/jul/21/764-network-gamification-of-harm-the-com-cybercrime-ntwnfb">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta’s smartglasses mean any child can be covertly filmed. In the age of AI, how do we tackle that risk?]]></title>
<description><![CDATA[The company argues that it’s for individuals to ensure they don’t ‘actively exploit’ this technology. That won’t keep children safeIt took me a while to realise what the man sitting next to me on the train was doing. He was flicking through pictures of a little girl on his phone; zooming in on so...]]></description>
<link>https://tsecurity.de/de/3683034/it-nachrichten/metas-smartglasses-mean-any-child-can-be-covertly-filmed-in-the-age-of-ai-how-do-we-tackle-that-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683034/it-nachrichten/metas-smartglasses-mean-any-child-can-be-covertly-filmed-in-the-age-of-ai-how-do-we-tackle-that-risk/</guid>
<pubDate>Tue, 21 Jul 2026 10:33:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The company argues that it’s for individuals to ensure they don’t ‘actively exploit’ this technology. That won’t keep children safe</p><p>It took me a while to realise what the man sitting next to me on the train was doing. He was flicking through pictures of a little girl on his phone; zooming in on some, cropping the images. Hardly unusual, of course, except that on closer inspection the pictures were very clearly of the toddler sitting opposite us, playing with her parents. On a crowded train of people mostly staring obliviously at our own phones, a stranger had been covertly photographing that little girl over and over again. And if it hadn’t been for that very visible phone screen giving him away, he wouldn’t have been caught.</p><p>That encounter was a while ago but my memory was jogged last week listening to a clip of Meta’s VP of wearables, Alex Himel, talk fondly to the BBC about using his new smartglasses <a href="https://www.bbc.co.uk/sounds/play/m002sr4h">to film his daughter</a> singing in a talent contest.<strong> </strong>They let him capture the memory without having to watch her through a screen, he said, freeing him to be “kind of living in the moment, head up and hands free”. So far, so sweet. But what about the risk of creeps potentially using them to film other people’s daughters covertly, heads up and hands free? Meta’s smartglasses have a tiny flashing warning light on the frame to indicate when the wearer is recording, but the technology is still new enough that many people don’t think to look for it. And in the age of AI, stolen images of children matter. Taken in real life or <a href="https://www.theguardian.com/society/2026/jul/03/ai-sexual-abuse-fears-uk-parents-warned-posting-images-children-national-crime-agency">scraped from the internet</a>, they’re the raw material for generating realistic-looking child abuse material of the most extreme and disturbing kind. (If that sounds like a grim but ultimately fairly victimless crime, the <a href="https://www.iwf.org.uk/about-us/why-we-exist/our-research/how-ai-is-being-abused-to-create-child-sexual-abuse-imagery/">Internet Watch Foundation warned</a> in a recent report that AI-generated material risks fuelling sexual interest in children, normalising violence and increasing the risk of real-life offending.)</p><p>Gaby Hinsliff is a Guardian columnist</p><p><em><strong>Do you have an opinion on the issues raised in this article? If you would like to submit a response of up to 300 words by email to be considered for publication in our<a href="https://www.theguardian.com/tone/letters"> letters</a> section, please <a href="mailto:guardian.letters@theguardian.com?body=Please%20include%20your%20name,%20full%20postal%20address%20and%20phone%20number%20with%20your%20letter%20below.%20Letters%20are%20usually%20published%20with%20the%20author%27s%20name%20and%20city/town/village.%20The%20rest%20of%20the%20information%20is%20for%20verification%20only%20and%20to%20contact%20you%20where%20necessary.">click here</a>.</strong></em></p> <a href="https://www.theguardian.com/commentisfree/2026/jul/21/meta-smartglasses-child-filmed-ai-risk-technology">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How this researcher helps parents with their children’s mental health]]></title>
<description><![CDATA[Connell points to a noticeable upward trend in the levels of children experiencing anxiety.
Read more: How this researcher helps parents with their children’s mental health]]></description>
<link>https://tsecurity.de/de/3682777/it-nachrichten/how-this-researcher-helps-parents-with-their-childrens-mental-health/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682777/it-nachrichten/how-this-researcher-helps-parents-with-their-childrens-mental-health/</guid>
<pubDate>Tue, 21 Jul 2026 08:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Connell points to a noticeable upward trend in the levels of children experiencing anxiety.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/innovation/sandra-connell-ucd-university-college-dublin-mental-health">How this researcher helps parents with their children’s mental health</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Experts warn of rise in sadistic online exploitation of vulnerable children]]></title>
<description><![CDATA[Global increase in cases of predators coercing children to harm themselves or produce child sexual abuse materialCases of predators coercing children into producing sexual photos and videos of themselves have surged globally in the past year, a cruel phenomenon known as “sadistic online exploitat...]]></description>
<link>https://tsecurity.de/de/3680974/it-nachrichten/experts-warn-of-rise-in-sadistic-online-exploitation-of-vulnerable-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680974/it-nachrichten/experts-warn-of-rise-in-sadistic-online-exploitation-of-vulnerable-children/</guid>
<pubDate>Mon, 20 Jul 2026 13:17:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Global increase in cases of predators coercing children to harm themselves or produce child sexual abuse material</p><p>Cases of predators coercing children into producing sexual photos and videos of themselves have surged globally in the past year, a cruel phenomenon known as “sadistic online exploitation”, child safety experts and law enforcement officials warn.</p><p>In cases of sadistic online exploitation, perpetrators target vulnerable teens on social media platforms and online games. These predators then compel their victims into producing child sexual abuse material (CSAM), harming themselves and others, or, in extreme cases, attempting suicide.</p><p><em>In the US, call or text the <a href="https://www.childhelp.org/hotline/">Childhelp</a> abuse hotline on 800-422-4453 or visit <a href="https://www.childhelphotline.org/">their website</a> for more resources and to report child abuse or DM for help. For adult survivors of child abuse, help is available at <a href="https://www.ascasupport.org/">ascasupport.org</a>. In the UK, the <a href="https://www.nspcc.org.uk/">NSPCC</a> offers support to children on 0800 1111, and adults concerned about a child on 0808 800 5000. The National Association for People Abused in Childhood (<a href="https://napac.org.uk/">Napac</a>) offers support for adult survivors on 0808 801 0331. In Australia, children, young adults, parents and teachers can contact the Kids Helpline on 1800 55 1800, or <a href="https://bravehearts.org.au/">Bravehearts</a> on 1800 272 831, and adult survivors can contact <a href="https://www.blueknot.org.au/">Blue Knot Foundation</a> on 1300 657 380. Other sources of help can be found at <a href="https://www.childhelplineinternational.org/child-helplines/child-helpline-network/">Child Helplines International</a></em></p> <a href="https://www.theguardian.com/technology/2026/jul/20/online-exploitation-children-warning">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix’s Desire Ending Explained: Who Killed Matías and What Happens to Lucero?]]></title>
<description><![CDATA[Netflix’s Desire ends by revealing that nearly every member of Lucero’s family played a role in Matías’ death. The final poolside sequence explains how jealousy, betrayal and fear turned a secret affair into a fatal family cover-up.



Major spoilers for Desire follow.



Desire Release Date, Cas...]]></description>
<link>https://tsecurity.de/de/3680069/ios-mac-os/netflixs-desire-ending-explained-who-killed-matas-and-what-happens-to-lucero/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680069/ios-mac-os/netflixs-desire-ending-explained-who-killed-matas-and-what-happens-to-lucero/</guid>
<pubDate>Mon, 20 Jul 2026 00:24:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Netflix’s Desire ends by revealing that nearly every member of Lucero’s family played a role in Matías’ death. The final poolside sequence explains how jealousy, betrayal and fear turned a secret affair into a fatal family cover-up.



Major spoilers for Desire follow.



Desire Release Date, Cast and Other Details




Netflix release date: July 17, 2026



Original title: Deseo



Genre: Erotic thriller, psychological drama



Runtime: Around 98 minutes



Director: Teresa Simone



Language: Spanish



Main cast: Ludwika Paleta, Óscar Casas, José María Yazpik and Pilar Pascual




The Mexican-Spanish movie follows Lucero, a successful 47-year-old lawyer who appears to have a comfortable life with her husband, Fernando, and their two children. However, she feels increasingly dissatisfied with her marriage and begins an affair with Matías, the young swimming coach hired by Fernando.



The situation becomes more dangerous when Lucero’s daughter, Viviana, also develops feelings for Matías. What begins as an affair soon becomes a tense triangle involving secrecy, manipulation and jealousy.



Where Is the Story Heading Before the Final Scene?



The movie opens with blood near the family’s indoor swimming pool, immediately confirming that someone has died. It then moves back through the events that caused the tragedy.



Lucero’s relationship with Matías grows more intense, even as she understands that the affair could destroy her marriage, career and relationship with her children. Matías also becomes involved with Viviana, creating further tension inside the family.



As the truth begins to surface, each character reacts differently. Viviana feels betrayed by both Matías and her mother, while Fernando begins to understand what has been happening inside his home. Lucero, meanwhile, focuses on protecting her family and preventing the affair from becoming public.



Since Desire is a standalone movie, there are no previous seasons to revisit. The entire story builds toward the night at the pool and the mystery surrounding Matías’ death.



Desire Ending Explained: Who Killed Matías?



The ending reveals that Matías’ death was caused by several actions rather than one sudden attack.



Julian secretly drugs Matías earlier in the evening. The drug leaves him physically weakened and less capable of defending himself when the conflict reaches the swimming pool.



Viviana then confronts Matías after discovering the truth about his relationship with Lucero. Feeling humiliated and used, she attacks him and leaves him injured.



Fernando later finds Matías bleeding and struggling in the pool. Instead of rescuing him, Fernando chooses to leave him there. His decision makes him directly responsible for allowing the situation to become fatal.



Lucero arrives for the final confrontation and sees that Matías is still alive. Matías appears to believe that she has come to help him or choose him over her family. However, Lucero pushes him beneath the water and holds him there until he drowns.



Lucero therefore delivers the final killing act, although every member of the family contributes to the chain of events that leads to his death.



Why Does Lucero Kill Matías?



Lucero kills Matías because she sees him as a threat to everything she wants to protect. Their affair once offered excitement and escape, but it eventually endangered her children, marriage and public life.



By the final scene, Lucero no longer views Matías as a romantic partner. She sees him as the person capable of exposing the family’s secrets and destroying their remaining sense of stability.



Her decision also completes her transformation. She begins the movie searching for freedom from her controlled life, yet she ends it committing murder to regain control.



Does Lucero’s Family Escape?



The movie does not show the family facing immediate legal consequences. Since several people contributed to Matías’ death, they share a reason to hide what happened.



The final revelation suggests that their family can remain together only by protecting the same secret. Any one of them could expose the others, creating an uneasy balance based on guilt rather than trust.



The opening bloodstains also take on a clearer meaning. They represent the evidence the family must remove, but they also reflect damage that cannot be completely erased.



What Does the Ending of Desire Mean?



The ending shows how unchecked desire damages every relationship around Lucero. Her affair affects her husband, draws her daughter into a painful rivalry and eventually turns the entire family into participants in Matías’ death.



Lucero technically protects her family from Matías, but their earlier life cannot return. Fernando knows about her betrayal, Viviana knows that her mother was involved with the same man, and everyone understands what happened beside the pool.



Desire ends without offering a clean resolution because the family’s punishment comes from living with the truth. What did you think about Lucero’s final decision, and who carries the most blame for Matías’ death? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Don’t Mention the Children]]></title>
<description><![CDATA[Michael Rosen reads his poem Don’t Mention the Children Related: Genocide Hidden in Arkansas’ Cadron Settlement on Trail of Tears Thirty of the list’s 50 victims were children, hardly any with listed identities. The inscription explains that “before 1850, it was common for Cherokee children to be...]]></description>
<link>https://tsecurity.de/de/3679757/it-security-nachrichten/dont-mention-the-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679757/it-security-nachrichten/dont-mention-the-children/</guid>
<pubDate>Sun, 19 Jul 2026 18:27:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Michael Rosen reads his poem Don’t Mention the Children Related: Genocide Hidden in Arkansas’ Cadron Settlement on Trail of Tears Thirty of the list’s 50 victims were children, hardly any with listed identities. The inscription explains that “before 1850, it was common for Cherokee children to be unnamed…”]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Agent Kim Reactivated’ Episode 9 Release Date and What to Expect]]></title>
<description><![CDATA[Agent Kim Reactivated Episode 9 will release on Friday, July 24, 2026, as Kim Do-hyeon enters the final stage of his dangerous mission.



The upcoming episode will continue directly after Episode 8’s cliffhanger, which placed Do-hyeon and General Ri in a difficult position. With only two regular...]]></description>
<link>https://tsecurity.de/de/3679678/ios-mac-os/agent-kim-reactivated-episode-9-release-date-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679678/ios-mac-os/agent-kim-reactivated-episode-9-release-date-and-what-to-expect/</guid>
<pubDate>Sun, 19 Jul 2026 17:24:40 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Episode 9 will release on Friday, July 24, 2026, as Kim Do-hyeon enters the final stage of his dangerous mission.



The upcoming episode will continue directly after Episode 8’s cliffhanger, which placed Do-hyeon and General Ri in a difficult position. With only two regular episodes remaining, the story is moving toward its final rescue mission and confrontation.



Agent Kim Reactivated Episode 9 release details




Episode 9 release date: Friday, July 24, 2026



Episode 10 release date: Saturday, July 25, 2026



Broadcast time: 9:50 p.m. KST



Network: SBS



Streaming platform: Netflix



Genre: Action, thriller, drama and comedy



Total regular episodes: 10



Based on: The Manager Kim webtoon




The series releases two episodes every week on Friday and Saturday. Episode 9 begins the final weekend, while Episode 10 will conclude the main story.



What happened before Episode 9?



Spoilers ahead for Episodes 7 and 8.



Kim Do-hyeon finally rescued his daughter, Min-ji, after facing the people responsible for her kidnapping. He also confronted Ju Gang-chan, who tried to convince him to join his side by promising money and protection.



Do-hyeon defeated Gang-chan but stopped before killing him after Min-ji intervened. He later shared an emotional farewell with his daughter and surrendered to the agency, believing that she would remain safe.



The agency then gave him one final mission. Do-hyeon must protect General Ri, a high-ranking North Korean defector connected to his past. Successful completion of the mission would allow Do-hyeon and Min-ji to receive new identities and begin a safer life.



However, Gang-chan exposed General Ri’s location to North Korean officials. Episode 8 ended when Mole Cricket arrived at Park Jin-cheol’s hideout and announced that Do-hyeon had failed. He also ordered General Ri’s return to North Korea.



What to expect from Agent Kim Reactivated Episode 9



The Episode 9 preview suggests that Do-hyeon and General Ri will be taken toward North Korea, where General Ri faces interrogation. Do-hyeon will need to find another escape route while protecting the man he was ordered to save.



Park Jin-cheol and Seong Han-soo are also expected to return for the counterattack. Their friendship with Do-hyeon has become an important part of the series, especially as the former agents work together against stronger government and criminal forces.



The preview also hints at another meeting between Do-hyeon and Ju Gang-chan. Do-hyeon appears ready to offer Gang-chan a deal, although trusting him remains dangerous after his repeated attacks against Min-ji and General Ri.



Episode 9 should include gunfights, escape attempts and a high-risk rescue operation as Do-hyeon tries to complete his mission. Gang-chan’s warning that their children will suffer if anyone harms him also raises the possibility that Min-ji could face another threat before the finale.



The story is heading toward a final family reunion



Agent Kim Reactivated began with Do-hyeon leaving his quiet life behind after Min-ji disappeared. Since then, the series has revealed his background as a former black-ops agent and the sacrifices he made to become an ordinary father.



Episode 9 will bring those two sides of his life together. Do-hyeon must survive one final mission before he can return to Min-ji, while his enemies continue using his family as pressure against him.



Do you think Do-hyeon will complete his mission and reunite with Min-ji, or will Ju Gang-chan create one final problem? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mum, can I play Roblox? Navigating online gaming safety for parents and caregivers (emf2026)]]></title>
<description><![CDATA[Unlike most adults, I play videogames professionally with children online all day, every day. I play the games children love, such as Roblox and Fortnite, many of which parents are not interested in - either giving their children total freedom with them or banning them entirely. I will immerse ad...]]></description>
<link>https://tsecurity.de/de/3679580/it-security-video/mum-can-i-play-roblox-navigating-online-gaming-safety-for-parents-and-caregivers-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679580/it-security-video/mum-can-i-play-roblox-navigating-online-gaming-safety-for-parents-and-caregivers-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 16:16:59 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unlike most adults, I play videogames professionally with children online all day, every day. I play the games children love, such as Roblox and Fortnite, many of which parents are not interested in - either giving their children total freedom with them or banning them entirely. I will immerse adults in my world for 30 minutes and give them confidence in navigating parenting in this modern age.

In this talk I will help caregivers to feel more confident in setting boundaries and limits for their child’s online gaming, by explaining the main sources of harm in some popular platforms. I give tips on how to discuss boundaries with children (especially when 'everyone in my class plays it!'), as well as describe ways I have seen children get around restrictions.

I will share the games I will and will not let my own children play - and you may be surprised as to why. I will describe how I try to keep them as safe as possible online, while maintaining friendships.

Young people are very welcome to attend alongside their caregivers to spark the discussion moving forward. Caregivers should be aware that there is talk of the harms in online gaming, but that these are sensitively covered.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/159-mum-can-i-play-roblox-navigating-online-gaming-safety]]></content:encoded>
</item>
<item>
<title><![CDATA[Scientifically ruining the interfaces in children’s shows (emf2026)]]></title>
<description><![CDATA[Previously, I used scientific research in the field of Human Computer Interaction to point out huge flaws in interface designs seen in film and tv. I’ve had two kids since then so all I see are kids shows now. Turns out the issues persist and the academic study of how we interact with technology ...]]></description>
<link>https://tsecurity.de/de/3679401/it-security-video/scientifically-ruining-the-interfaces-in-childrens-shows-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679401/it-security-video/scientifically-ruining-the-interfaces-in-childrens-shows-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 13:33:34 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Previously, I used scientific research in the field of Human Computer Interaction to point out huge flaws in interface designs seen in film and tv. I’ve had two kids since then so all I see are kids shows now. Turns out the issues persist and the academic study of how we interact with technology has a lot to say about the design of Mickey Mouse’s club house. 

A light hearted talk to discuss interesting scientific theories through the silly lens of children’s tv shows. The audience do not need a working knowledge of any children's shows to enjoy!

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/276-scientifically-ruining-the-interfaces-in-children-s-shows]]></content:encoded>
</item>
<item>
<title><![CDATA[New Study Links Teen Boys' ADHD Symptoms To Addictive Social Media Use]]></title>
<description><![CDATA[A new study by researchers at the University of California at San Francisco "adds to growing research linking increased social media use to detrimental effects on attention, memory and cognition," reports the Washington Post:

The study followed more than 11,000 U.S. adolescents over a period of ...]]></description>
<link>https://tsecurity.de/de/3679090/it-security-nachrichten/new-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679090/it-security-nachrichten/new-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use/</guid>
<pubDate>Sun, 19 Jul 2026 09:52:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new study by researchers at the University of California at San Francisco "adds to growing research linking increased social media use to detrimental effects on attention, memory and cognition," reports the Washington Post:

The study followed more than 11,000 U.S. adolescents over a period of five years, with participants first asked about their own social media use at the average age of 12, and surveyed annually through the average age of 16. Researchers found that increases in addictive social media use were followed by rising ADHD one year later — particularly among boys who reported rising addictive social media use at ages 14 and 15. This association was not found consistently in reverse, meaning that ADHD symptoms did not appear to precede higher levels of addictive social media use... "When an individual adolescent's addictive social media use score increased from one year to the next, that same adolescent tended to show an increase in ADHD symptoms in the following year...." [said Jason Nagata, lead author of the study and an associate professor of pediatrics at the University of California at San Francisco]. He urged parents to consider: "Can their kids stop if they want to? Is social media interfering with their schoolwork? Is it impairing their social relationships? Are there addiction-like symptoms, like withdrawal and relapse?" 

Approximately 7 million American children between the ages of 3 and 17 have received an ADHD diagnosis, according to the Centers for Disease Control and Prevention, and boys are diagnosed with ADHD at about twice the rate of girls. The study did not find a clear link between addictive social media use and ADHD among girls, Nagata said. "Some studies do suggest that teenage boys in particular may be more sensitive to immediate reward and sensation-seeking in adolescence," he said. And social media platforms are designed to provide exactly that: "It encourages frequent task-switching, and there's this constant stream of stimulation that might make it harder for adolescents to maintain and sustain attention that is needed for schoolwork and daily life," he said. "The design features of social media offer the constant reinforcement of impulsivity — it offers immediate gratification and novelty and it encourages multitasking, which can then override working memory and executive control." Experts have long noted that this kind of digital exposure is particularly significant during critical stages of mental, social-emotional and cognitive development... 

[I]t's especially important for parents themselves to demonstrate a healthier relationship with screens and social media. "One of our previous findings was that parental screen use is a very strong predictor of kids' screen use," Nagata said.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=New+Study+Links+Teen+Boys'+ADHD+Symptoms+To+Addictive+Social+Media+Use%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F18%2F0327200%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F18%2F0327200%2Fnew-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/18/0327200/new-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Victoria announces new social media ‘demasking’ powers for accounts accused of vilification]]></title>
<description><![CDATA[New laws would give Vcat power to force social and AI platforms to identify anonymous users in move premier says will protect childrenGet our breaking news email, free app or daily news podcastSocial media companies could be forced to identify anonymous accounts accused of online vilification, un...]]></description>
<link>https://tsecurity.de/de/3678971/ai-nachrichten/victoria-announces-new-social-media-demasking-powers-for-accounts-accused-of-vilification/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678971/ai-nachrichten/victoria-announces-new-social-media-demasking-powers-for-accounts-accused-of-vilification/</guid>
<pubDate>Sun, 19 Jul 2026 08:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New laws would give Vcat power to force social and AI platforms to identify anonymous users in move premier says will protect children</p><ul><li><p>Get our <a href="https://www.theguardian.com/email-newsletters?CMP=cvau_sfl">breaking news email</a>, <a href="https://app.adjust.com/w4u7jx3">free app</a> or <a href="https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl">daily news podcast</a></p></li></ul><p>Social media companies could be forced to identify anonymous accounts accused of online vilification, under new laws being proposed in Victoria.</p><p>The Victorian premier, Jacinta Allan, announced a suite of social media reforms on Sunday, saying families needed new ways to protect their children online.</p> <a href="https://www.theguardian.com/australia-news/2026/jul/19/victoria-proposes-social-media-account-identification-powers">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[If you can dream it: building a pop-up escape room (emf2026)]]></title>
<description><![CDATA[We love escape rooms, and it's awesome how the industry has evolved to provide ever more impressive and immersive experiences. Some of the top escape rooms today are huge warehouse-spanning installations with six-figure budgets.

But what if they didn't have to be? Last year, our team had the opp...]]></description>
<link>https://tsecurity.de/de/3678706/it-security-video/if-you-can-dream-it-building-a-pop-up-escape-room-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678706/it-security-video/if-you-can-dream-it-building-a-pop-up-escape-room-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 03:17:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We love escape rooms, and it's awesome how the industry has evolved to provide ever more impressive and immersive experiences. Some of the top escape rooms today are huge warehouse-spanning installations with six-figure budgets.

But what if they didn't have to be? Last year, our team had the opportunity to build a pop-up escape room. We wanted to match the creative ambition and capacity for wonder demonstrated by the biggest and best escape rooms in the world; implemented with the scrappy enthusiasm, inherent impermanence, and modest budget of an amateur theatre production.

What we built turned out to be a real dream. Over our five-month run, our core team (gradually bolstered by dozens more volunteers) provided a unique and delightful experience for over six hundred visitors of all ages, including twenty children, two babies, and one dog. We received amazing feedback, tremendously kind reviews, and hugely encouraging industry recognition.

In this talk we'll cover how we turned our ideas into reality, what went to plan, what went wrong, and what we learned. Most importantly, we hope to show what is possible and perhaps inspire other projects, because we'd love to see more escape rooms in the world.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/229-if-you-can-dream-it-building-a-pop-up-escape-room]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI will start notifying parents if their teen has been kicked off of ChatGPT]]></title>
<description><![CDATA[OpenAI will send a notification to parents with linked teen accounts if their children have violated its policies around violence.]]></description>
<link>https://tsecurity.de/de/3677899/it-nachrichten/openai-will-start-notifying-parents-if-their-teen-has-been-kicked-off-of-chatgpt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677899/it-nachrichten/openai-will-start-notifying-parents-if-their-teen-has-been-kicked-off-of-chatgpt/</guid>
<pubDate>Sat, 18 Jul 2026 13:17:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI will send a notification to parents with linked teen accounts if their children have violated its policies around violence.]]></content:encoded>
</item>
<item>
<title><![CDATA[Internet of Baby - the privacy implications of a smart nursery. (emf2026)]]></title>
<description><![CDATA[IoT baby monitors, smart bassinets, connected toys, and AI-powered parenting apps promise peace of mind and convenience for tired parents of wee children.

But behind the reassuring notifications and cutesy designs lies an ever expanding ecosystem of microphones, cameras, biometric sensors, cloud...]]></description>
<link>https://tsecurity.de/de/3677011/it-security-video/internet-of-baby-the-privacy-implications-of-a-smart-nursery-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677011/it-security-video/internet-of-baby-the-privacy-implications-of-a-smart-nursery-emf2026/</guid>
<pubDate>Fri, 17 Jul 2026 22:48:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[IoT baby monitors, smart bassinets, connected toys, and AI-powered parenting apps promise peace of mind and convenience for tired parents of wee children.

But behind the reassuring notifications and cutesy designs lies an ever expanding ecosystem of microphones, cameras, biometric sensors, cloud analytics, and behaviour profiling systems collecting data about children - before they even have started solids!

This talk explores the privacy implications of modern baby IoT devices: what data is collected, where it goes, who profits from it.

I will examine real-world breaches, insecure ecosystems, children's data gathering, and the consequences of normalising surveillance from infancy.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/220-internet-of-baby-the-privacy-implications-of-a-smart-nursery]]></content:encoded>
</item>
<item>
<title><![CDATA[Middle Rage - Social Media and the War on Democracy (emf2026)]]></title>
<description><![CDATA[What happens when the people we think of as “having it all sorted” start being quietly pulled towards extremism online?
This talk from the SMIDGE project shines a light on an often-overlooked group: the middle aged. This includes some of the most powerful people in the world CEOs, influencers and...]]></description>
<link>https://tsecurity.de/de/3676645/it-security-video/middle-rage-social-media-and-the-war-on-democracy-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676645/it-security-video/middle-rage-social-media-and-the-war-on-democracy-emf2026/</guid>
<pubDate>Fri, 17 Jul 2026 19:19:21 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What happens when the people we think of as “having it all sorted” start being quietly pulled towards extremism online?
This talk from the SMIDGE project shines a light on an often-overlooked group: the middle aged. This includes some of the most powerful people in the world CEOs, influencers and politicians. For most however, middle-age looks very different: juggling jobs, children, ageing parents, mortgages, and a constant stream of news, advice, and opinions online.
Far from being “sorted,” this stage of life is full of pressures including health worries, financial strain, and caring responsibilities. So, when something appears online that promises a clear explanation, a simple answer, or someone to blame, it can be hard not to pay attention.
The problem is that the systems shaping what we see are not designed to inform us but are designed to keep us engaged. AI-driven content is becoming more convincing by the day, blurring the line between what is real and what is not. What starts as an innocent search for diet tips or money advice can lead down a path towards more extreme, emotionally charged content. Not suddenly, but step by step.
This talk explores why the “invisible middle” matters both as a group vulnerable to misinformation, and as one with real influence over how ideas spread. Because if we want to understand radicalisation today, we cannot afford to ignore the middle aged.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/129-middle-rage-social-media-and-the-war-on-democracy]]></content:encoded>
</item>
<item>
<title><![CDATA[July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave]]></title>
<description><![CDATA[Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Se...]]></description>
<link>https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</guid>
<pubDate>Fri, 17 Jul 2026 18:08:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview">Active Directory Federation Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155">CVE-2026-56155</a>), and an elevation of privilege in <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> Server (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>). A third, a <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) is publicly disclosed but not yet exploited.</p>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today. The Readiness team has provided a handy <a href="https://applicationreadiness.com/perspectives/assurance-security-dashboard-july-2026-patch-tuesday/">infographic</a> of the expected risk profile of this month’s Patch Tuesday updates.</p>



<h2 class="wp-block-heading">Known issues</h2>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July release note</a> flags known issues against the following updates:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> recovery prompt on first restart – the PCR7 recovery condition tracked since April remains live on the platforms that did not receive the Boot Manager servicing fix (Windows Server 2022 and Windows 10 22H2). Devices with BitLocker on the OS drive, the Group Policy “Configure TPM platform validation profile for native UEFI firmware configurations” set with PCR7 included, and <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/system-security/trusted-boot">Secure Boot</a> State PCR7 Binding reported as “Not Possible” may be prompted for the recovery key on the first restart after installing this update. This month’s publicly disclosed BitLocker security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) keeps the component in focus.</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a> synchronization error details suppressed (Windows Server 2025 and 2022) – WSUS no longer displays synchronization error details in its error reporting, a deliberate change made to address the Remote Code Execution Vulnerability <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287">CVE-2025-59287</a>. Sync still works, but administrators triaging a failed synchronization lose the detail pane and must fall back to the SoftwareDistribution logs.</li>
</ul>



<p class="wp-block-paragraph">Windows Update can still replace manually installed graphics drivers with older OEM versions from the catalogue (the four-part Hardware ID ranking issue acknowledged on the <a href="https://techcommunity.microsoft.com/blog/hardware-dev-center/updated-graphics-driver-publishing-policy-from-4-part-to-2-part-hwid--chid-targe/4519070">Hardware Dev Center</a>). The two-part HWID pilot runs to September 2026.</p>



<h2 class="wp-block-heading">Major revisions and mitigations</h2>



<p class="wp-block-paragraph">Between the June and July Patch Tuesdays, MSRC Security Update Guide notices updated 651 reported CVEs across six notification dates (15, 19, 26 June and 3, 8, 11 July), 532 of them routine Chromium upstream re-publications. Of the roughly 30 Microsoft revisions, almost all were cross-platform Office catch-up with no bearing on a Windows enterprise estate. No further action required for IT administrators for this Windows update cycle.</p>



<h2 class="wp-block-heading">Windows lifecycle and enforcement updates</h2>



<p class="wp-block-paragraph">This is the deadline cycle June pointed at. The July end-of-support wave lands today, and it collides with the month’s heaviest patching. <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a> take some of their most active security updates ever on platforms receiving their last.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2016">SharePoint Server 2016</a> and <a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2019">2019</a>, <a href="https://learn.microsoft.com/en-us/lifecycle/products/project-server-2016">Project Server 2016</a> and 2019, <a href="https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2016">SQL Server 2016</a> and InfoPath 2013 have all reached end of support. SQL Server 2014 ESU Year 2 reaches end of support today. SharePoint 2016/2019 take an actively exploited zero-day and two RCEs this cycle, and SQL Server 2016 takes a critical RCE, all as their final security update. Now is the time to get moving on updating these platforms.</li>
</ul>



<p class="wp-block-paragraph">The 2011 Secure Boot certificate expiries have now passed; devices that never took the Windows UEFI CA 2023 key updates under <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932">CVE-2023-24932</a> can no longer receive updated boot components, with the Windows Production PCA for the boot manager still ahead on 19 October 2026. <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview">Kerberos</a> RC4 hardening (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833">CVE-2026-20833</a>) has been in enforcement since April 2026; the July 2026 update removes the RC4DefaultDisablementPhase rollback control that let administrators defer it, making enforcement final.</p>



<p class="wp-block-paragraph">Microsoft’s <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> is a security-only release: 180 test-guidance entries, 14 of them high risk (June had one). Printing and graphics are the centre of gravity: win32kfull.sys, the kernel-mode window manager, is the most-patched binary (14 entries), and seven high-risk flags sit alongside it – the <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-spooler-components">Print Spooler</a>, four win32k entries, and two <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-gdi-start">GDI+</a> metafile entries. <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> is the second theme, with 10 entries, two high risk. Every entry reports no functional changes – it’s pure regression validation. The packages span Windows 11 26H1 back to Server 2012 ESU.</p>



<h2 class="wp-block-heading">Printing and graphics (high risk)</h2>



<p class="wp-block-paragraph">The Print Spooler flag centres on shared printers, whose queue status must track jobs accurately; the win32k flags cover 32-bit application printing, font rendering in printed and exported output, on-screen rendering, and window management; the GDI+ flags cover metafiles.</p>



<ul class="wp-block-list">
<li>Share a printer from a print server, print from a separate client in varied sizes and formats, and cancel a job, confirming the queue reflects every state change</li>



<li>Print from your 32-bit applications, and print text-heavy, graphics-heavy, and multi-page documents to physical and virtual (PDF or XPS) printers, repeating after orientation, scaling, and resolution changes</li>



<li>Export documents with varied fonts to PDF and confirm fonts and layout survive; render EMF+ files that apply effects to very large images, and convert EMF files to WMF</li>



<li>Open and close windows rapidly, drive common dialogs by mouse and keyboard, and close parents with children open – no orphaned windows</li>
</ul>



<h2 class="wp-block-heading">Storage and file systems (high risk)</h2>



<p class="wp-block-paragraph">Both NTFS high-risk flags target integrity – extended attributes, and volume recovery after an unexpected shutdown. File History carries its own high-risk flag on clients. A Windows Server 2025-only bundle across boot, <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a>, and <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> demands the full Secure Boot/BitLocker matrix. Eight entries hit Server 2025 alone, including WSL, GPU partitioning, and a scripted Windows Server Backup pass repeating recovery after rolling the date 90 days forward.</p>



<ul class="wp-block-list">
<li>Exercise NTFS extended attributes – older-system EAs, backup workflows that preserve them, concurrent same-file operations where supported – with antivirus, encryption, or storage filters active</li>



<li>Simulate an unexpected shutdown during file activity, verify the volume mounts intact, run chkdsk, and confirm indexing, shadow copies, and backup still work</li>



<li>Run a full File History pass: back up, modify and back up again, exclude folders, change frequency, move the destination</li>



<li>On Server 2025, boot all four Secure Boot/BitLocker combinations, in standard and confidential VMs where supported</li>
</ul>



<h2 class="wp-block-heading">Devices, input and networking (high risk)</h2>



<p class="wp-block-paragraph">Three further high-risk flags land here: HID input (hidparse.sys with win32k) – touch, keyboard, mouse, touchpad, through disconnects and restarts; the WinSock bundle (afd.sys plus Bluetooth and multicast drivers); and IrDA. The heaviest ask is not high risk at all: the NetAdapterCx driver (24H2/25H2, Server 2025) wants 500-plus adapter enable-disable cycles under Driver Verifier.</p>



<ul class="wp-block-list">
<li>Run the connectivity suite: browsing, large downloads, mapped drives, an RDP session idle 30+ minutes, a Teams call, an hour of streaming, and localhost apps such as Docker or WSL</li>



<li>Stress Bluetooth: pairing, 10+ minutes of audio, input after idle, and reconnection after sleep</li>



<li>Where infrared hardware exists, transfer a file and run at least 100 connect-disconnect cycles</li>



<li>Sweep the rest: DNS Server (zone data must stay under its configured database directory), the client resolver (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> Server (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview">SMB</a>, <a href="https://learn.microsoft.com/en-us/windows-server/storage/nfs/nfs-overview">NFS</a>, Message Queuing (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-access/remote-access">RRAS</a> administration, client VPN, and WinHTTP/WinINet consumers</li>
</ul>



<h2 class="wp-block-heading">Other windows components</h2>



<p class="wp-block-paragraph">Windows Installer itself is patched: testing should include application install, uninstall, repair, and force a rollback. <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> wants virtual-switch traffic as part of its testing exercises with Virtual Filtering Platform policies enforced. Sixteen media-related security entries cover playback, HEVC and MPEG-TS, USB audio, and MIDI 2.0.</p>



<h2 class="wp-block-heading">Shell hardening and LSA isolation</h2>



<p class="wp-block-paragraph">These two entries are a little different from the rest of the cycle: they ask you to confirm a security behaviour actively works, not just that nothing regressed. A pass here means the protection fired, so treat them as functional checks rather than box-ticking.</p>



<ul class="wp-block-list">
<li>Shortcut handling (windows.storage.dll; Windows 11 23H2 and earlier, plus Server 2022): drop a shortcut file carrying the <a href="https://learn.microsoft.com/en-us/deployoffice/security/internet-macros-blocked">Mark of the Web</a> into a folder and confirm the system refuses to extract its icon and leaks no <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview">NTLM</a> credential hash – include the zero-click paths, where the icon would otherwise render without you opening anything</li>



<li>LSA isolation and KeyGuard (24H2/25H2, Server 2025): run the supplied PowerShell validation script, which turns on <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">Virtualization-based Security</a> if it isn’t already, exercises KeyGuard key operations in both required and best-effort isolation modes, and reports pass or fail – it needs TPM 2.0, UEFI with Secure Boot disabled, and PowerShell 7</li>



<li>Run that script on a dedicated test machine, never a shared one: it enables test signing, disables automatic updates, and reboots without asking</li>
</ul>



<h2 class="wp-block-heading">Office &amp; SharePoint</h2>



<p class="wp-block-paragraph">July’s <a href="https://learn.microsoft.com/en-us/office/">Office</a> wave is security-only; everything landed on 14 July, and nothing critical or non-security shipped in the 7 July preview. It’s an MSI-only cycle, so <a href="https://learn.microsoft.com/en-us/deployoffice/overview-office-deployment-tool">Click-to-Run</a> estates can sit this one out.</p>



<ul class="wp-block-list">
<li>On MSI Office 2016, apply the client updates – <a href="https://learn.microsoft.com/en-us/office/client-developer/excel/excel-home">Excel</a> (KB5002886), <a href="https://learn.microsoft.com/en-us/office/client-developer/word/word-home">Word</a> (KB5002890), PowerPoint (KB5002867), and five further Office 2016 security updates (<a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002273">KB5002273</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002887">KB5002887</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002748">KB5002748</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002857">KB5002857</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002830">KB5002830</a>) – then exercise macros, external data, embedded objects, and any line-of-business add-ins</li>



<li>On <a href="https://learn.microsoft.com/en-us/sharepoint/sharepoint-server">SharePoint Server</a>, patch 2016 (KB5002891, plus the KB5002892 language pack) and Subscription Edition (KB5002882), then check browser-based editing; the guidance lists SharePoint 2019 with a baseline but ships no 2019 package, so there is nothing to install there</li>
</ul>



<p class="wp-block-paragraph">Mind the rollback rules before you schedule the window: most client updates can be uninstalled, but the server updates cannot and always require a reboot.</p>



<h2 class="wp-block-heading">Developer tools &amp; databases</h2>



<p class="wp-block-paragraph">The developer estate gets a broad but low-drama sweep this month. Both .NET and SQL Server patch widely, but the ask is representative-application validation rather than anything exotic – install on the matching branch and confirm normal behaviour.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/dotnet/core/sdk">.NET</a>: install the SDK updates (8.0.423, 9.0.316, 10.0.302, x64 and x86) and the Framework rollups spanning 3.5 through 4.8.1 – which reach from Windows Server 2012 up to Windows 11 26H1 and Server 2025 – then run a representative set of applications and confirm they function normally</li>



<li><a href="https://learn.microsoft.com/en-us/sql/sql-server/">SQL Server</a>: the <a href="https://learn.microsoft.com/en-us/troubleshoot/sql/releases/servicing-models-sql-server">GDR</a> updates span 2016 SP3 through 2025 – install each on its matching branch and test that each removes cleanly</li>



<li>Check an encrypted client connection through the separately patched Windows SQL client (dbnetlib.dll), which ships outside the server branches</li>
</ul>



<p class="wp-block-paragraph">The Readiness team recommends the following priorities for your larger enterprise deployments:</p>



<ul class="wp-block-list">
<li>Start with printing and graphics: half the high-risk flags sit in the Print Spooler, win32k, and GDI+, so regress shared printers, 32-bit printing, PDF export, metafiles, and window management before anything else</li>



<li>Take NTFS next – extended attributes and crash recovery both touch data integrity – and add a client File History backup-and-restore pass</li>



<li>Give Server 2025 its wider matrix – the Secure Boot/BitLocker combinations, WSL, GPU partitioning, and the scripted backup pass – and work through the stress suites</li>



<li>Run the scripted KeyGuard validation on any <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">VBS</a> estate, preferably on a dedicated machine.</li>
</ul>



<p class="wp-block-paragraph">Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings:</p>



<ul class="wp-block-list">
<li>Browsers (Microsoft IE and Edge)</li>



<li>Microsoft Windows (both desktop and server)</li>



<li>Microsoft Office</li>



<li>Microsoft Exchange and SQL Server</li>



<li>Microsoft Developer Tools (Visual Studio and .NET)</li>



<li>Adobe (if you get this far)</li>
</ul>



<h2 class="wp-block-heading">Browsers</h2>



<p class="wp-block-paragraph">Edge has had a busier month than usual. Microsoft addressed 46 <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business">Microsoft Edge</a> (Chromium-based) CVEs this cycle. None critical, but heavily weighted to remote code execution (21 entries) and spoofing (13), led by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289">CVE-2026-58289</a>, a remote code execution flaw. A run of further RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57981">CVE-2026-57981</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56645">CVE-2026-56645</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57974">CVE-2026-57974</a>) follows.</p>



<ul class="wp-block-list">
<li>Microsoft Edge – the Edge-specific fixes ship in the Edge stable channel (version 150.0.4078.65, released 9 July). The concentration of RCE and spoofing this month is worth a look for managed Edge estates rather than a routine wave-through.</li>



<li>Chromium upstream – 427 CVEs relayed through MSRC this cycle, spanning the weekly Chrome release cadence since the June report: use-after-free, out-of-bounds read/write, type confusion, and inappropriate-implementation flaws across V8, Dawn, ANGLE, Skia, and Tint. The same fixes ship in the Chrome Stable channel; see the <a href="https://chromereleases.googleblog.com/">Chrome releases blog</a> for the upstream notes.</li>
</ul>



<p class="wp-block-paragraph">The Chromium volume looks (quite) alarming but is routine plumbing: it flows to Edge through its own auto-update channel. Add these browser (Edge) updates to your standard release schedule for your managed environments.</p>



<h2 class="wp-block-heading">Microsoft Windows</h2>



<p class="wp-block-paragraph">Windows carries the bulk of this month’s updates: 406 CVEs, 31 rated critical and 374 important. Elevation of privilege dominates by volume (226 entries), followed by remote code execution (70), information disclosure (70), denial of service (23), and a scatter of security-feature-bypass, tampering, and spoofing entries across the following feature groupings:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> – the standout network cluster: DHCP Server remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518">CVE-2026-50518</a>, “Exploitation More Likely,” and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56159">CVE-2026-56159</a>), with further critical DHCP Server and DHCP Client RCEs behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48564">CVE-2026-48564</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50370">CVE-2026-50370</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128">CVE-2026-54128</a>). DHCP servers are the deployment priority.</li>



<li><a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/virtual-switch">VMSwitch</a> and <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> – the Windows VMSwitch elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092">CVE-2026-57092</a>) is one of the month’s highest-severity flaws, joined by two critical Hyper-V elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50680">CVE-2026-50680</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54127">CVE-2026-54127</a>), guest-to-host risk on virtualisation hosts.</li>



<li>Network stack RCE – a Windows Server Network driver RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188">CVE-2026-56188</a>, “Exploitation More Likely”), plus <a href="https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/tcpip-addressing-and-subnetting">TCP/IP</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54999">CVE-2026-54999</a>), the Reliable Multicast Transport Driver (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54982">CVE-2026-54982</a>), and SSTP (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50694">CVE-2026-50694</a>).</li>



<li>Graphics – Windows <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-overview-of-gdi--about">GDI+</a> remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50380">CVE-2026-50380</a>) and a <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/display/directx-graphics-kernel-subsystem">DirectX Graphics Kernel</a> RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50382">CVE-2026-50382</a>), both reachable through document-rendering paths.</li>



<li>Windows Media – a large cluster: three critical <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/microsoft-media-foundation-sdk">Media Foundation</a> RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57090">CVE-2026-57090</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57094">CVE-2026-57094</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57087">CVE-2026-57087</a>) lead 14 Windows Media and seven Media Foundation entries overall.</li>



<li>Identity infrastructure – beyond the exploited ADFS flaw, <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview">Active Directory Domain Services</a> takes a critical RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164">CVE-2026-49164</a>) and <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/active-directory-certificate-services-overview">Active Directory Certificate Services</a> a critical elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121">CVE-2026-54121</a>). Domain controllers take priority again.</li>



<li><a href="https://learn.microsoft.com/en-us/windows/win32/printdocs/print-spooler">Print Spooler</a>, <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a>, and MSMQ – critical RCE/EoP in the Print Spooler (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58608">CVE-2026-58608</a>), <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">Windows Server Update Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50444">CVE-2026-50444</a>), and <a href="https://learn.microsoft.com/en-us/windows/win32/rpc/overview-of-message-queuing-services-architecture">Message Queuing</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992">CVE-2026-54992</a>, “Exploitation More Likely”), all server-role attack surface.</li>
</ul>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/windows-kernel-mode-kernel-library">Windows Kernel</a> is the most-patched component (28 CVEs, seven “More Likely”), followed by <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> (21), Windows Runtime (17), Windows Media (14), <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> (12), and Win32k (15 across its two entries). Add this Windows update to your Patch Now deployment schedule.</p>



<h2 class="wp-block-heading">Microsoft Office</h2>



<p class="wp-block-paragraph">Microsoft released 96 Office CVEs this month: 19 critical, 76 important. Remote code execution leads (53 entries), ahead of information disclosure (27) and spoofing (10). <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> is the centre of gravity: it touches 39 of the 96 CVEs and supplies the family’s one actively exploited flaw.</p>



<ul class="wp-block-list">
<li>SharePoint Server: has been exploited (who would have guessed) and reaches end of support today. <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>, an elevation of privilege, is under active exploitation. Above it sit two critical remote code execution flaws, both “Exploitation More Likely” (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522">CVE-2026-50522</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644">CVE-2026-58644</a>) and a critical security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040">CVE-2026-55040</a>). SharePoint Server 2016 and 2019 reach end of support on 14 July, so this exploited, critical-heavy set is the final security update those on-premises farms will receive.</li>



<li>Office has experienced a long run of critical remote code execution entries across Office, Word, and PowerPoint (among them <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55033">CVE-2026-55033</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55127">CVE-2026-55127</a> in Word, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55043">CVE-2026-55043</a> in PowerPoint, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55018">CVE-2026-55018</a> in Office), topped by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55045">CVE-2026-55045</a>.</li>
</ul>



<p class="wp-block-paragraph">With an exploited zero-day, two RCEs, and an end-of-support deadline all landing on SharePoint in the same cycle, SharePoint environments are the priority. Add the July Office and SharePoint updates to your Patch Now schedule.</p>



<h2 class="wp-block-heading">Microsoft Exchange and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a></h2>



<p class="wp-block-paragraph">Both Exchange and SQL Server carry critical-rated security vulnerabilities this month. <a href="https://learn.microsoft.com/en-us/exchange/">Exchange Server</a> returns with an on-premises security update for Exchange Server Subscription Edition, the only on-premises release still supported after Exchange Server 2016 and 2019 reached end of support in October 2025; SQL Server takes two critical remote code execution flaws, one of them against SQL Server 2016, which reaches end of support on the same day.</p>



<ul class="wp-block-list">
<li>Exchange Server (on-premises) – <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008">CVE-2026-55008</a>, a spoofing vulnerability rated critical and “Exploitation More Likely,” is the headline. Behind it, a remote code execution entry (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55005">CVE-2026-55005</a>) and two elevation-of-privilege flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55006">CVE-2026-55006</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55009">CVE-2026-55009</a>) round out the on-premises set. A separate Exchange Online elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998">CVE-2026-54998</a>, critical) is fixed service-side with no customer action.</li>



<li>SQL Server – two critical remote code execution flaws: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117">CVE-2026-54117</a> (SQL Server 2025) and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118">CVE-2026-54118</a> (which reaches back to SQL Server 2016 SP3), with five further important elevation-of-privilege and information-disclosure entries behind them. The 2016 exposure matters because SQL Server 2016 reaches end of support on 14 July: a critical RCE on a platform taking its final update.</li>
</ul>



<p class="wp-block-paragraph">Both belong on the Patch Now schedule this month: the Exchange on-premises update for its critical spoofing flaw, and the SQL Server update for the two critical RCEs.</p>



<h2 class="wp-block-heading">Microsoft developer tools</h2>



<p class="wp-block-paragraph">Microsoft released 24 CVEs across its developer tooling this month, all rated important. The weighting shifts from last month’s <a href="https://code.visualstudio.com/">Visual Studio Code</a> concentration toward <a href="https://learn.microsoft.com/en-us/dotnet/core/introduction">.NET</a> and <a href="https://learn.microsoft.com/en-us/aspnet/core/overview?view=aspnetcore-10.0">ASP.NET Core</a>, where a run of denial-of-service entries dominates the volume:</p>



<ul class="wp-block-list">
<li>ASP.NET Core and .NET – the two highest-severity entries are ASP.NET Core elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300">CVE-2026-47300</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303">CVE-2026-47303</a>), ahead of a .NET security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528">CVE-2026-50528</a>) and two .NET / .NET Framework remote code execution flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50646">CVE-2026-50646</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50649">CVE-2026-50649</a>).</li>



<li><a href="https://learn.microsoft.com/en-us/visualstudio/get-started/visual-studio-ide?view=visualstudio">Visual Studio</a> and VS Code – a GitHub Copilot / Visual Studio Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109">CVE-2026-41109</a>) and a second VS Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57102">CVE-2026-57102</a>) lead here, with a VS Code remote code execution entry behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50520">CVE-2026-50520</a>) and a Visual Studio RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47305">CVE-2026-47305</a>).</li>
</ul>



<p class="wp-block-paragraph">Add these Microsoft updates to your standard developer update release schedule.</p>



<h2 class="wp-block-heading">Adobe (and third-party updates)</h2>



<p class="wp-block-paragraph">Outside Microsoft’s own catalogue, July is quiet. Adobe issued no Acrobat or Reader security updates. So, the month belongs to Microsoft, and it is a heavy one: 722 CVEs, roughly three times a normal cycle and one of the largest on record. Worth noting that this lands in the same season Microsoft has been talking up AI-assisted vulnerability management, and the AI stack it is selling as the answer, Copilot and Azure OpenAI among them, sits in the centre of this patch cycle’s own critical-rated updates. The (AI) tooling may be getting smarter, but the patch pile is (definitely) not getting smaller. This may be the beginning of an accelerating curve of ever larger patch cycles. My feeling is that we are in the middle of the beginning of this coming patch surge.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.computerworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Confirms Stillwater Season 5 Release Date, All Episodes Arrive This August]]></title>
<description><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The...]]></description>
<link>https://tsecurity.de/de/3676102/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676102/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</guid>
<pubDate>Fri, 17 Jul 2026 14:54:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The new season continues the award-winning story of siblings Karl, Addy, and Michael, whose wise panda neighbor helps them understand their feelings and look at difficult situations from a calmer perspective. Viewers can currently stream the first four seasons on Apple TV.



Here are the main details about the upcoming season:




Release date: Friday, August 21, 2026



Number of episodes: Five



Release schedule: All episodes will arrive together



Genre: Animated kids and family series



Start airing date: August 21, 2026



Finish date: August 21, 2026



Where to watch: Apple TV



Main voice cast: James Sie, Eva Ariel Binder, Tucker Chandler, and Judah Mackey




What is Stillwater season 5 about?







Stillwater follows Karl, Addy, and Michael as they deal with problems that feel familiar to young viewers, including disappointment, uncertainty, disagreements, and fear of trying something new.



Their neighbor Stillwater listens to their concerns and often shares a thoughtful story that helps them see the situation differently. His advice encourages the children to slow down, understand their emotions, and find their own way forward.



Season 5 will continue this familiar format through five new adventures. Each episode will focus on the children learning more about themselves, their relationships, and the world around them. The series remains inspired by Jon J Muth’s bestselling Zen book collection.



The first look at the season shows Stillwater returning alongside the three siblings, suggesting that the new episodes will maintain the peaceful visual style and warm storytelling that have defined the show since its 2020 debut.



There are currently no major plot details or episode descriptions available, so viewers will need to wait for a trailer or further announcements to learn which specific challenges Karl, Addy, and Michael will face.




https://www.youtube.com/watch?v=zz1GkcvkT1g




FAQs



When is the Stillwater season 5 release date?



Stillwater season 5 will premiere globally on Apple TV on Friday, August 21, 2026.



How many episodes are in Stillwater season 5?



The fifth season contains five new episodes. Apple TV will release all five episodes on the premiere date, allowing families to watch the full season immediately.



Will Stillwater season 5 release weekly?



No. All five episodes will become available together on August 21, 2026.



Who voices Stillwater in the animated series?



James Sie voices Stillwater. The main cast also includes Eva Ariel Binder as Addy, Tucker Chandler as Michael, and Judah Mackey as Karl.



Is Stillwater suitable for children?



Yes. Stillwater is an animated kids and family series that focuses on emotional awareness, mindfulness, kindness, and solving everyday problems.



Where can I watch the previous seasons?



All four previous seasons are available to stream on Apple TV before season 5 arrives.



Is Stillwater season 5 the final season?



Apple TV has announced the fifth season but has not officially described it as the final season. Its future beyond these five episodes remains unconfirmed.



Apple TV costs $12.99 per month in the United States after a seven-day free trial. With every new episode arriving on the same day, families can watch Stillwater season 5 at their own pace from August 21. Do you plan to watch the new season? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tesla's selling a $225 balance bike for toddlers]]></title>
<description><![CDATA[Tesla's Autopilot may fail to recognize children at times, but the company certainly recognizes their potential as future buyers.]]></description>
<link>https://tsecurity.de/de/3675929/it-nachrichten/teslas-selling-a-225-balance-bike-for-toddlers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675929/it-nachrichten/teslas-selling-a-225-balance-bike-for-toddlers/</guid>
<pubDate>Fri, 17 Jul 2026 13:48:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tesla's Autopilot may fail to recognize children at times, but the company certainly recognizes their potential as future buyers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Privacy Blog: Beyond technical fixes: Protecting kids online without breaking the internet]]></title>
<description><![CDATA[This is part one of a two-part series in which we explore approaches to protecting children online while safeguarding privacy, security and the open web. Part one covers our concerns regarding age gates, and alternative policy proposals that address the root causes of online harms. 
Young people ...]]></description>
<link>https://tsecurity.de/de/3675858/tools/mozilla-privacy-blog-beyond-technical-fixes-protecting-kids-online-without-breaking-the-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675858/tools/mozilla-privacy-blog-beyond-technical-fixes-protecting-kids-online-without-breaking-the-internet/</guid>
<pubDate>Fri, 17 Jul 2026 13:10:44 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>This is part one of a two-part series in which we explore approaches to protecting children online while safeguarding privacy, security and the open web. Part one covers our concerns regarding age gates, and alternative policy proposals that address the root causes of online harms. </i></p>
<p>Young people today have unprecedented opportunities to learn, connect, and explore — not just the web and the world, but also themselves. With the increased ubiquity of digital technologies and devices, worries around the <a href="https://www.nature.com/articles/s41562-018-0506-1">relationship between these technologies and young people’s well-being</a> have grown, too. While concerns about the societal implications of new technologies is <a href="https://journals.sagepub.com/doi/10.1177/1745691620919372">not a new phenomenon</a>, <a href="https://www.science.org/doi/10.1126/science.adt6807">experts argue</a> that the accelerating speed of deployment of new technologies has outpaced scientists’ capacity to feed into policy recommendations addressing risks. A growing body of research <a href="https://osf.io/preprints/psyarxiv/m38u6_v2">documents</a> the harms experienced by young people online and the challenges <a href="https://ijse.padovauniversitypress.it/2024/1/8">reported</a> by parents attempting to mediate their kids’ technology use. At the same time, experts highlight the importance of contextual factors like <a href="https://www.nature.com/articles/s41562-025-02134-4">existing mental health conditions</a>, <a href="https://onlinelibrary.wiley.com/doi/full/10.1002/jad.12193">socio-economic circumstances</a> and <a href="https://www.sciencedirect.com/science/article/pii/S0747563224000244">parental mediation</a> to understand the real-world effects of digital technologies.</p>
<p>Faced with this complexity, and mounting public pressure, policymakers around the world are urgently seeking ways to improve child safety online. Driven by a sense of time running out and promises of new <a href="https://www.schneier.com/blog/archives/2026/05/laurie-anderson-is-quoting-me.html">technical solutions</a> to difficult questions, this has led, <a href="https://avpassociation.com/map/">across jurisdictions</a>, to proposals to restrict young people’s access to certain technologies or platforms by introducing age assurance mandates.</p>
<p>Privacy and user empowerment have always formed a core part of Mozilla’s mission. As <a href="https://blog.mozilla.org/netpolicy/2025/12/19/australias-social-media-ban-why-age-limits-wont-fix-what-is-wrong-with-online-platforms/">we have said before</a>, we support safer spaces for minors, but we caution against approaches that rely on identity checks, surveillance-based enforcement, or exclusionary defaults. Such interventions rely on the collection of personal and sensitive data and, thus, introduce major new privacy and security risks.</p>
<p>While many technologies exist to verify, estimate, or infer users’ ages, fundamental tensions around accessibility, their effectiveness and effects on user’s privacy, security and free expression <a href="https://kgi.georgetown.edu/wp-content/uploads/2026/01/Age_Assurance_Online_Technical-Assessment_Report_KGI.pdf">remain</a>. Technological approaches must be part of wider efforts to address the root causes of online harms. However, the deployment of age assurance technologies will not solve the complex challenge of preparing young people to navigate an increasingly online world and ensure their wellbeing. That will require more holistic approaches: offering education and support to navigate the web safely, addressing harmful business practices and acknowledging the offline factors shaping children’s lives including social inequality, poverty or disparate access to (mental) health care services.</p>
<p><em><b>Ineffective age-gating mandates and the dangerous shift toward VPN restrictions</b></em></p>
<p>As jurisdictions around the world gain experience with government-mandated age gates for certain services, evidence is mounting that age restrictions are not an effective policy tool. Avoiding age gates is widespread and trivially easy: In Australia, where minors under 16 year of age have been banned from certain social media platforms since December 2025, the government’s Compliance Update <a href="https://www.esafety.gov.au/sites/default/files/2026-03/SocialMediaMinimumAgeComplianceUpdateMarch2026.pdf?v=1775600939713">reports</a> that seven out of ten young Australians remain online, often skirting age checks by simply entering a fake birthdate. A recent <a href="https://www.internetmatters.org/wp-content/uploads/2026/04/Internet-Matters-Online-Safety-Act-Report-May-2026.pdf">study</a> on the implementation of the UK’s Online Safety Act found that a third of children have bypassed age gates with fairly trivial steps like faking their birthdate, borrowing someone else’s login credentials, or even drawing on facial hair, and that a quarter of parents have helped their children to bypass age assurance systems. In the US, <a href="https://www.ftc.gov/sites/default/files/documents/public_comments/massachusetts-00243%C2%A0/00243-82161.pdf">studies</a> indicate that as far back as 2011, 64% of parents who were aware their child under 13 had a social media account were also ones who helped them create that account.</p>
<p>Confronted with the apparent ineffectiveness of age gates, policymakers around the world seem to be shifting their attention to alleged circumvention tools. While <a href="https://www.internetmatters.org/wp-content/uploads/2026/04/Internet-Matters-Online-Safety-Act-Report-May-2026.pdf">research</a> shows that many young people bypass age barriers by using other people’s devices and accounts or tricking age estimation tools by making themselves look older, virtual private networks (VPNs) are <a href="https://www.europarl.europa.eu/RegData/etudes/ATAG/2026/782618/EPRS_ATA(2026)782618_EN.pdf">increasingly</a> <a href="https://www.bbc.com/news/articles/cn438z3ejxyo">framed</a> as primarily a “loophole” to age gates. VPNs create encrypted “tunnels” between a user’s device and the internet, protecting all internet traffic from that device and concealing users’ IP addresses. VPNs are an essential privacy and security resource for millions of users worldwide, <a href="https://home.crin.org/the-big-debates/vpns-for-children">including young people</a>.</p>
<p><a href="https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week">Utah’s recent age verification law</a> holds websites hosting age-restricted content liable for verifying the age of anyone physically located in Utah, including individuals using VPNs or proxies. While the law does not ban VPNs outright, it forces websites to either block known VPN IP addresses or verify the age of every visitor globally. In the UK, policymakers <a href="https://www.bbc.com/news/articles/c9824zvpz9po">debated</a> <a href="https://www.bbc.com/news/articles/cn438z3ejxyo">age gates</a> for VPNs extensively, but <a href="https://www.bbc.com/news/articles/c982857nlrlo">stopped short</a> of restricting VPNs after <a href="https://www.gov.uk/government/publications/childrens-circumvention-behaviours-online?utm_medium=email&amp;utm_campaign=govuk-notifications-topic&amp;utm_source=97439257-1368-42dd-835e-2ecc1f690097&amp;utm_content=immediately">new evidence</a> <a href="https://vpntrust.net/2026/07/08/new-yougov-research-finds-vpns-are-not-widely-used-by-children-to-avoid-age-checks/?msg_pos=1">confirmed</a> that VPNs are not a relevant pathway for children seeking to bypass age checks. In Brazil, the ECA Digital law <a href="https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2026/decreto/d12880.htm">empowers</a> the regulatory authority to order technical countermeasures against circumvention tools such as VPNs. These developments suggest a worrying trend: well-meaning but ineffective attempts to protect children risk undermining the fundamental rights to privacy, security, and free expression of all users, as well as the health and openness of the web itself.</p>
<p>We are convinced, however, that there are rights-respecting alternatives policymakers can pursue to empower young people online and improve their safety and well-being.</p>
<p><em><strong>Moving beyond access bans</strong></em></p>
<p>We strongly believe that online safety frameworks should be grounded in <a href="https://www.unicef.org/innovation/stories/protecting-childrens-rights-in-digital-environments">children’s rights</a>, striking a balance between their right to protection and their right to participate in society, express themselves freely, and access media and information. Such frameworks must also be proportionate and should not undermine the fundamental rights and access to tools like VPNs for all users.</p>
<p>Rather than focusing on limiting access, we believe that policymakers should prioritize interventions that tackle the root causes of online harm. Before considering new instruments, this work starts with ensuring that independent regulatory authorities have the necessary resources to enforce existing online safety frameworks. In Europe, preliminary findings against <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1579">Meta</a> and <a href="https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-tiktoks-addictive-design-breach-digital-services-act">TikTok</a> find these companies’ addictive design features to be in breach of the Digital Services Act, underlining the potential of frameworks like the DSA to address key concerns.</p>
<p>The design of online interfaces, and the affordances and constraints they offer, significantly influences users’ interactions, decisions and overall wellbeing. ‘Dark patterns’ or deceptive interfaces are key drivers of harms experienced by users, and especially young people: they can compel people to consent to extensive data collection and processing, resulting in hyper-personalized feeds, personalized ads that may exploit cognitive vulnerabilities and promote unhealthy or excessive consumer choices, and an overall erosion of privacy.</p>
<p>This is why we support proposals like <a href="https://blog.mozilla.org/netpolicy/2025/10/31/pathways-to-a-fairer-digital-world-mozilla-shares-views-on-the-eu-digital-fairness-act/">EU Digital Fairness Act (DFA) </a>and the <a href="https://blog.mozilla.org/netpolicy/2026/06/11/a-handful-of-companies-control-the-web-aicoa-can-change-that/">American Innovation and Choice Online Act (AICOA)</a> that could fill regulatory gaps. Specifically, we advocate for the <b>prohibition of harmful design</b>, guided by harmonized definitions of core concepts like “dark patterns”, “deceptive design,” and “addictive design” and anti-circumvention clauses to prevent companies from avoiding regulation through small tweaks. Platforms should be responsible for demonstrating that their design choices are fair, non-manipulative and non-exploitative. And services that are likely to be accessed by children should be required to refrain from enabling certain design features, including excessive notifications, endless feeds and gambling-like features by default, and only with parental consent.</p>
<p>Further, we urge policymakers to adopt a <b>privacy-first approach to online harms</b>. Many of the risks encountered by young people online are related to the collection and processing of personal data. Platforms collect enormous amounts of personal data, including sensitive data, to personalize and target services, ranging from algorithmic recommender systems to online ads. While the systems that target and display ads and curate online content are distinct, both are based on the surveillance and profiling of users.</p>
<p>Such profiling is the basis for young people being targeted with personalized ads and content recommendations, which can segment, exclude, or steer people into inequitable options and towards harmful content. Providers should thus be prohibited from using sensitive personal data (e.g. ethnicity, religious belief, health status, sexual orientation, political affiliation) to personalize content recommendations or ads, and they should be mandated to enable privacy-protective settings by default, including restricting access to users’ location, camera, microphone, contacts, and camera roll. Policymakers should also extend the fairness and transparency obligations to personalization systems and advertising actors, including intermediaries and data brokers.</p>
<p>Additionally, everyone online, including families and young people, should be fully in control of their online experiences and navigate the web according to their preferences and needs. There is a significant opportunity to <b>empower users with easy, effective opt-out rights and granular user controls</b>. In practice, users should have the right to opt out of personalized content and targeting without being penalized with a downgraded version of the service. Some frameworks already strengthen choice – in those cases, we advocate for their robust enforcement.</p>
<p>Across jurisdictions, choice can be strengthened by ensuring that preferences explicitly expressed (e.g. settings selected, feedback signals, customization choices made, survey responses) are respected and “sticky”, so do not get reset without being explicitly requested by the user. Interoperability mandates should let people integrate third-party content moderation systems or recommendation algorithms that better match their preferences and help them break out of the walled gardens of a few dominant companies. Parental controls are another important lever to operationalize user controls: Providers should deploy easy-to-use and effective parental controls that allow families to tailor online experiences to their preferences, across platforms.</p>
<p>We appreciate that this is a long list of complex policy recommendations which are also impacted by broader (geo)political developments. The fact remains that current age assurance approaches are not a silver bullet, and will create more, rather than solve, problems in the long term.</p>
<p>Where policymakers consider age signals as necessary to ensure age-appropriate online experiences, we believe that there are technical approaches better suited to balance users’ rights than those currently pursued. We will explore these developments and approaches in the second part of this series.</p>
<p>The post <a href="https://blog.mozilla.org/netpolicy/2026/07/17/beyond-technical-fixes-protecting-kids-online-without-breaking-the-internet/">Beyond technical fixes: Protecting kids online without breaking the internet </a> appeared first on <a href="https://blog.mozilla.org/netpolicy">Open Policy &amp; Advocacy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TikTok Age Verification Under Investigation as UK Tightens Child Safety Rules]]></title>
<description><![CDATA[The UK's communications regulator has launched a formal investigation into TikTok age verification, raising questions over whether the platform is adequately protecting children online under the country's Online Safety Act. The move comes as Britain prepares to introduce a social media ban for un...]]></description>
<link>https://tsecurity.de/de/3675156/it-security-nachrichten/tiktok-age-verification-under-investigation-as-uk-tightens-child-safety-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675156/it-security-nachrichten/tiktok-age-verification-under-investigation-as-uk-tightens-child-safety-rules/</guid>
<pubDate>Fri, 17 Jul 2026 07:53:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="TikTok age verification" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification.webp 1536w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification.webp 1536w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/TikTok-age-verification-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="TikTok Age Verification Under Investigation as UK Tightens Child Safety Rules 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="405" data-end="878">The UK's communications regulator has launched a formal investigation into TikTok age verification, raising questions over whether the platform is adequately protecting children online under the country's <a href="https://thecyberexpress.com/uk-online-age-checks-are-failing/" target="_blank" rel="noopener">Online Safety Act</a>. The move comes as Britain prepares to introduce a <a href="https://thecyberexpress.com/uk-social-media-ban-set-for-2027-rollout/" target="_blank" rel="noopener">social media ban for under-16s</a>, with regulators warning that current age assurance methods used by some platforms may not be sufficient to prevent children from accessing harmful content.</p>
<p data-start="880" data-end="1113">The investigation follows the publication of a new <a href="https://thecyberexpress.com/ofcom-online-child-safety-rules/" target="_blank" rel="noopener">Ofcom</a> report that found age checks are becoming more common across online services, but significant gaps remain, particularly on social media platforms and some pornography websites.</p>

<h2 data-section-id="yy7t36" data-start="1115" data-end="1168"><span role="text"><strong data-start="1118" data-end="1168">Ofcom Questions TikTok Age Verification Method</strong></span></h2>
<p data-start="1170" data-end="1388">According to Ofcom, some social media companies rely primarily on age inference methods to identify child users. These systems estimate a user's age based on their online behavior rather than verifying it directly.</p>
<p data-start="1390" data-end="1750">The regulator <a href="https://www.ofcom.org.uk/online-safety/protecting-children/age-checks-helping-make-online-experiences-safer-for-uk-children-but-job-not-done-and-tech-industry-must-act-to-strengthen-protections" target="_blank" rel="nofollow noopener">said</a> it has "serious doubts" about whether these methods are capable of meeting the standards required under the Online Safety Act. Ofcom believes some companies may be failing to correctly identify a significant number of children, potentially exposing them to harmful content, including pornography, self-harm, and suicide-related material.</p>
<p data-start="1752" data-end="1907">As a result, Ofcom has launched a formal investigation into whether TikTok is complying with its legal duties to protect children from harmful content.</p>
<p data-start="1909" data-end="2249">The regulator also warned that age inference alone will not be considered sufficient for enforcing the government's planned restrictions on social media use by children under 16. Platforms using such methods have been urged to adopt more effective age assurance technologies or provide compelling evidence demonstrating their effectiveness.</p>

<h2 data-section-id="c7nu5l" data-start="2251" data-end="2300"><span role="text"><strong data-start="2254" data-end="2300">Age Checks Increase Across Online Services</strong></span></h2>
<p data-start="2302" data-end="2457">The report found significant progress in the adoption of age checks since the Online Safety Act's child protection duties came into force in July 2025.</p>
<p data-start="2459" data-end="2589">Between July 2025 and January 2026, the proportion of children encountering highly effective age checks increased from 25% to 43%.</p>
<p data-start="2591" data-end="2783">Ofcom said more than 69 million age checks were completed across a sample of 32 UK services during the second half of 2025, representing a 23-fold increase compared to the previous six months.</p>
<p data-start="2785" data-end="2930">The regulator also reported that all of the UK's top 10 pornography websites and most of the top 100 now have age verification measures in place.</p>
<p data-start="2932" data-end="3209">Among children aged 8 to 14 who attempted to access pornography, only 8% visited such services. Half of those children reached only websites with age checks, while nearly 87% of their visits lasted less than 30 seconds, suggesting age verification discouraged continued access.</p>

<h2 data-section-id="1ukhku3" data-start="3211" data-end="3251"><span role="text"><strong data-start="3214" data-end="3251">Search Engines Also Face Scrutiny</strong></span></h2>
<p data-start="3253" data-end="3428">Despite the wider rollout of age assurance, Ofcom found that children can still easily discover <a href="https://thecyberexpress.com/breachforums-admin-pompompurin-pleaded-guilty/" target="_blank" rel="noopener">pornography</a> websites without age checks through Google Search and Bing.</p>
<p data-start="3430" data-end="3608">Its analysis found that 33% of first-page Google search results and 54% of Bing results directed users to pornography websites lacking age verification or equivalent protections.</p>
<p data-start="3610" data-end="3781">Following discussions with the regulator, Google and Bing have agreed to work with Ofcom on practical measures to reduce the visibility of such websites in search results.</p>
<p data-start="3783" data-end="4049">Meanwhile, Ofcom continues enforcement against adult services that fail to comply with the law. The regulator has opened 23 investigations involving 88 adult service providers, with many either introducing age assurance or blocking UK users after enforcement action.</p>

<h2 data-section-id="1fml1dm" data-start="4051" data-end="4104"><span role="text"><strong data-start="4054" data-end="4104">UK Moves Toward Social Media Ban for Under-16s</strong></span></h2>
<p data-start="4106" data-end="4249">The investigation comes as the UK government advances plans to introduce a social media ban for under-16s, modeled on Australia's approach.</p>
<p data-start="4251" data-end="4503"><a href="https://www.gov.uk/government/news/social-media-to-be-banned-for-under-16s-in-landmark-government-move-to-givekids-their-childhood-back" target="_blank" rel="nofollow noopener">Under the proposal</a>, platforms including <a href="https://thecyberexpress.com/tiktok-addictive-design-breaches/" target="_blank" rel="noopener">TikTok</a>, Snapchat, <a href="https://thecyberexpress.com/instagram-teen-accounts-for-young-users/" target="_blank" rel="noopener">Instagram</a>, Facebook, YouTube, and X would be prohibited from offering social media services to users under 16. Messaging services such as <a class="wpil_keyword_link" href="https://thecyberexpress.com/unknown-international-calls-whatsapp-scams/" title="WhatsApp" data-wpil-keyword-link="linked" data-wpil-monitor-id="29008">WhatsApp</a> and Signal are not expected to be included.</p>
<p data-start="4505" data-end="4840">The government also plans to introduce additional protections, including restrictions on livestreaming and communication with strangers for children under 16 across social media and certain gaming platforms. Similar safeguards would apply by default to users aged 16 and 17 to avoid what officials describe as a "cliff-edge" at age 16.</p>
<p data-start="4842" data-end="4980">The proposed measures are expected to be presented to Parliament before the end of the year, with implementation targeted for Spring 2027.</p>
<p data-start="4982" data-end="5224">Ofcom said it will submit a rapid assessment to Parliament by the end of October outlining what constitutes highly effective age assurance for verifying whether someone is over 16, helping shape future enforcement of the planned restrictions.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Confirms Stillwater Season 5 Release Date, All Episodes Arrive This August]]></title>
<description><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The...]]></description>
<link>https://tsecurity.de/de/3675081/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675081/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The new season continues the award-winning story of siblings Karl, Addy, and Michael, whose wise panda neighbor helps them understand their feelings and look at difficult situations from a calmer perspective. Viewers can currently stream the first four seasons on Apple TV.



Here are the main details about the upcoming season:




Release date: Friday, August 21, 2026



Number of episodes: Five



Release schedule: All episodes will arrive together



Genre: Animated kids and family series



Start airing date: August 21, 2026



Finish date: August 21, 2026



Where to watch: Apple TV



Main voice cast: James Sie, Eva Ariel Binder, Tucker Chandler, and Judah Mackey




What is Stillwater season 5 about?







Stillwater follows Karl, Addy, and Michael as they deal with problems that feel familiar to young viewers, including disappointment, uncertainty, disagreements, and fear of trying something new.



Their neighbor Stillwater listens to their concerns and often shares a thoughtful story that helps them see the situation differently. His advice encourages the children to slow down, understand their emotions, and find their own way forward.



Season 5 will continue this familiar format through five new adventures. Each episode will focus on the children learning more about themselves, their relationships, and the world around them. The series remains inspired by Jon J Muth’s bestselling Zen book collection.



The first look at the season shows Stillwater returning alongside the three siblings, suggesting that the new episodes will maintain the peaceful visual style and warm storytelling that have defined the show since its 2020 debut.



There are currently no major plot details or episode descriptions available, so viewers will need to wait for a trailer or further announcements to learn which specific challenges Karl, Addy, and Michael will face.




https://www.youtube.com/watch?v=zz1GkcvkT1g




FAQs



When is the Stillwater season 5 release date?



Stillwater season 5 will premiere globally on Apple TV on Friday, August 21, 2026.



How many episodes are in Stillwater season 5?



The fifth season contains five new episodes. Apple TV will release all five episodes on the premiere date, allowing families to watch the full season immediately.



Will Stillwater season 5 release weekly?



No. All five episodes will become available together on August 21, 2026.



Who voices Stillwater in the animated series?



James Sie voices Stillwater. The main cast also includes Eva Ariel Binder as Addy, Tucker Chandler as Michael, and Judah Mackey as Karl.



Is Stillwater suitable for children?



Yes. Stillwater is an animated kids and family series that focuses on emotional awareness, mindfulness, kindness, and solving everyday problems.



Where can I watch the previous seasons?



All four previous seasons are available to stream on Apple TV before season 5 arrives.



Is Stillwater season 5 the final season?



Apple TV has announced the fifth season but has not officially described it as the final season. Its future beyond these five episodes remains unconfirmed.



Apple TV costs $12.99 per month in the United States after a seven-day free trial. With every new episode arriving on the same day, families can watch Stillwater season 5 at their own pace from August 21. Do you plan to watch the new season? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Pete Hegseth’s Plan for ‘High T’ Troops Is a Junk Science Fever Dream]]></title>
<description><![CDATA[The defense secretary’s idea of administering testosterone therapy to service members of the US Armed Forces reveals little understanding of the complexity of hormones.]]></description>
<link>https://tsecurity.de/de/3674868/it-nachrichten/pete-hegseths-plan-for-high-t-troops-is-a-junk-science-fever-dream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674868/it-nachrichten/pete-hegseths-plan-for-high-t-troops-is-a-junk-science-fever-dream/</guid>
<pubDate>Fri, 17 Jul 2026 02:47:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The defense secretary’s idea of administering testosterone therapy to service members of the US Armed Forces reveals little understanding of the complexity of hormones.]]></content:encoded>
</item>
<item>
<title><![CDATA[China Outlaws Virtual Intimacy in Sweep Against Companion Chatbots]]></title>
<description><![CDATA[China’s new AI companion rules restrict emotional dependency, require crisis protections, and impose safeguards for children and user data.]]></description>
<link>https://tsecurity.de/de/3674599/it-nachrichten/china-outlaws-virtual-intimacy-in-sweep-against-companion-chatbots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674599/it-nachrichten/china-outlaws-virtual-intimacy-in-sweep-against-companion-chatbots/</guid>
<pubDate>Thu, 16 Jul 2026 22:32:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[China’s new AI companion rules restrict emotional dependency, require crisis protections, and impose safeguards for children and user data.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ofcom, the UK's communications regulator, is investigating TikTok's child safety measures]]></title>
<description><![CDATA[The regulator is assessing whether the platform is doing enough to protect children from harmful content.]]></description>
<link>https://tsecurity.de/de/3673880/it-nachrichten/ofcom-the-uks-communications-regulator-is-investigating-tiktoks-child-safety-measures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673880/it-nachrichten/ofcom-the-uks-communications-regulator-is-investigating-tiktoks-child-safety-measures/</guid>
<pubDate>Thu, 16 Jul 2026 17:02:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The regulator is assessing whether the platform is doing enough to protect children from harmful content.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK investigation to determine if TikTok fails to protect children from harmful content]]></title>
<description><![CDATA[Ofcom concerned platform’s age verification is ineffective, leaving some at risk of seeing posts about self-harm and suicideTikTok is under formal investigation over concerns it has failed to protect children from harmful content, the UK’s online regulator, Ofcom, has announced.The social media p...]]></description>
<link>https://tsecurity.de/de/3672873/it-nachrichten/uk-investigation-to-determine-if-tiktok-fails-to-protect-children-from-harmful-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672873/it-nachrichten/uk-investigation-to-determine-if-tiktok-fails-to-protect-children-from-harmful-content/</guid>
<pubDate>Thu, 16 Jul 2026 11:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ofcom concerned platform’s age verification is ineffective, leaving some at risk of seeing posts about self-harm and suicide</p><p>TikTok is under formal investigation over concerns it has failed to protect children from harmful content, the UK’s online regulator, Ofcom, has announced.</p><p>The social media platform’s approach to checking the ages of users has sparked “particular concerns” at the watchdog, almost a year after measures to protect children from the worst of online content came into effect under <a href="https://www.theguardian.com/world/2025/jul/24/thursday-briefing-everything-you-need-to-know-about-the-new-internet-safety-rules">the Online Safety Act.</a></p> <a href="https://www.theguardian.com/technology/2026/jul/16/tiktok-uk-investigation-ofcom-child-protection-self-harm-suicide">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[xAI sues Grok user for generating nonconsensual sexualized deepfakes]]></title>
<description><![CDATA[xAI has filed a lawsuit against a man who used Grok to generate sexualized images of adults and children.]]></description>
<link>https://tsecurity.de/de/3672779/it-nachrichten/xai-sues-grok-user-for-generating-nonconsensual-sexualized-deepfakes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672779/it-nachrichten/xai-sues-grok-user-for-generating-nonconsensual-sexualized-deepfakes/</guid>
<pubDate>Thu, 16 Jul 2026 10:17:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[xAI has filed a lawsuit against a man who used Grok to generate sexualized images of adults and children.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Social media bans are likely to make things worse’: psychologist Candice Odgers on kids, tech and mental health]]></title>
<description><![CDATA[She has studied adolescent mental health for 25 years and fears the debate obscures some of the biggest issues facing teenagers – from the impact of Covid to the health of their adult caregiversThe quickest way to make being online safer for children and teens would be to kick all adult men off t...]]></description>
<link>https://tsecurity.de/de/3672299/ai-nachrichten/social-media-bans-are-likely-to-make-things-worse-psychologist-candice-odgers-on-kids-tech-and-mental-health/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672299/ai-nachrichten/social-media-bans-are-likely-to-make-things-worse-psychologist-candice-odgers-on-kids-tech-and-mental-health/</guid>
<pubDate>Thu, 16 Jul 2026 06:02:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>She has studied adolescent mental health for 25 years and fears the debate obscures some of the biggest issues facing teenagers – from the impact of Covid to the health of their adult caregivers</p><p>The quickest way to make being online safer for children and teens would be to kick all adult men off the internet, the Canadian psychologist Candice Odgers believes. Men are the biggest perpetrators of sextortion and most likely to spread misinformation, she says.</p><p>Odgers is not recommending this as a policy for governments to adopt: “That would be crazy, right? It would be unfair.” But she is on a drive to puncture the prevailing narrative that the best way to address online harms is a social media ban for teenagers.</p> <a href="https://www.theguardian.com/society/2026/jul/16/psychologist-candice-odgers-kids-tech-mental-health-social-media-bans">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spotify just made managed accounts free for all parents, no Premium required]]></title>
<description><![CDATA[Spotify managed accounts are now available to many more families after Spotify removed the Premium subscription requirement for parents and guardians. Starting today, parents with a free Spotify account can create a managed account for their child in supported countries, making it easier to give ...]]></description>
<link>https://tsecurity.de/de/3671486/ios-mac-os/spotify-just-made-managed-accounts-free-for-all-parents-no-premium-required/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671486/ios-mac-os/spotify-just-made-managed-accounts-free-for-all-parents-no-premium-required/</guid>
<pubDate>Wed, 15 Jul 2026 19:25:41 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spotify managed accounts are now available to many more families after Spotify removed the Premium subscription requirement for parents and guardians. Starting today, parents with a free Spotify account can create a managed account for their child in supported countries, making it easier to give young listeners a safer music experience with built in parental controls.



Spotify managed accounts now available on free accounts



Spotify says parents can now create a free managed account for children under 13 in the United States, the United Kingdom, Australia, France, Germany, and the Netherlands, while more countries across Europe, Latin America, and other regions will receive the feature soon.




"Managed accounts let young listeners explore music only, while you control the experience."




Parents can add a child account from the Spotify home page by selecting Add account and then Add a child under 13. During setup, they can filter explicit content, block specific songs or artists, disable videos and Canvas, and protect the main account with a PIN when using a shared device.



Spotify says managed accounts keep a child's music activity separate from the parent's account, which means recommendations, playlists, and Spotify Wrapped stay independent. Children also receive personalized music features such as Discover Weekly and Daylist while remaining in a music only environment without access to podcasts or audiobooks.




"Profiles can't be followed or searched by other users" and managed accounts also have "no in app purchases."




The company explains that managed accounts work on phones, tablets, and speakers, and children do not need their own phone to use one. Parents can manage up to 10 child accounts on the free plan, while Premium Family subscribers can also assign available Family plan slots to managed accounts for ad free listening and offline downloads.



Spotify adds that managed accounts can become regular Spotify accounts once children reach the minimum age in their country, although parents must approve the change until the user turns 18.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK 16- and 17-year-olds to be encouraged to follow midnight social media curfew]]></title>
<description><![CDATA[Midnight to 6am block on some apps is latest stage of Labour’s bid to protect young people from online harmsSixteen and 17-year-olds are to be encouraged to observe a midnight social media curfew, in the latest stage of Labour’s bid “to protect the next generation” from online harms, including po...]]></description>
<link>https://tsecurity.de/de/3669921/it-nachrichten/uk-16-and-17-year-olds-to-be-encouraged-to-follow-midnight-social-media-curfew/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669921/it-nachrichten/uk-16-and-17-year-olds-to-be-encouraged-to-follow-midnight-social-media-curfew/</guid>
<pubDate>Wed, 15 Jul 2026 09:48:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Midnight to 6am block on some apps is latest stage of Labour’s bid to protect young people from online harms</p><p>Sixteen and 17-year-olds are to be encouraged to observe a midnight social media curfew, in the latest stage of Labour’s bid “to protect the next generation” from online harms, including poor sleep caused by night-time scrolling.</p><p>From next spring, Britain’s oldest children will be urged to refrain from using certain apps with a midnight to 6am block being switched on by default. But the curfew will not be mandatory and can be overridden. The move is an extension of the under-16 social media ban announced last month, which included restrictions on platforms such as Snapchat, TikTok, YouTube, Instagram, Facebook and X.</p> <a href="https://www.theguardian.com/technology/2026/jul/14/uk-16-17-year-olds-midnight-social-media-curfew">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple wins major iCloud lawsuit after judge dismisses $32.8 billion CSAM case]]></title>
<description><![CDATA[Apple has won a proposed class action lawsuit that accused the company of failing to stop child sexual abuse material from being stored and shared through iCloud after a US federal judge ruled that the claims fall under legal protections provided by Section 230 of the Communications Decency Act. ...]]></description>
<link>https://tsecurity.de/de/3669876/ios-mac-os/apple-wins-major-icloud-lawsuit-after-judge-dismisses-328-billion-csam-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669876/ios-mac-os/apple-wins-major-icloud-lawsuit-after-judge-dismisses-328-billion-csam-case/</guid>
<pubDate>Wed, 15 Jul 2026 09:23:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has won a proposed class action lawsuit that accused the company of failing to stop child sexual abuse material from being stored and shared through iCloud after a US federal judge ruled that the claims fall under legal protections provided by Section 230 of the Communications Decency Act. 



The decision ends the current case with prejudice, which means the same lawsuit cannot be filed again, although the plaintiffs are considering an appeal.



According to Reuters, US District Judge Noël Wise ruled that Apple cannot be held legally responsible for content created and shared by users on its platform. The lawsuit claimed Apple failed to take action to prevent images of childhood sexual abuse from continuing to circulate through iCloud, but the court concluded that federal law broadly shields online services from this type of claim.



Judge says Congress must address the issue



The lawsuit was filed in 2024 by two survivors identified as Amy and Jessica, who argued that Apple knew child sexual abuse material continued to appear on iCloud but chose not to use available detection tools. They also criticized Apple's decision to abandon its planned NeuralHash system after announcing it in 2021. Court filings estimated the proposed class included about 2,680 people and sought compensatory damages of up to $32.8 billion, along with changes to Apple's iCloud policies.



Judge Noël Wise wrote:




"Nothing in federal law requires Apple to proactively utilize available technology or develop new technology to identify and report child sexual abuse material on its cloud platform. Lawmakers can fix this problem that is contributing to the exploitation of children. This Court cannot."




Reuters reported that Apple argued it adopted different methods instead of NeuralHash because it wanted to reduce risks to user privacy and security. The company has also maintained that it continues working to combat the spread of child sexual abuse material across its products and services.



James Marsh, the attorney representing the plaintiffs, said the legal team is reviewing its options after the dismissal.




"While the plaintiffs disagree with the judge's conclusion on the law, we agree with her conclusion that Congress should do more to protect children online and address the skyrocketing harms from online exploitation."




Although this case has ended, Apple still faces a separate lawsuit filed by West Virginia's attorney general over similar allegations involving child sexual abuse material on iCloud.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU Sets Out Plans For Social Media Restrictions]]></title>
<description><![CDATA[European Commission to propose phased approach to allowing children access to social media, amid pressure from member states on safety This article has been indexed from Silicon UK Read the original article: EU Sets Out Plans For Social Media Restrictions
Read more →
The post EU Sets Out Plans Fo...]]></description>
<link>https://tsecurity.de/de/3669756/it-security-nachrichten/eu-sets-out-plans-for-social-media-restrictions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669756/it-security-nachrichten/eu-sets-out-plans-for-social-media-restrictions/</guid>
<pubDate>Wed, 15 Jul 2026 08:38:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>European Commission to propose phased approach to allowing children access to social media, amid pressure from member states on safety This article has been indexed from Silicon UK Read the original article: EU Sets Out Plans For Social Media Restrictions</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/eu-sets-out-plans-for-social-media-restrictions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/eu-sets-out-plans-for-social-media-restrictions/">EU Sets Out Plans For Social Media Restrictions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The UK Is Planning a Social Media Curfew for 16- and 17-Year-Olds]]></title>
<description><![CDATA[The restrictions, which can be turned off, will include a crackdown on “addictive” app features and will be in addition to a total ban on children under 16 accessing platforms like TikTok and YouTube.]]></description>
<link>https://tsecurity.de/de/3669188/it-nachrichten/the-uk-is-planning-a-social-media-curfew-for-16-and-17-year-olds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669188/it-nachrichten/the-uk-is-planning-a-social-media-curfew-for-16-and-17-year-olds/</guid>
<pubDate>Wed, 15 Jul 2026 00:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The restrictions, which can be turned off, will include a crackdown on “addictive” app features and will be in addition to a total ban on children under 16 accessing platforms like TikTok and YouTube.]]></content:encoded>
</item>
<item>
<title><![CDATA[No, it's not age verification — privacy is the top reason UK children use a VPN]]></title>
<description><![CDATA[Independent research commissioned by the UK Government found that between just 7 and 10% of  British children use a VPN to bypass age verification]]></description>
<link>https://tsecurity.de/de/3668701/it-nachrichten/no-its-not-age-verification-privacy-is-the-top-reason-uk-children-use-a-vpn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668701/it-nachrichten/no-its-not-age-verification-privacy-is-the-top-reason-uk-children-use-a-vpn/</guid>
<pubDate>Tue, 14 Jul 2026 18:57:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Independent research commissioned by the UK Government found that between just 7 and 10% of  British children use a VPN to bypass age verification]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Warns Parents: Limit Online Sharing of Kids’ Photos Amid AI Abuse Risks]]></title>
<description><![CDATA[  UK authorities have issued urgent warnings to parents about sharing children’s photos online, as AI tools increasingly enable digital abuse and exploitation. The National Crime Agency (NCA) and the Internet Watch Foundation (IWF) say that ordinary images of kids…
Read more →
The post UK Warns P...]]></description>
<link>https://tsecurity.de/de/3668338/it-security-nachrichten/uk-warns-parents-limit-online-sharing-of-kids-photos-amid-ai-abuse-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668338/it-security-nachrichten/uk-warns-parents-limit-online-sharing-of-kids-photos-amid-ai-abuse-risks/</guid>
<pubDate>Tue, 14 Jul 2026 16:38:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  UK authorities have issued urgent warnings to parents about sharing children’s photos online, as AI tools increasingly enable digital abuse and exploitation. The National Crime Agency (NCA) and the Internet Watch Foundation (IWF) say that ordinary images of kids…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/uk-warns-parents-limit-online-sharing-of-kids-photos-amid-ai-abuse-risks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/uk-warns-parents-limit-online-sharing-of-kids-photos-amid-ai-abuse-risks/">UK Warns Parents: Limit Online Sharing of Kids’ Photos Amid AI Abuse Risks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The UK wants to catch up in the global AI race – but is too wary of risks to go all-in]]></title>
<description><![CDATA[UK fears a ‘triple whammy’: oversized investment in AI stocks, slower adoption of AI than predicted and the breakneck pace of AI’s developmentHello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today, we’re discussing the UK’s difficult position in th...]]></description>
<link>https://tsecurity.de/de/3668192/it-nachrichten/the-uk-wants-to-catch-up-in-the-global-ai-race-but-is-too-wary-of-risks-to-go-all-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668192/it-nachrichten/the-uk-wants-to-catch-up-in-the-global-ai-race-but-is-too-wary-of-risks-to-go-all-in/</guid>
<pubDate>Tue, 14 Jul 2026 16:02:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UK fears a ‘triple whammy’: oversized investment in AI stocks, slower adoption of AI than predicted and the breakneck pace of AI’s development</p><p>Hello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today, we’re discussing the UK’s difficult position in the AI race, new doubts over OpenAI’s path toward a trillion-dollar stock market debut and the changes to IRL tech reporting in the age of AI.</p><p><a href="https://www.theguardian.com/commentisfree/2026/jul/08/chatgpt-ai-therapy">My patients use ChatGPT for therapy. Now I use it too | Sarah Darghouth | The Guardian</a></p><p><a href="https://www.theguardian.com/technology/ng-interactive/2026/jul/12/software-developers-engineers-ai">Chasing new skills, going back to basics and pushing for collective action: how software engineers are adapting to AI</a></p> <a href="https://www.theguardian.com/technology/2026/jul/13/uk-catch-up-global-ai-race-risks">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[VPN firms and digital rights groups join forces to urge the UK government to leave VPNs alone]]></title>
<description><![CDATA[A coalition of over 20 digital rights groups and tech firms, including Amnesty International, NordVPN, and Mozilla, warns that plans to age-gate or restrict VPNs will severely compromise national cybersecurity while doing little to keep children safe.]]></description>
<link>https://tsecurity.de/de/3668148/it-nachrichten/vpn-firms-and-digital-rights-groups-join-forces-to-urge-the-uk-government-to-leave-vpns-alone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668148/it-nachrichten/vpn-firms-and-digital-rights-groups-join-forces-to-urge-the-uk-government-to-leave-vpns-alone/</guid>
<pubDate>Tue, 14 Jul 2026 15:47:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A coalition of over 20 digital rights groups and tech firms, including Amnesty International, NordVPN, and Mozilla, warns that plans to age-gate or restrict VPNs will severely compromise national cybersecurity while doing little to keep children safe.]]></content:encoded>
</item>
<item>
<title><![CDATA[Safety Regulators Press Tech Companies To Fix Sextortion Flaws]]></title>
<description><![CDATA[An online safety regulator in Australia says big technology platforms need to do much more to protect young people from sexual extortion. According to the eSafety Commission, teenagers are facing a massive wave of attacks where bad actors trick them into sharing private photos and then demand mon...]]></description>
<link>https://tsecurity.de/de/3668024/ios-mac-os/safety-regulators-press-tech-companies-to-fix-sextortion-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668024/ios-mac-os/safety-regulators-press-tech-companies-to-fix-sextortion-flaws/</guid>
<pubDate>Tue, 14 Jul 2026 15:10:00 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An online safety regulator in Australia says big technology platforms need to do much more to protect young people from sexual extortion. According to the eSafety Commission, teenagers are facing a massive wave of attacks where bad actors trick them into sharing private photos and then demand money. More than ten percent of teens between sixteen and eighteen have fallen victim to this crime, often starting before they turn sixteen.



Platforms must find clear ways to block repeat offender scripts



The latest report points fingers at several large companies, noting that Google and Meta fall short in catching these bad actors. Scammers typically pose as teens to build trust, send a fake explicit picture, and ask for one in return. Once the victim replies, the scammer threatens to send the images to family and friends unless a payment is made.



The core issue involves how these apps handle text monitoring. "The specific failure named is language analysis. Sexual extortion offenders work from recognisable scripts, the same coercive phrases repeated across thousands of approaches, and the report says platforms are not deploying the technology that would spot them."



The regulator stated that apps like WhatsApp often lack clear reporting buttons for sexual extortion. Apple also caught criticism over how iMessage handles these threats. The safety group suggested the company could scan for these common scam phrases directly on the iPhone without breaking user privacy. 



Apple already uses similar on-device scanning to blur nude photos sent to children. Recent test versions of its mobile software show the company might be testing a malicious message detection feature to solve this exact problem.



For now, safety groups are making it clear that the technology industry holds the tools to stop these scams at the source. If a company steps up and uses the tracking methods already available to it, it can cut off these extortion scripts before the messages ever reach a teenager's screen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Let’s build a children’s public internet]]></title>
<description><![CDATA[An increasing number of people seem to agree the internet is terrible for children - allegedly addictive, destructive to self-esteem, possibly a portal to predators. Over the past year, several countries have started requiring stringent age verification or outright bans for minors. At the end of ...]]></description>
<link>https://tsecurity.de/de/3667694/it-nachrichten/lets-build-a-childrens-public-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667694/it-nachrichten/lets-build-a-childrens-public-internet/</guid>
<pubDate>Tue, 14 Jul 2026 13:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An increasing number of people seem to agree the internet is terrible for children - allegedly addictive, destructive to self-esteem, possibly a portal to predators. Over the past year, several countries have started requiring stringent age verification or outright bans for minors. At the end of June in the US, the House of Representatives passed […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Pinwheel launches a retro-inspired landline phone for kids]]></title>
<description><![CDATA[Kid-friendly tech company Pinwheel announced the launch of a new landline phone designed to let children stay connected without the distractions of a smartphone.]]></description>
<link>https://tsecurity.de/de/3667373/it-nachrichten/pinwheel-launches-a-retro-inspired-landline-phone-for-kids/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667373/it-nachrichten/pinwheel-launches-a-retro-inspired-landline-phone-for-kids/</guid>
<pubDate>Tue, 14 Jul 2026 11:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kid-friendly tech company Pinwheel announced the launch of a new landline phone designed to let children stay connected without the distractions of a smartphone.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU to Review Social Media Age Limits After Child Safety Report]]></title>
<description><![CDATA[The European Commission is moving closer to introducing new measures on Child Safety Online after President Ursula von der Leyen received recommendations from a Special Panel examining the impact of social media on children. The report, released Monday, calls for stronger safeguards, greater plat...]]></description>
<link>https://tsecurity.de/de/3666978/it-security-nachrichten/eu-to-review-social-media-age-limits-after-child-safety-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666978/it-security-nachrichten/eu-to-review-social-media-age-limits-after-child-safety-report/</guid>
<pubDate>Tue, 14 Jul 2026 08:10:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Child Safety Online" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="EU to Review Social Media Age Limits After Child Safety Report 1"></p><p data-start="371" data-end="819">The European Commission is moving closer to introducing new measures on <a href="https://thecyberexpress.com/ofcom-online-child-safety-rules/" target="_blank" rel="noopener">Child Safety Online</a> after President Ursula von der Leyen received recommendations from a Special Panel examining the <a href="https://thecyberexpress.com/uk-social-media-ban-set-for-2027-rollout/" target="_blank" rel="noopener">impact of social media</a> on children. The report, released Monday, calls for stronger safeguards, greater platform accountability, and age-appropriate restrictions as the EU prepares to review the findings and present legislative proposals after the summer.</p>
<p data-start="821" data-end="1144">Speaking alongside the panel's co-chairs, von der Leyen said protecting children online has become one of the most pressing challenges facing governments. She stressed that parents, not algorithms, should shape children's development and warned that the current digital environment is exposing young users to growing <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28954">risks</a>.</p>

<h3 data-section-id="h0xe6l" data-start="1146" data-end="1202"><strong><span role="text">Child Safety Online Becomes a Priority for the EU</span></strong></h3>
<p data-start="1204" data-end="1584">Von der Leyen <a href="https://ec.europa.eu/commission/presscorner/detail/en/statement_26_1590" target="_blank" rel="nofollow noopener">said</a> the Special Panel examined both the opportunities and harms created by social media algorithms and their effects on children. According to the findings highlighted in her statement, young people across Europe now spend between four and six hours each day on screens, while nearly 60% of young children have experienced emotional or psychosocial problems online.</p>
<p data-start="1586" data-end="1797">She said these challenges include loss of sleep, anxiety, depression, <a href="https://thecyberexpress.com/ai-vs-cyberbullying-protecting-the-vulnerable/" target="_blank" rel="noopener">cyberbullying</a>, exposure to harmful content, and unwanted online interactions, all occurring while children's brains are still developing.</p>
<p data-start="1799" data-end="1983">"We believe that parents bring up our kids, and not predatory algorithms," von der Leyen said, adding that social media platforms should no longer have unrestricted access to children.</p>

<h3 data-section-id="1e4yfwu" data-start="1985" data-end="2047"><strong><span role="text">Digital Services Act Places Responsibility on Platforms</span></strong></h3>
<p data-start="2049" data-end="2297">A key recommendation focuses on holding technology companies accountable for the safety of their services. Von der Leyen said platforms that build online systems should also be responsible for ensuring they do not harm users, particularly children.</p>
<p data-start="2299" data-end="2513">She pointed to the Digital Services Act (DSA) as the EU's framework for requiring providers to remove harmful features, including addictive algorithms, dark patterns, harmful content, and unwanted contacts.</p>
<p data-start="2515" data-end="2803">According to the Commission President, the EU has already taken action under the Digital Services Act against <a href="https://thecyberexpress.com/tiktok-addictive-design-breaches/" target="_blank" rel="noopener">TikTok</a> over its addictive design and recently against Meta. She said platforms have a duty of care toward users and must respond quickly when children report harmful experiences.</p>

<h3 data-section-id="1334s9i" data-start="2805" data-end="2854"><strong><span role="text">EU Considers Social Media Age Restrictions</span></strong></h3>
<p data-start="2856" data-end="3091">The report also strengthens the case for introducing <a href="https://thecyberexpress.com/eu-age-verification-app/" target="_blank" rel="noopener">social media age restrictions</a>, with von der Leyen arguing that the debate is no longer about whether children use social media but when platforms should be allowed to reach them.</p>
<p data-start="3093" data-end="3294">She said the European Union's <a href="https://thecyberexpress.com/eu-age-verification-app/" target="_blank" rel="noopener">age verification app </a>is designed to help parents by providing an easy-to-use, privacy-preserving, and open-source tool to verify age before accessing online platforms.</p>
<p data-start="3296" data-end="3466">Von der Leyen also suggested that Europe should consider establishing a "social media start date," comparing it to existing age limits for driving and purchasing alcohol.</p>

<h3 data-section-id="al4wmm" data-start="3468" data-end="3521"><strong><span role="text">Panel Calls for Age-Appropriate Digital Access</span></strong></h3>
<p data-start="3523" data-end="3769">According to the statement, children under the age of three should have no exposure to screens or digital platforms. Older children should only access social media under parental, caregiver, or teacher supervision and within limited time periods.</p>
<p data-start="3771" data-end="4010">Von der Leyen said childhood is a critical stage of brain development and argued that children need opportunities to play, build real-world friendships, and develop their identities before algorithms begin shaping their online experiences.</p>
<p data-start="4012" data-end="4225">She added that policymakers should first identify platforms with age-inappropriate and addictive features, describing the category as "social media plus," before considering phased access for different age groups.</p>

<h3 data-section-id="m1ejl3" data-start="4227" data-end="4282"><strong><span role="text">EU to Review Recommendations Before New Proposal</span></strong></h3>
<p data-start="4284" data-end="4464">The <a href="https://thecyberexpress.com/european-commission-cyberattack/" target="_blank" rel="noopener">European Commission</a> said the report comes after consultations with parents, educators, experts, young people, EU member states, and international partners, including Australia.</p>
<p data-start="4466" data-end="4599">Von der Leyen confirmed that the Commission will now review the recommendations before presenting a formal proposal after the summer.</p>
<p data-start="4601" data-end="4876">While no legislative measures have yet been announced, the report signals the EU's intent to strengthen Child Safety Online protections by expanding platform accountability, improving age verification, and evaluating new rules governing children's access to social media.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Rolls Out iPadOS 27 Public Beta: How to Install and What’s New]]></title>
<description><![CDATA[Apple has released the first iPadOS 27 public beta, giving iPad users an early look at Siri AI, faster system performance, new Apple Intelligence tools, improved parental controls, and several useful app upgrades. The public beta is free, but users should create a backup before installing it beca...]]></description>
<link>https://tsecurity.de/de/3666614/ios-mac-os/apple-rolls-out-ipados-27-public-beta-how-to-install-and-whats-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666614/ios-mac-os/apple-rolls-out-ipados-27-public-beta-how-to-install-and-whats-new/</guid>
<pubDate>Tue, 14 Jul 2026 02:08:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first iPadOS 27 public beta, giving iPad users an early look at Siri AI, faster system performance, new Apple Intelligence tools, improved parental controls, and several useful app upgrades. The public beta is free, but users should create a backup before installing it because early software can contain bugs and affect battery life.



How to Install the iPadOS 27 Public Beta



Before updating, back up your iPad through iCloud or a Mac or PC. Apple also recommends testing beta software on a secondary device whenever possible.




Visit the Apple Beta Software Program website.



Select Sign Up or Sign In.



Use the same Apple Account connected to your iPad.



Accept the program terms and enrol your device.



Open Settings on your iPad.



Go to General &gt; Software Update &gt; Beta Updates.



Select iPadOS 27 Public Beta.



Return to the Software Update page and tap Update Now.




The first public beta matches the revised third developer beta released on July 13. Apple’s beta program is free and includes the Feedback Assistant app for reporting problems.



Everything New in the iPadOS 27 Public Beta




Siri AI: Apple’s redesigned assistant supports natural conversations, follow-up questions, personal context, onscreen awareness, web searches, and actions across supported apps. A dedicated Siri app stores conversations and lets users continue chats across Apple devices. Siri AI requires an iPad with an M1 chip or newer, or an iPad mini with the A17 Pro chip.



Write with Siri: Siri can create drafts, improve existing text, and offer feedback in apps where users type. In Mail and Messages, it can also match the user’s writing style, punctuation, and tone.



Visual Intelligence on iPad: Users can ask questions about anything displayed on the screen. They can tap an object with a finger or circle it using Apple Pencil to search for more information or take an action.



Smarter Notes tools: Siri can work with typed and handwritten notes. It can organise bullet points, create an agenda, summarise information, or turn handwritten lecture notes into a study guide.



Apple Intelligence in apps: Photos, Safari, Messages, Calendar, Shortcuts, and other Apple apps receive new AI features. Photos adds improved editing tools, while Safari can organise tabs and help users find information more quickly.



Faster system performance: Apple has improved memory use, CPU scheduling, search, display rendering, and system responsiveness. Files should also handle large folders and external drives more efficiently, especially on newer iPad Pro models.



Liquid Glass improvements: iPadOS 27 refines the Liquid Glass design introduced with iPadOS 26. Updated controls, clearer backgrounds, stronger visual separation, and improved icon details should make the interface easier to read.



New child safety controls: Parents receive a redesigned dashboard for checking device activity and changing access quickly. Ask to Browse lets children request permission before opening restricted websites, while contact approval controls cover communication with new people.



Improved Shared Albums: Friends and family using Android or Windows can join albums and upload pictures through iCloud.com. Shared Albums also support full-resolution photos, reactions, filters, and additional invitation options.



Smarter Home features: Apple Intelligence can group related security camera notifications, describe recorded activity, and search clips using natural language. Compatible HomeKit Secure Video cameras can also stream and record in 4K with an eligible iCloud+ plan.




iPadOS 27 Compatible Devices



The iPadOS 27 public beta supports the following models:




iPad Pro 12.9-inch, 4th generation and newer



iPad Pro 11-inch, 2nd generation and newer



iPad Air, 4th generation and newer



iPad, 9th generation and newer



iPad mini, 6th generation and newer




However, Siri AI and other Apple Intelligence features require an iPad with an M1 chip or later, or the iPad mini with A17 Pro. Some advanced voice features require an M4 iPad with at least 12GB of unified memory.



Apple will continue updating the iPadOS 27 beta throughout the summer before releasing the final version later this year. Since this remains early software, users may experience app crashes, reduced battery life, heating, or compatibility problems.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Public Beta Is Now Available: Here’s Everything New]]></title>
<description><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility ...]]></description>
<link>https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</guid>
<pubDate>Tue, 14 Jul 2026 01:53:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility problems.



How to Install the iOS 27 Public Beta



Back up your iPhone through iCloud or a computer before installing the beta. Using a secondary device is safer because returning to iOS 26 can require erasing the iPhone.




Visit the Apple Beta Software Program website.



Sign in using the Apple Account connected to your iPhone.



Accept the program terms and enroll your account.



Open Settings on your iPhone.



Go to General &gt; Software Update &gt; Beta Updates.



Select iOS 27 Public Beta.



Return to the previous screen and tap Update Now.




Your iPhone must have enough available storage, a stable Wi-Fi connection, and sufficient battery power to complete the installation.



Everything New in the iOS 27 Public Beta




Siri AI: Siri now supports more natural conversations, follow-up questions, personal information searches, onscreen awareness, and actions across supported apps. A dedicated Siri app also stores previous conversations. Siri AI requires an iPhone that supports Apple Intelligence.



Visual Intelligence in Camera: Users can point the camera at real-world information and ask Siri for help. The system can identify details, extract information, create calendar events, and perform tasks such as reading a barcode or analysing a meal.



Faster iPhone performance: Apple has improved app launches, AirDrop transfers, photo processing, keyboard loading, unlocking, Home Screen navigation, and system animations. These improvements also apply to older supported models, including the iPhone 11 series.



Liquid Glass controls: iOS 27 refines the Liquid Glass design introduced with iOS 26. A new slider under Settings &gt; Appearance lets users adjust how clear or tinted the interface appears.



Smarter Safari tools: Safari can automatically group tabs and organize bookmarks by topic. It can also watch webpages for changes and help users create extensions through natural-language instructions.



New Photos editing features: The Photos app includes an improved Clean Up tool for removing larger distractions. Extend can generate content beyond the edges of a photo, while Spatial Reframing lets users adjust the apparent camera angle after taking a picture.



Natural-language Shortcuts: Users can describe an automation in everyday language, and the Shortcuts app will build it. Additional instructions can refine the automation without starting again.



Improved password security: The Passwords app can replace some weak or compromised passwords automatically. It can also manage verification codes and show the replacement process through a Live Activity.



Screen Time redesign: Parents receive a clearer activity dashboard, category-based time allowances, and schedules for school days, evenings, and weekends. Children can request permission before visiting certain websites or contacting new people.



More child safety features: Communication Safety can detect and blur sensitive images. iOS 27 expands these protections to include violent or graphic content.



AirPods custom equalizer: Compatible AirPods gain separate controls for low, mid, and high frequencies, giving users more control over how music and other audio sound.



Messages improvements: Large photos and videos can continue sending in the background without delaying newer messages. Group conversations also handle Tapback notifications more clearly.



Better Photos sharing: Shared Albums support full-resolution media, contributions from Windows and Android devices, keywords, star ratings, and customizable slideshows.



Independent alarm volume: Users can change alarm volume without changing the overall system volume.



Larger Home Screen widgets: New extra-large widgets can take up an entire Home Screen page and show more information at once.



Home app upgrades: The Home app adds improved HomeKit Secure Video reliability and support for compatible 4K security cameras.



Better network switching: iPhones can move between Wi-Fi and cellular data more quickly when the current connection becomes weak.




The iOS 27 public beta will receive more updates before the final version arrives later this year. Anyone testing the software can report bugs through the Feedback Assistant app.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe to Curb Children's Social Media Use With 'Phased' Age-Based Access]]></title>
<description><![CDATA[Instead of an outright ban, EU President Ursula von der Leyen is suggesting social media start dates that will allow kids gradual access to platforms.]]></description>
<link>https://tsecurity.de/de/3666363/it-nachrichten/europe-to-curb-childrens-social-media-use-with-phased-age-based-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666363/it-nachrichten/europe-to-curb-childrens-social-media-use-with-phased-age-based-access/</guid>
<pubDate>Mon, 13 Jul 2026 22:18:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Instead of an outright ban, EU President Ursula von der Leyen is suggesting social media start dates that will allow kids gradual access to platforms.]]></content:encoded>
</item>
<item>
<title><![CDATA[Social Media Limits Are Coming For Teens Across Europe]]></title>
<description><![CDATA[The European Union is considering major new restrictions on children's access to social media, including age limits, phased access, and an outright ban. "This is not about whether children can access social media," said European Commission President Ursula von der Leyen. "It is about when social ...]]></description>
<link>https://tsecurity.de/de/3665989/it-security-nachrichten/social-media-limits-are-coming-for-teens-across-europe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665989/it-security-nachrichten/social-media-limits-are-coming-for-teens-across-europe/</guid>
<pubDate>Mon, 13 Jul 2026 19:09:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The European Union is considering major new restrictions on children's access to social media, including age limits, phased access, and an outright ban. "This is not about whether children can access social media," said European Commission President Ursula von der Leyen. "It is about when social media can access our children." The Verge reports: Social media platforms could also be forced to prove their services are not harmful before young people are allowed to use them. European Commission President Ursula von der Leyen said the bloc's executive arm could propose new legislation within months, after reviewing recommendations from a panel of experts released today.
 
The panel recommended using a phased approach, including "no screens at all" for children under 3, supervised internet use for those under 13, and some limits for older teens. It also said social media platforms should have to prove their services are safe to younger users, an approach von der Leyen said she supports. Von der Leyen said the Commission will consider the report and return with proposals "after the summer." Any legislation would still need approval from the European Parliament and the EU's 27 member countries before becoming law across the bloc.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Social+Media+Limits+Are+Coming+For+Teens+Across+Europe%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F13%2F1638208%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F13%2F1638208%2Fsocial-media-limits-are-coming-for-teens-across-europe%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/13/1638208/social-media-limits-are-coming-for-teens-across-europe?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU Proposes Banning Social Media For Kids Under 13 With Phased Access]]></title>
<description><![CDATA[The European Union is preparing to introduce strict new rules to limit how young children interact with online platforms. Based on expert recommendations, the bloc plans to ban kids under 13 from using social media altogether. The proposed changes also outline a system for phased and gradual acce...]]></description>
<link>https://tsecurity.de/de/3665294/ios-mac-os/eu-proposes-banning-social-media-for-kids-under-13-with-phased-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665294/ios-mac-os/eu-proposes-banning-social-media-for-kids-under-13-with-phased-access/</guid>
<pubDate>Mon, 13 Jul 2026 14:54:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The European Union is preparing to introduce strict new rules to limit how young children interact with online platforms. Based on expert recommendations, the bloc plans to ban kids under 13 from using social media altogether. The proposed changes also outline a system for phased and gradual access for teenagers, marking a major shift in how governments handle digital safety and online well-being.



Platforms must prove their safety before teenagers gain gradual access



European Commission President Ursula von der Leyen recently shared that the focus should be on when social media can access children, rather than the other way around. Following advice from a special panel of doctors and youth experts, the plan calls for a strict cutoff date for when children can first create accounts. Kids under 13 would only be allowed to use these services for limited times under direct supervision from a parent or teacher.



Once a child turns 13, the restrictions will slowly begin to lift. However, this gradual access depends entirely on the platforms themselves. Tech companies will have to prove that their services are safe and age-appropriate before teenagers can use them freely. A formal legal proposal to enforce these rules across all member states is expected in the second half of the year.



The new digital rules target addictive designs from large companies



This new initiative builds on previous actions taken by European lawmakers to protect younger users. The region has already started targeting the addictive nature of modern apps. For example, lawmakers have warned large tech platforms about specific design choices that keep users hooked for hours.



Features like the infinite scrolling feeds found on Facebook and other sites might soon face heavy restrictions if they are proven harmful to mental health. The European Union has repeatedly pressured Meta and similar businesses to rethink how their apps operate. If these companies cannot show effective safety measures, popular apps like Instagram could be forced to change how they deliver content to younger audiences or face massive fines.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU weighs under-13 social media ban]]></title>
<description><![CDATA[Almost 60pc of young children across Europe experienced emotional or psychosocial problems online, von der Leyen said. 
Read more: EU weighs under-13 social media ban]]></description>
<link>https://tsecurity.de/de/3665207/it-nachrichten/eu-weighs-under-13-social-media-ban/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665207/it-nachrichten/eu-weighs-under-13-social-media-ban/</guid>
<pubDate>Mon, 13 Jul 2026 14:33:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Almost 60pc of young children across Europe experienced emotional or psychosocial problems online, von der Leyen said. </p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/eu-social-media-ban-under-13-child-safety-online-meta-x-facebook-instagram">EU weighs under-13 social media ban</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe takes step toward social media ban for kids]]></title>
<description><![CDATA[Following a worrying new report, Europe is taking steps toward barring children from using social media.]]></description>
<link>https://tsecurity.de/de/3665059/it-nachrichten/europe-takes-step-toward-social-media-ban-for-kids/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665059/it-nachrichten/europe-takes-step-toward-social-media-ban-for-kids/</guid>
<pubDate>Mon, 13 Jul 2026 13:17:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Following a worrying new report, Europe is taking steps toward barring children from using social media.]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe Takes Step Toward Possible Social Media Ban for Children]]></title>
<description><![CDATA[After the release of a new report, the European Commission is considering changing the rules across the 27-nation bloc.]]></description>
<link>https://tsecurity.de/de/3664907/it-nachrichten/europe-takes-step-toward-possible-social-media-ban-for-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664907/it-nachrichten/europe-takes-step-toward-possible-social-media-ban-for-children/</guid>
<pubDate>Mon, 13 Jul 2026 12:17:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After the release of a new report, the European Commission is considering changing the rules across the 27-nation bloc.]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe Takes Step Toward Possible Social Media Ban for Children]]></title>
<description><![CDATA[After the release of a new report, the European Commission is considering changing the rules across the 27-nation bloc.]]></description>
<link>https://tsecurity.de/de/3664813/it-nachrichten/europe-takes-step-toward-possible-social-media-ban-for-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664813/it-nachrichten/europe-takes-step-toward-possible-social-media-ban-for-children/</guid>
<pubDate>Mon, 13 Jul 2026 11:48:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After the release of a new report, the European Commission is considering changing the rules across the 27-nation bloc.]]></content:encoded>
</item>
<item>
<title><![CDATA[Social media limits are coming for teens across Europe]]></title>
<description><![CDATA[The European Union is weighing sweeping new restrictions on children's and teenagers' access to social media, including age limits, an outright ban, and phased access. Social media platforms could also be forced to prove their services are not harmful before young people are allowed to use them. ...]]></description>
<link>https://tsecurity.de/de/3664773/it-nachrichten/social-media-limits-are-coming-for-teens-across-europe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664773/it-nachrichten/social-media-limits-are-coming-for-teens-across-europe/</guid>
<pubDate>Mon, 13 Jul 2026 11:32:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The European Union is weighing sweeping new restrictions on children's and teenagers' access to social media, including age limits, an outright ban, and phased access. Social media platforms could also be forced to prove their services are not harmful before young people are allowed to use them. European Commission President Ursula von der Leyen said […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Cape Fear Episode 7 Sparks Wild Theories About Max Cady’s Children]]></title>
<description><![CDATA[Warning: Major spoilers for Cape Fear Episode 7.



Episode 7 of Cape Fear has sparked one of the biggest debates of the season after suggesting that Natalie could be Max Cady's daughter. The twist has left viewers questioning almost every relationship in the show, while many believe Max is simpl...]]></description>
<link>https://tsecurity.de/de/3664518/ios-mac-os/cape-fear-episode-7-sparks-wild-theories-about-max-cadys-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664518/ios-mac-os/cape-fear-episode-7-sparks-wild-theories-about-max-cadys-children/</guid>
<pubDate>Mon, 13 Jul 2026 09:23:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Warning: Major spoilers for Cape Fear Episode 7.



Episode 7 of Cape Fear has sparked one of the biggest debates of the season after suggesting that Natalie could be Max Cady's daughter. The twist has left viewers questioning almost every relationship in the show, while many believe Max is simply playing another psychological game.



Is Natalie Really Max Cady's Daughter?



The latest episode appears to confirm that Natalie may be Max's biological daughter after he gives her a beard hair for a DNA test. If that turns out to be true, it would also make her Nevaeh's half-sister, creating an uncomfortable layer to their earlier relationship.



However, many fans are not buying the reveal.



Across Reddit, viewers argue that Max has spent the entire season manipulating vulnerable people. Some believe he has been using emotional pressure, drugs, and carefully planned lies to convince both Natalie and Zack that he is their father. Others think the DNA sample is simply another part of his plan, either because Natalie will never complete the test or because the results will arrive too late to stop him.



That theory also fits Max's actions later in the episode. If he genuinely believed Natalie was his daughter, many viewers question why he would frame her for Ray Rawlins' murder and put her directly in danger.



Fans Are More Confused Than Ever



The family tree has become one of the biggest talking points online.



Some fans are convinced everyone somehow ends up connected to Max, while others think the writers are deliberately encouraging that confusion before revealing another twist. Reddit discussions are filled with theories ranging from fake paternity claims to psychological manipulation rather than actual biological relationships.



Many viewers expect the show to reveal that Max has been exploiting Natalie's search for answers instead of telling her the truth.



Javier Bardem Keeps Winning Fans



Despite the increasingly wild storyline, one thing viewers almost universally agree on is Javier Bardem's performance.



His version of Max Cady remains the strongest part of the series, with many fans admitting they have started rooting for him because he consistently outsmarts the Bowden family. Even viewers frustrated by the plot twists continue to watch largely because of Bardem's performance and the story's unpredictable direction.



Episode 7 Also Drew Criticism



While the paternity reveal dominated the discussion, viewers also pointed out several questionable moments.



Some criticized the characters for making unbelievable decisions, while others noticed a dialogue mistake in which a therapist uses "exasperated" instead of "exacerbated." Although it is a minor detail, fans questioned how the error remained in the finished episode.



Viewers Are Still Watching



Even with growing criticism, Cape Fear continues to keep audiences engaged.



Episode 7 has turned nearly every major relationship into a mystery, and fans are still debating whether Max is revealing long hidden truths or creating another elaborate deception. With several episodes still remaining, the biggest question has not changed. Is Max Cady finally telling the truth, or is this simply his most convincing lie yet?]]></content:encoded>
</item>
<item>
<title><![CDATA[European Parliament Revives Controversial Chat Scanning Law]]></title>
<description><![CDATA[The Chat Control 1.0 framework has been revived after the European Parliament voted to restore the legal basis that allows major technology companies to voluntarily scan users' private communications for Child Sexual Abuse Material (CSAM). The decision, taken on July 9, comes months after the tem...]]></description>
<link>https://tsecurity.de/de/3664301/it-security-nachrichten/european-parliament-revives-controversial-chat-scanning-law/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664301/it-security-nachrichten/european-parliament-revives-controversial-chat-scanning-law/</guid>
<pubDate>Mon, 13 Jul 2026 07:37:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chat Control" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="European Parliament Revives Controversial Chat Scanning Law 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="372" data-end="824">The Chat Control 1.0 framework has been revived after the <a href="https://thecyberexpress.com/european-parliament-data-breach/" target="_blank" rel="noopener">European Parliament</a> voted to restore the legal basis that allows major technology companies to voluntarily scan users' private communications for <a href="https://thecyberexpress.com/eu-csam-law-gap-child-sexual-exploitation-risk/" target="_blank" rel="noopener">Child Sexual Abuse Material</a> (CSAM). The decision, taken on July 9, comes months after the temporary regulation expired in April and has reignited debate over privacy, surveillance, and the future of online safety laws in the <a href="https://thecyberexpress.com/enisa-and-commission/" target="_blank" rel="noopener">European Union</a>.</p>
<p data-start="826" data-end="1186">The vote was held on the final sitting day before the Parliament's summer recess. Under an urgent legislative procedure, rejecting the proposal required an absolute majority of all Members of the European Parliament rather than a simple majority of those present. As a result, the proposal passed despite more lawmakers present voting against it than in favor.</p>

<h3 data-section-id="1jb6ks5" data-start="1188" data-end="1244"><strong><span role="text">Chat Control 1.0 Restores Voluntary CSAM Scanning</span></strong></h3>
<p data-start="1246" data-end="1501">The revived regulation, formally known as Regulation (EU) 2021/1232, provides the legal basis for online platforms to voluntarily scan private communications for known and new Child Sexual Abuse Material (CSAM) as well as the solicitation of children.</p>
<p data-start="1503" data-end="1727">The original regulation was introduced in 2021 as a temporary derogation from the ePrivacy Directive. It expired in April after lawmakers failed to agree on a long-term replacement amid widespread concerns over user <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="28928">privacy</a>.</p>
<p data-start="1729" data-end="2047">Although several technology companies continued voluntary scanning after the regulation lapsed, European authorities had warned that doing so without a legal basis could expose platforms to legal uncertainty. The restored framework does not authorize scanning on end-to-end encrypted messaging services such as Signal.</p>

<h3 data-section-id="1sydelx" data-start="2049" data-end="2084"><strong>Urgent Procedure Draws Criticism</strong></h3>
<p data-start="2086" data-end="2411">The <a href="https://cdt.org/insights/return-of-mass-scanning-of-private-communications-through-undemocratic-procedure/" target="_blank" rel="nofollow noopener">renewed proposal</a> followed an urgent legislative process that critics described as highly unusual. According to CDT Europe, the Parliament had previously rejected a similar proposal in March, but the issue returned through a fast-tracked second-reading procedure supported by European Parliament President Roberta Metsola.</p>
<p data-start="2413" data-end="2732">Because the proposal was treated as a second reading, opponents needed at least 361 votes to block it. While a simple majority supported rejecting the measure during voting, it did not reach the higher threshold required under the urgent procedure. Reduced attendance before the summer recess also affected the outcome.</p>
<p data-start="2734" data-end="2854">Only two amendments were adopted during the process, both aimed at preserving protections for <a href="https://thecyberexpress.com/eu-agrees-on-child-sexual-abuse-detection-law/" target="_blank" rel="noopener">end-to-end encryption</a>.</p>

<h3 data-section-id="12ev3io" data-start="2856" data-end="2905"><strong>Debate Continues Over Permanent CSAM Framework</strong></h3>
<p data-start="2907" data-end="3163">The revival of Chat Control 1.0 comes shortly after negotiations on the proposed Child Sexual Abuse Material Regulation (CSAR) ended without agreement on June 29. Discussions on the permanent framework are expected to resume after the summer break.</p>
<p data-start="3165" data-end="3464">CDT Europe argued that restoring the temporary regulation could complicate ongoing negotiations over the long-term legislative framework. The organization said questions surrounding voluntary or mandatory scanning require careful legal and technical assessment before permanent rules are introduced.</p>

<h3 data-section-id="qt09lz" data-start="3466" data-end="3511"><strong>Questions Raised Over the Need for Urgency</strong></h3>
<p data-start="3513" data-end="3707">Supporters of the urgent procedure argued that allowing the temporary regulation to expire would create an immediate regulatory gap for online platforms investigating <a href="https://thecyberexpress.com/eu-csam-law-gap-child-sexual-exploitation-risk/" target="_blank" rel="noopener">child sexual abuse content</a>.</p>
<p data-start="3709" data-end="3967">However, CDT Europe challenged that justification, pointing to statements from the German Federal Police, which reportedly acknowledged there was no direct connection between the expiration of the temporary regulation and the number of CSAM reports received.</p>
<p data-start="3969" data-end="4405">The organization also noted that several legal mechanisms remain available even without the temporary derogation. These include targeted telecommunications surveillance with judicial authorization, electronic evidence preservation under the EU's e-evidence framework, existing content removal and reporting processes under the <a href="https://thecyberexpress.com/dsa-child-protection-investigation/" target="_blank" rel="noopener">Digital Services Act</a>, and hash-matching technology that identifies previously verified CSAM for human review.</p>

<h3 data-section-id="1eca2tw" data-start="4407" data-end="4433"><strong>Privacy Concerns Remain</strong></h3>
<p data-start="4435" data-end="4783">Following the vote, CDT Europe said it opposed both the outcome and the legislative process used to restore the regulation. The organization stated it would continue advocating for a future Child Sexual Abuse Material Regulation (CSAR) that rejects indiscriminate mass scanning while protecting end-to-end encryption and fundamental rights.</p>
<p data-start="4785" data-end="5027">The renewed Chat Control 1.0 regulation restores the legal framework for voluntary scanning by online platforms, but the broader debate over balancing child protection, privacy, and digital rights in the European Union remains unresolved.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CurrentBody Multi Light Therapy LED mask review: hands down the best I’ve tested]]></title>
<description><![CDATA[With five light modes targeting everything from fine lines to blemishes and pigmentation, CurrentBody’s latest mask promises a lot – and so does its price tag• The best LED face masksI’ve been testing LED masks for a couple of years now, and the CurrentBody Series 2 red-light face mask has long b...]]></description>
<link>https://tsecurity.de/de/3663258/it-nachrichten/currentbody-multi-light-therapy-led-mask-review-hands-down-the-best-ive-tested/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663258/it-nachrichten/currentbody-multi-light-therapy-led-mask-review-hands-down-the-best-ive-tested/</guid>
<pubDate>Sun, 12 Jul 2026 14:17:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>With five light modes targeting everything from fine lines to blemishes and pigmentation, CurrentBody’s latest mask promises a lot – and so does its price tag</p><p>• <a href="https://www.theguardian.com/thefilter/2025/sep/19/best-led-red-light-therapy-face-masks"><strong>The best LED face masks</strong></a></p><p>I’ve been testing <a href="https://www.theguardian.com/thefilter/2025/sep/19/best-led-red-light-therapy-face-masks">LED masks</a> for a couple of years now, and the <a href="https://www.currentbody.com/products/currentbody-skin-led-light-therapy-mask">CurrentBody Series 2</a> red-light face mask has long been my favourite option for anti-ageing. It’s comfortable, offers excellent coverage and powerful deep near-infrared treatments. Sadly, it doesn’t work for other skin concerns. It’s a one-trick pony.</p><p>So, when I heard that CurrentBody had launched its Multi Light Therapy mask with five different modes, I was interested to see how it would stand up to the stellar performance of its predecessor. As someone with hormonal acne, I was especially keen to try the mask’s “clearing” mode, but it also offers a calming “restoring” mode, a pigmentation-reducing “brightening” mode, and a distinctive “complete” mode, as well as the “anti-ageing” mode.</p> <a href="https://www.theguardian.com/thefilter/2026/jul/12/currentbody-skin-multi-light-therapy-led-mask-review">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘This was a righteous case. A holy war’: the lawyer who took on Meta and Google – and won]]></title>
<description><![CDATA[When Mark Lanier and his young client Kaley faced the tech giants in an LA courtroom earlier this year, it seemed a bigger battle than David v Goliath. But they scored a landmark victory, proving that the social media giants had created ‘addiction machines’ that harmed mental health. How did they...]]></description>
<link>https://tsecurity.de/de/3663200/it-nachrichten/this-was-a-righteous-case-a-holy-war-the-lawyer-who-took-on-meta-and-google-and-won/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663200/it-nachrichten/this-was-a-righteous-case-a-holy-war-the-lawyer-who-took-on-meta-and-google-and-won/</guid>
<pubDate>Sun, 12 Jul 2026 13:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Mark Lanier and his young client Kaley faced the tech giants in an LA courtroom earlier this year, it seemed a bigger battle than David v Goliath. But they scored a landmark victory, proving that the social media giants had created ‘addiction machines’ that harmed mental health. How did they pull it off?</p><p>When Mark Zuckerberg walked into a Los Angeles courtroom on 18 February <a href="https://www.theguardian.com/technology/2026/feb/18/mark-zuckerberg-meta-trial-testimony">flanked by an entourage</a> bedecked in Meta Ray-Bans, some people laughed. If this was an attempt at product placement for the company’s newest range of smart glasses, it was jarringly ill-judged: Zuckerberg was about to testify before a jury in a landmark lawsuit that sought to prove that Instagram and YouTube are addictive by design, and he had passed a throng of bereaved parents on his way into the courthouse. But the prosecution team, led by Mark Lanier, were not laughing.</p><p>This was a serious trial. For the first time, the most powerful names in social media were being held to account for the inherent design of their platforms, rather than the content hosted on them. They were accused of deliberately and maliciously building products that keep children hooked, with disastrous consequences for the mental wellbeing of young people. It was a landmark case – a big tobacco moment for big tech.</p> <a href="https://www.theguardian.com/media/2026/jul/12/mark-lanier-the-lawyer-who-took-on-meta-and-google-and-won-interview">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Says US States Seek $1.4 Trillion In Penalties In August's Youth Safety Trial]]></title>
<description><![CDATA[Meta "said in a court filing on Monday that four states were seeking $1.4 trillion in penalties," reports Reuters, "over accusations the company designed its Facebook and Instagram platforms to addict young users and misled the public about their safety."

Meta put forward the figure in its respo...]]></description>
<link>https://tsecurity.de/de/3662117/it-security-nachrichten/meta-says-us-states-seek-14-trillion-in-penalties-in-augusts-youth-safety-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662117/it-security-nachrichten/meta-says-us-states-seek-14-trillion-in-penalties-in-augusts-youth-safety-trial/</guid>
<pubDate>Sat, 11 Jul 2026 18:09:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta "said in a court filing on Monday that four states were seeking $1.4 trillion in penalties," reports Reuters, "over accusations the company designed its Facebook and Instagram platforms to addict young users and misled the public about their safety."

Meta put forward the figure in its response to the attorneys general's filings on how penalties should be calculated if the states prevailed at trial. The number, which has not previously been disclosed and is close to Meta's market capitalization of around $1.5 trillion, comes ahead of an August trial in Oakland, California, over the claims brought by California, Colorado, Kentucky and New Jersey against the company. Meta said the amount was unsupported by the evidence. "A sanction of that size has no analog in the history of consumer protection enforcement," the company said in the filing. "The plaintiffs' outlandish calculations have no basis in fact or law," the company said in a statement, adding that it would continue to defend itself against the states' demands.

 A spokesperson for California Attorney General Rob Bonta said in a statement the lawsuit "alleges Meta has prioritized profits over the safety of kids and fueled the mental health crisis we see impacting a generation of American children. The California Department of Justice looks forward to holding Meta fully accountable at trial in August...." 

Meta has denied the allegations, saying the attorneys general have no evidence it misled consumers about its platforms' alleged addictiveness because "social media addiction" is not an established psychiatric condition, and therefore statements that its platforms were not addictive could not be false... Last month, [U.S. District Judge] Rogers rejected Meta's bid to cancel the trial, saying there remained factual disputes over whether its social media platforms were addictive, whether Meta falsely denied it designed them that way, and whether it "partially" directed the platforms at children.

 

"A further 14 states have brought claims under their own laws, which will be heard at a separate trial in February..." 


Thanks to Slashdot reader Sparkatron for sharing the article.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Says+US+States+Seek+%241.4+Trillion+In+Penalties+In+August's+Youth+Safety+Trial%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F11%2F0614250%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F11%2F0614250%2Fmeta-says-us-states-seek-14-trillion-in-penalties-in-augusts-youth-safety-trial%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/11/0614250/meta-says-us-states-seek-14-trillion-in-penalties-in-augusts-youth-safety-trial?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Zealand Says It Has No Plans to Ban VPNs Under Proposed Child Social Media Rules]]></title>
<description><![CDATA[The New Zealand government has cleared up reports that it plans to ban virtual private networks (VPNs). Officials say they are not working on any rule that would stop people from using the privacy tool. The statement came after reports suggested the government could block VPNs. The reports claime...]]></description>
<link>https://tsecurity.de/de/3661920/it-security-nachrichten/new-zealand-says-it-has-no-plans-to-ban-vpns-under-proposed-child-social-media-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661920/it-security-nachrichten/new-zealand-says-it-has-no-plans-to-ban-vpns-under-proposed-child-social-media-rules/</guid>
<pubDate>Sat, 11 Jul 2026 15:34:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The New Zealand government has cleared up reports that it plans to ban virtual private networks (VPNs). Officials say they are not working on any rule that would stop people from using the privacy tool. The statement came after reports suggested the government could block VPNs. The reports claimed the move would stop children under […]</p>
<p>The post <a href="https://privacysavvy.com/news/vpn/new-zealand-no-vpn-ban-child-social-media-rules/">New Zealand Says It Has No Plans to Ban VPNs Under Proposed Child Social Media Rules</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU extends mass scanning of messages without a warrant]]></title>
<description><![CDATA[Members of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice.



This time too, more votes were cast against the proposal than in favor, but due to the absence of numerous MEPs on the...]]></description>
<link>https://tsecurity.de/de/3660067/it-security-nachrichten/eu-extends-mass-scanning-of-messages-without-a-warrant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660067/it-security-nachrichten/eu-extends-mass-scanning-of-messages-without-a-warrant/</guid>
<pubDate>Fri, 10 Jul 2026 16:54:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Members of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice.</p>



<p>This time too, more votes were cast against the proposal than in favor, but due to the absence of numerous MEPs on the eve of the summer recess, the motion to reject did not attain the necessary absolute majority. The proposal passed by default.</p>



<p>Similarly, an amendment to require warrants for the scanning received more votes in favor than against, but failed to attain the necessary absolute majority to pass.</p>



<p>The so-called Chat Control 1.0 law will now be extended through 2028.</p>



<p>According to its supporters, the measure can be seen as a vital component in the fight against the sexual abuse of children, while opponents see it as a move to restrict privacy.</p>



<p>This has been a long-running battle within the European Union. Last November, the European Commission <a href="https://www.csoonline.com/article/4097728/eu-chat-control-proposals-should-be-red-flag-to-businesses-everywhere.html">put a halt to proposals for large-scale monitoring</a> and proposed a voluntary approach. This has now changed. Under the new measure, service providers will be able to scan private messages without a warrant. This affects direct messages on platforms including Discord, Skype, Instagram, Snapchat, and Xbox, as well as emails sent via Google’s Gmail and Apple’s iCloud. Encrypted services like WhatsApp remain unaffected.</p>



<p>“Today’s vote on the interim regulation was a setback, but the political battle over the permanent ‘Chat Control 2.0’ is just getting started. The resistance we saw in Parliament today was so strong that finding a majority for permanent, suspicionless mass scanning in future negotiations is a complete pipe dream,” <a href="https://www.patrick-breyer.de/en/eu-parliament-greenlights-chat-control-1-0-breyer-our-children-lose-out/" target="_blank" rel="noreferrer noopener">wrote Patrick Beyer</a>, a long-standing critic of the proposal and a former MEP himself.</p>



<p>In November, he warned that enterprises could be affected by the measure. “For a corporation, a ‘false positive’ could mean that confidential internal documents, code, or strategic plans are flagged and sent to external authorities or police forces without the company’s knowledge.”</p>



<p>Discussions on a permanent solution to the issue are continuing, with some firmly entrenched views on both sides. “The core dispute between the EU Parliament, member state governments, and the EU Commission remains the scanning of private chats: should it be indiscriminate, or targeted at criminal suspects?” wrote Beyer.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘AI accountability agenda’: US senator unveils package of bills to curb tech’s harms]]></title>
<description><![CDATA[Exclusive: Senator Ed Markey on why he has proposed legislation aimed at curbing datacenters, automated hiring systems and harm to childrenUS senator Ed Markey is worried about the perils of unregulated artificial intelligence.What part? All of it: the costs associated with thirsty, energy-guzzli...]]></description>
<link>https://tsecurity.de/de/3659186/ai-nachrichten/ai-accountability-agenda-us-senator-unveils-package-of-bills-to-curb-techs-harms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659186/ai-nachrichten/ai-accountability-agenda-us-senator-unveils-package-of-bills-to-curb-techs-harms/</guid>
<pubDate>Fri, 10 Jul 2026 11:03:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Exclusive: Senator Ed Markey on why he has proposed legislation aimed at curbing datacenters, automated hiring systems and harm to children</p><p>US senator Ed Markey is worried about the perils of unregulated artificial intelligence.</p><p>What part? All of it: the costs associated with thirsty, energy-guzzling datacenters, intrusive workplace surveillance, bias in discriminatory algorithms, AI overriding workers’ judgments, and deepening economic inequality – as those who profit most from AI rake in extraordinary windfalls.</p> <a href="https://www.theguardian.com/technology/2026/jul/10/us-senator-unveils-ai-accountability-agenda-bills">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Dink on Apple TV: Release Date, Cast, Plot, and What to Expect]]></title>
<description><![CDATA[Apple TV is adding another original comedy to its July lineup with The Dink, a sports comedy that mixes tennis, pickleball, family drama, and plenty of humor. Starring Jake Johnson, Mary Steenburgen, and Ed Harris, the film follows a former tennis star whose life takes an unexpected turn after an...]]></description>
<link>https://tsecurity.de/de/3658603/ios-mac-os/the-dink-on-apple-tv-release-date-cast-plot-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658603/ios-mac-os/the-dink-on-apple-tv-release-date-cast-plot-and-what-to-expect/</guid>
<pubDate>Fri, 10 Jul 2026 05:23:47 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV is adding another original comedy to its July lineup with The Dink, a sports comedy that mixes tennis, pickleball, family drama, and plenty of humor. Starring Jake Johnson, Mary Steenburgen, and Ed Harris, the film follows a former tennis star whose life takes an unexpected turn after an injury forces him to reconsider everything he believed about the sport. The movie premieres worldwide on July 24, 2026.



The Dink at a glance



DetailsInformationRelease DateJuly 24, 2026PlatformApple TVGenreSports ComedyDuration1 hour 42 minutesRatingPG-13DirectorJosh GreenbaumWriterSean ClementsProducerBen Stiller, John Lesher, Rob Paris, Mike Witherill, Jake Johnson and others



Main cast




Jake Johnson as Dusty Boyd



Mary Steenburgen as Candace



Ed Harris as Chuck Boyd



Aaron Chen as PJ



Chloe Fineman



Patton Oswalt



Chris Parnell



Andy Roddick as himself



John McEnroe as himself



Ben Stiller in a supporting role





https://www.youtube.com/watch?v=YyVNFzx5Pl8




What is The Dink about?



Dusty Boyd was once a promising tennis player, but those days are long behind him. He now spends his time coaching children at his father's country club while trying to earn his father's respect. Things become even more complicated when Chuck starts a battle against the growing popularity of pickleball.



After Dusty suffers another injury that keeps him away from tennis, he reluctantly gives pickleball a chance. With help from his new partner, Candace, he slowly discovers that the sport he once dismissed may offer him a fresh start. Along the way, he must deal with old rivalries, family expectations, and the mistakes that have followed him for years.



Spoilers: Where the story appears to be heading



Spoiler Warning



Based on the official synopsis and trailer, the movie builds toward Dusty's emotional journey rather than focusing only on sports. As he embraces pickleball, he finds himself caught between loyalty to his father and his growing love for the game.



The story also brings back tennis legend Andy Roddick, who plays himself and represents part of Dusty's unfinished past. The final act is expected to center on the future of the country club, Dusty's relationship with his father, and whether he can finally move beyond his earlier failures.



What to expect from The Dink



The Dink looks very different from the serious sports dramas audiences often see. Instead, it focuses on comedy, awkward family moments, and an underdog story that happens to revolve around the rapidly growing sport of pickleball.



Jake Johnson's comedic style, Ed Harris' strong dramatic presence, and Mary Steenburgen's warm performance give the film a balanced cast. The addition of real tennis stars like Andy Roddick and John McEnroe should also make it fun for sports fans. Producer Ben Stiller and director Josh Greenbaum are aiming for a lighthearted comedy that appeals to both casual viewers and longtime sports enthusiasts.



Is The Dink worth watching?



If you enjoy sports comedies with heart, family conflicts, and a redemption story, The Dink is shaping up to be one of Apple TV's notable July releases. It combines familiar comedy talent with the growing popularity of pickleball, giving the movie a fresh angle ahead of its global debut on July 24.



The Dink joins a busy month for Apple TV, making it one of the platform's most talked-about original films this summer. If you plan to watch it, let us know your expectations in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4680: Robert A. Heinlein: The Future History, Part 2]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.
In his early days as a writer, Heinlein wrote his stories in the context of a shared universe that he called the Future History. These were mostly short stories at first, with the occasional novella. But they include some great stories.
The Future ...]]></description>
<link>https://tsecurity.de/de/3658424/podcasts/hpr4680-robert-a-heinlein-the-future-history-part-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658424/podcasts/hpr4680-robert-a-heinlein-the-future-history-part-2/</guid>
<pubDate>Fri, 10 Jul 2026 02:01:49 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<p>In his early days as a writer, Heinlein wrote his stories in the context of a shared universe that he called the Future History. These were mostly short stories at first, with the occasional novella. But they include some great stories.</p>
<h1 class="entry-title">The Future History, Part 2</h1>
						
<p>There were a few key themes running through Heinlein’s body of work. One we have already remarked upon, individual freedom, which had to be protected from any source of power, including both government and private corporations. This was essentially a libertarian perspective, but unlike many of today’s libertarians he was equally averse to the corporate type of power as a threat. But he had a complex view of the world which has resisted some attempts to pigeonhole him. He started out as a socialist, and while he didn’t remain one, he never became a knee-jerk reactionary either. In fact, he clearly despised them just as much. One way of looking at his body of work is that he explored the ramifications of different social policies through his stories, but in most cases the needs of a good story came first in the early years. In his later works he often surrendered to the temptation to pontificate, which reduced the enjoyment of them somewhat for anyone who was not already in agreement with his opinions</p>

<p>The second major theme you see throughout all of his works is the idea of the competent individual. He admired anyone who could do a job well, and clearly did not care whether they were man or woman, nor black or white. Alexei Panshin writes, in <a href="https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015" data-type="link" data-id="https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015" target="_blank" rel="noreferrer noopener">Heinlein in Dimension</a>: </p>

<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“There is one unique and vivid human Heinlein character, but he is a composite of Joe-Jim Gregory, Harriman, Waldo, Lazarus Long, Mr. Kiku, and many others, rather than any one individual.  I call the composite the Heinlein Individual.  . . .  It is a single personality that appears in three different stages and is repeated in every Heinlein book in one form or another.</p>

<p>“The earliest stage is that of the competent but naïve youngster. . . .  The second stage is the competent man in full glory, the man who knows how things work. . . .  The last stage is the wise old man who not only knows how things work, but why they work, too.”</p>
</blockquote>

<p>Harriman we have already encountered in <em>The Man Who Sold The Moon</em>, and the others appear later. The Heinlein Individual, as he is often referred to, appears in many of Heinlein’s stories.</p>

<p>A third major theme has to do with morality and religion. Heinlein grew up in what he considered the heart of the Bible Belt, in Missouri, and saw first-hand how the evangelical Christians operated, and despised what he saw. As someone who believed in individual freedom, he could never surrender to someone else’s idea of how he should live his life. He saw them as a danger to his ideal libertarian society, and this shows up very early in his work. He personified the good, upright, church-going folk as “Mrs. Grundy”, and while you might want to draw the drapes to keep her from knowing what you were doing, you should never let her dictate how you would live your life. Revolt in 2100 begins the exploration of this in detail.</p>

<p>There is a chart of the future history at <a href="https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm" data-type="link" data-id="https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm" target="_blank" rel="noreferrer noopener">Baen Books</a>, and in it we see that the 1960s were what Heinlein called The Crazy Years. (Remember, he conceived this in the 1940s and 1950s.) But in 2012 the major thing occurred when Nehemiah Scudder, a backwoods preacher, managed to get elected as President. This would be the last election held under the U.S. Constitution as he established a religious dictatorship that lasted a couple of generations. IS this plausible? Heinlein wrote about this:</p>

<p>“<em>As for … the idea that we could lose our freedom by succumbing to a wave of religious hysteria, I am sorry to say that I consider it possible. I hope that it is not probable. But there is a latent deep strain of religious fanaticism in this, our culture; it is rooted in our history and it has broken out many times in the past.</em></p>

<p><em>“It is with us now; there has been a sharp rise in strongly evangelical sects in this country in recent years, some of which hold beliefs theocratic in the extreme, anti-intellectual, anti-scientific, and anti-libertarian.</em>“</p>

<p>His background in the Bible Belt is what informs a lot of his thinking. He goes on to describe how this might happen:</p>

<p><em>“Throw in a Depression for good measure, promise a material heaven here on earth, add a dash of anti-Semitism, anti-Catholicism, anti-Negroism, and a good large dose of anti-“furriners” in general and anti-intellectuals here at home, and the result might be something quite frightening — particularly when one recalls that our voting system is such that a minority distributed as pluralities in enough states can constitute a working majority in Washington.”</em></p>

<p>As the science fiction author <a href="https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a" data-type="link" data-id="https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a" target="_blank" rel="noreferrer noopener">David Brin</a> points out, Heinlein accurately predicted much of what we are going through in the United States right now. There is an emerging dictatorship in the United States, promoted by right-wing religious groups. The “material heaven here on earth” is represented by the Prosperity Gospel, prominent in the Trump movement, and so on. Where the Prophet used a restored Ku Klux Klan as his muscle, we have The Proud Boys, and so on. It really does track very closely. Read David Brin’s article for more on this.</p>

<p>But nothing lasts forever. Empires rise and fall, governments change, and in this case a resistance movement arises. The revolt is depicted in the novella <em><a href="https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22" data-type="link" data-id="https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22" target="_blank" rel="noreferrer noopener">If This Goes On— (1940)</a></em>, and it is set in the year 2100, giving the title to the book. The main character is John Lyle, who is a young army officer assigned to the group protecting The Prophet in his capital of New Jerusalem. In the beginning he is thoroughly indoctrinated, but then begins to question his beliefs when he falls for one of The Prophet’s virgins, Sister Judith. He has an older companion in the military who is not only unshocked when John confides in him about his doubts, but offers to help him. It turns out this companion, Zeb Jones, is a member of the underground group called The Cabal that is working to overthrow the theocracy. In the end they are successful, and in the course of this John Lyle does a lot of growing up. In this we see another common characteristic of Heinlein stories: a young, naive boy meets up with an older and wiser man who helps him to grow.</p>

<p>In 2016 <em>If This Goes On—</em> won the Retro-Hugo Award for best novella of 1940. And in a personal note, I have T-shirt that says “Scudder for President 2012”. This baffles most people, but I enjoy the in-joke.</p>

<p>What is interesting in this book is that Heinlein doesn’t stop with a successful revolution. He then goes on in a second novella to describe the government that arose following the revolution, and this story is called <em><a href="https://en.wikipedia.org/wiki/Coventry_(short_story)" data-type="link" data-id="https://en.wikipedia.org/wiki/Coventry_(short_story)" target="_blank" rel="noreferrer noopener">Coventry (1940)</a></em>. The new government that arises after the revolution is called The Covenant, and it is an attempt to make sure that what happened with Scudder in 2012 could never happen again. It is a strongly libertarian government based on an agreement to be non-violent. In this society, scientists can cured criminal or violent tendencies, but any citizen convicted of such must agree to the treatment. The alternative to treatment is that they can be exiled to a place called Coventry. Coventry is outside of the Covenant society, and the Covenant society has nothing to do with them. </p>

<p>Our protagonist, David McKinnon, is convicted of assault, and chooses to go to Coventry instead of getting treatment. He imagines it is a peaceful anarchy, but is disabused of this notion when he is robbed of all of this possessions upon entry and thrown in jail. A fellow inmate, Fader Magee, helps him escape, and we learn he is an agent of the Covenant government. They learn that two of the factions in Coventry have joined forces, and found a way to break through the barrier that surrounds Coventry. They plan to attack and overthrow the Covenant government. David and Fader separately work to escape and get back to warn the Covenant government, which they do successfully. And by doing this, David has demonstrated that he is no longer a danger to the Covenant society and no longer subject to treatment.</p>

<p>This story won a <a href="https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees" data-type="link" data-id="https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees" target="_blank" rel="noreferrer noopener">Prometheus Hall of Fame Award</a>, which is awarded by the Libertarian Futurist Society. And the Covenant society certainly has libertarian features. But this is not the Randian version of libertarianism, as exemplified by the fact that David is restored to the society because he demonstrated his concern for others. Heinlein always promoted individual freedom, but also the idea that people have a responsibility towards others.</p>

<p>Finally, <em>Revolt in 2100</em> contains the short story <em>Misfit</em>, w2hich we have looked at previously.</p>

<p><em><a href="https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow" data-type="link" data-id="https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow" target="_blank" rel="noreferrer noopener">The Past Through Tomorrow (1967)</a></em> is a one volume collection of most of the Future history stories. I say most because just which stories belonged in this group could change from time to time. It also has the last version of the Chart of the Future History, and a few stories we have not yet mentioned (<em>Methusaleh’s Children</em>, and <em>The Menace From Earth</em>). And many of his other works contain back references to these events that imply that they might be set in the same alternate universe. Heinlein gets the last word on this:</p>

<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><em>“I have never been sure whether or not publishing that chart was a good idea or a bad mistake. Possibly it helped to sell some stories later—but certainly it caused me and still causes me to receive a lot nuisance mail from nitpickers. I have never felt bound by that chart; it was to serve me, not the other way around. If I found myself with a good story notion which fitted fairly well into the chart but not perfectly, I shed no tears—I went ahead and let the inconsistencies stand.</em></p>

<p><em>I want each story to be internally consistent . . . but I won’t let myself be painted into a corner through trying to fit that chart perfectly. I may start another “Future History” story tomorrow . . . and find that to make it a good yarn I must violate some item on that chart. I’ll give the nitpickers something to pick, for I will not hurt a good yarn for the sake of “logic”—logic is not involved, as that chart is fiction, not Holy Writ.”</em></p>
</blockquote>

<h3>Links:</h3>
<ul>
<li><a href="https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015">https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015</a></li>
<li><a href="https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm">https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm</a></li>
<li><a href="https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a">https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a</a></li>
<li><a href="https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22">https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22</a></li>
<li><a href="https://en.wikipedia.org/wiki/Coventry_(short_story)">https://en.wikipedia.org/wiki/Coventry_(short_story)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees">https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees</a></li>
<li><a href="https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow">https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow</a></li>
<li><a href="https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/the-future-history-part-2/">https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/the-future-history-part-2/</a></li>
</ul>

<p><a href="https://hackerpublicradio.org/eps/hpr4680/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Parents' Phone Addiction Affects Bond With Kids, New Study Finds]]></title>
<description><![CDATA[An anonymous reader quotes a report from Bloomberg: Parents' attachment to screens and smartphones can have negative, long-lasting developmental and psychological effects on their children, according to new research. Caregivers who mismanage their devices can both exacerbate "insecure attachment"...]]></description>
<link>https://tsecurity.de/de/3657467/it-security-nachrichten/parents-phone-addiction-affects-bond-with-kids-new-study-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657467/it-security-nachrichten/parents-phone-addiction-affects-bond-with-kids-new-study-finds/</guid>
<pubDate>Thu, 09 Jul 2026 17:07:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Bloomberg: Parents' attachment to screens and smartphones can have negative, long-lasting developmental and psychological effects on their children, according to new research. Caregivers who mismanage their devices can both exacerbate "insecure attachment" and make healthy relationships more anxious and avoidant for children, according to the findings, which were published last month in Frontiers in Psychology, a peer-reviewed journal. The study, which surveyed 600 minors in the US from 12 to 17 years old, found that kids reported feeling marginalized or neglected by parents glued to their screens. "A child with insecure attachment may lack confidence or display a lower sense of self; demonstrate difficulty with interpersonal relationships and intimacy; and possess an unwillingness to take risks necessary to achieve success," reports Bloomberg, citing one of the study's researchers.
 
This type of behavior has become normalized: 2024 Pew data found that nearly half of U.S. teens say their parents are at least sometimes distracted by phones during interactions. "When parents were asked about their own behavior, far fewer said this was an issue," the report adds. "Still, earlier Pew data from 2020 found most parents feel their phones can interfere with quality family time, with 68% reporting being 'at least sometimes' distracted by them.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Parents'+Phone+Addiction+Affects+Bond+With+Kids%2C+New+Study+Finds%3A+https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F07%2F09%2F0445259%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F07%2F09%2F0445259%2Fparents-phone-addiction-affects-bond-with-kids-new-study-finds%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://mobile.slashdot.org/story/26/07/09/0445259/parents-phone-addiction-affects-bond-with-kids-new-study-finds?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX's Grok 4.5 launches at half the price of rivals — here's why that could rattle Anthropic and OpenAI]]></title>
<description><![CDATA[Elon Musk's SpaceX released Grok 4.5 on Wednesday, the first artificial intelligence model the company has trained specifically for coding and autonomous agents — and the first tangible product of its $60 billion acquisition of the AI coding startup Cursor, completed just weeks ago.The launch mar...]]></description>
<link>https://tsecurity.de/de/3655560/it-nachrichten/spacexs-grok-45-launches-at-half-the-price-of-rivals-heres-why-that-could-rattle-anthropic-and-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655560/it-nachrichten/spacexs-grok-45-launches-at-half-the-price-of-rivals-heres-why-that-could-rattle-anthropic-and-openai/</guid>
<pubDate>Thu, 09 Jul 2026 00:47:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Elon Musk's <a href="https://www.spacex.com/">SpaceX</a> released <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> on Wednesday, the first artificial intelligence model the company has trained specifically for coding and autonomous agents — and the first tangible product of its <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">$60 billion acquisition</a> of the AI coding startup Cursor, completed just weeks ago.</p><p>The launch marks a pivotal test of the sprawling, vertically integrated AI empire Musk has assembled over the past six months, and of a strategy that bets developers care less about topping benchmark leaderboards than about speed, cost, and whether a model can actually do the work.</p><p>"Announcing Grok 4.5, our first model trained specifically for coding and agents," the company said in a post on X. "It was trained with Cursor and offers frontier intelligence at leading speeds and cost efficiency."</p><div></div><h2><b>Why Grok 4.5's pricing strategy matters more than its benchmark scores</b></h2><p><a href="https://www.spacex.com/">SpaceX</a> is not claiming <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> is the smartest model in the world. Instead, it is making an economic argument. The company says the model uses half as many tokens per task as comparable models, delivers higher throughput, and costs less than half as much — priced at $2 per million input tokens and $6 per million output tokens. That undercuts the premium tiers of rivals like Anthropic's Claude Opus line and OpenAI's frontier models by a wide margin.</p><p>Musk framed the positioning candidly. "Our internal assessment is that Grok 4.5 is roughly comparable to Opus 4.7, but much faster," <a href="https://x.com/elonmusk/status/2074911038286295049?s=20">he wrote on X</a>. "The combination of capability, faster speed and lower cost is what makes it competitive. We are closing the loop on real-world usefulness, not benchmarks. Hardcore engineers at Tesla &amp; SpaceX find Grok 4.5 genuinely useful, which is what actually matters."</p><p>That framing is both a philosophy and a hedge. Independent evaluations released Wednesday suggest Grok 4.5 is genuinely competitive but not dominant on raw capability. The benchmarking firm <a href="https://artificialanalysis.ai/models/grok-4-5">Artificial Analysis</a> ranked the model fourth on its <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2 index</a> of real-world agentic knowledge work, with an Elo score of 1543, "behind only the latest Claude releases from Anthropic." But the cost figures are where the model stands out. Artificial Analysis measured Grok 4.5 at <a href="https://artificialanalysis.ai/models/grok-4-5">$0.49 per completed task</a> — "nearly 90% cheaper than the models ahead of it on our leaderboard," the firm wrote, placing it "clearly on the Pareto frontier for performance versus cost."</p><p>For enterprise buyers, that math matters enormously. Agentic workloads — where a model works autonomously for minutes or hours, reading codebases, calling tools, and iterating on its own output — consume tokens voraciously. A model that is <a href="https://artificialanalysis.ai/models/grok-4-5">90% cheaper per completed task</a>, even if slightly less capable, changes the calculus for any engineering organization deploying agents across hundreds of developers. Investor <a href="https://x.com/GavinSBaker/status/2074943300725887104">Gavin Baker</a> captured the market's cautious optimism: "Pareto dominant for coding by the numbers. We will see on the all-important vibes."</p><div></div><h2><b>How the $60 billion Cursor acquisition shaped Grok 4.5's training</b></h2><p>Grok 4.5 is the first concrete evidence of what SpaceX bought when it acquired Cursor, and the deal itself unfolded in stages. In April, SpaceX struck an <a href="https://www.businessinsider.com/spacex-cursor-coding-xai-deal-acquisition-2026-4">unusual arrangement</a> giving it the right to buy the coding startup for $60 billion — or pay billions in fees and compute if it walked away, as <a href="https://www.businessinsider.com/spacex-cursor-coding-xai-deal-acquisition-2026-4">Business Insider</a> reported at the time. Days after SpaceX's record-setting Nasdaq debut in June, the company exercised that right, announcing an all-stock acquisition that <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">CNBC reported</a> is roughly 3.4% dilution at the IPO valuation. SpaceX shares rose 16% on the news.</p><p>The strategic logic was always about data as much as product. Cursor's AI-first code editor generates an enormous stream of high-quality interaction data: how expert engineers write, edit, review, and debug code in real production environments. Musk said openly this spring that <a href="https://cursor.com/blog/grok-4-5">Cursor interaction data was being fed directly into Grok's training</a>. Cursor, for its part, got access to SpaceX's Colossus supercomputer in Memphis — roughly 200,000 Nvidia GPUs with plans to scale toward one million — after publicly acknowledging it had been "<a href="https://cursor.com/blog/spacex-model-training">bottlenecked by compute</a>."</p><p>"We've partnered with SpaceXAI to train Grok 4.5," Cursor's official account <a href="https://x.com/cursor_ai/status/2074915744999969059">posted</a> Wednesday. "It's our most powerful model yet and the first we've built for more than software engineering." SpaceX says the model reflects that pedigree: it "excels in large codebases and handles long-running tasks that span multiple repositories, hundreds of skills, and a variety of tools" — precisely the messy, multi-file reality of professional software engineering that clean coding benchmarks often fail to capture. Early developer reactions suggest the training paid off. "Ok Grok 4.5 is wild," <a href="https://x.com/Baconbrix/status/2074945996799504876">posted</a> developer Evan Bacon. "It just built me this rocket tracking app with live data and a 3D globe. I might need a new benchmark after this."</p><div></div><h2><b>Inside xAI's turbulent year of scandals, departures, and rebuilding</b></h2><p>The polished launch belies how chaotic the road here has been. Grok has spent much of the past year in crisis. In mid-2025, the <a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">chatbot generated antisemitic content</a> and at one point called itself "<a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">MechaHitler</a>," episodes covered extensively by <a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">NPR</a> and <a href="https://www.cnn.com/2025/07/08/tech/grok-ai-antisemitism">CNN</a>. Earlier this year, its image-generation features allowed users to create sexualized deepfakes, including of children — drawing investigations from the European Commission and Britain's Ofcom, as the BBC reported, and prompting SpaceX to list the behavior as a business risk in its own IPO filings.</p><p>The organization behind the model was fracturing, too. All 11 of Musk's xAI co-founders had departed by the end of March, according to <a href="https://techcrunch.com/2026/03/28/elon-musks-last-co-founder-reportedly-leaves-xai/">TechCrunch</a>, and Musk publicly conceded that xAI "was not built right [the] first time around," saying he was rebuilding it "from the foundations up." Musk himself admitted at a conference this spring that Grok was "currently behind in coding" — a rare public concession from an executive not known for them.</p><p>Against that backdrop, <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> reads as the first product of the rebuilt organization — and the first proof point for the audacious story SpaceX told public market investors. During its IPO roadshow, the company pitched a total <a href="https://fortune.com/2026/05/20/spacex-ipo-filing-s1-total-addressable-market-make-life-multiplanetary/">addressable market of roughly $28 trillion</a>, with about $26 trillion tied to AI, including a $22.7 trillion "enterprise applications" opportunity. Those numbers strained credulity even by Silicon Valley standards. A competitive, cheap coding model is the most direct route from that narrative to actual revenue, which is why Wednesday's launch carries weight far beyond a routine model release.</p><h2><b>Grok 4.5 vs. Claude: the battle for the AI coding market</b></h2><p>The competitive stakes are hard to overstate, because the AI coding market has been consolidating around a single leader — and it isn't Musk. Even as Cursor's revenue exploded, its market share was eroding. <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">Spending data from Ramp cited by CNBC</a> showed Cursor's share of the AI coding category falling from 41% in June 2025 to about 26% by May 2026, while Anthropic came to control roughly half the market. Anthropic also topped CNBC's Disruptor 50 list this year and, by Artificial Analysis's own measure, still holds the top spots on <a href="https://artificialanalysis.ai/models/capabilities/agentic">agentic performance rankings</a>.</p><p>That is the gap <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> is engineered to close — not by out-thinking Claude, but by underpricing it. The model's economics create a classic disruption dynamic: if it delivers most of the frontier's capability at a fraction of the cost per task, price-sensitive enterprise workloads will migrate, and incumbents will face pressure on their most profitable API traffic. The counterargument is that in coding, quality compounds. A model that resolves a complex bug correctly on the first attempt can be cheaper in practice than one that costs half as much per token but requires three tries. That is why Baker's caveat about "vibes" — the developer community's shorthand for a model's felt reliability on real work — will determine more than any launch-day benchmark.</p><p>There is also a structural question buried in the deal. Cursor built its business on offering developers their choice of models, including Claude and GPT. If Grok becomes the favored child inside Cursor — and Musk was already urging users to "Try out Grok 4.5 in Cursor!" within hours of launch — the product risks alienating the very users whose data made Grok 4.5 possible. Regulators, already scrutinizing Grok on safety grounds in two jurisdictions, may take a keen interest in a company that controls the training data, the model, and a dominant distribution channel simultaneously.</p><div></div><h2><b>What Musk's trillion-dollar vertical integration bet means for AI's future</b></h2><p>Grok 4.5 also crystallizes what Musk's frenetic dealmaking was building toward. In February, SpaceX absorbed xAI in a share-exchange merger that CNBC confirmed valued the combined company at <a href="https://www.cnbc.com/2026/02/03/musk-xai-spacex-biggest-merger-ever.html">$1.25 trillion</a> — the largest merger of all time, valuing SpaceX at $1 trillion and xAI at $250 billion. The June IPO followed, the biggest in history, and the stock has since surged past $200 from its $135 offering price, vaulting SpaceX past Amazon and Microsoft to become the fourth most valuable company in the United States.</p><p>The result is a single public company that owns nearly the entire stack: Colossus for training compute, ambitions for orbital data centers to power future scaling, a frontier model in Grok, a distribution channel in Cursor's developer base, and captive demand from Tesla and SpaceX's own engineering organizations. Neither OpenAI nor Anthropic can fully replicate that integration; both must reach developers through third-party tools, some of which Musk now owns. Whether that concentration proves to be an unassailable moat or a regulatory target — or both — is now one of the defining questions in enterprise AI.</p><div></div><p>The next few weeks will start to answer it. Artificial Analysis says its full <a href="https://x.com/ArtificialAnlys/status/2074942097158021371">Intelligence Index</a> results are forthcoming. Enterprise pilots will reveal whether the token-efficiency claims survive contact with real codebases. And Anthropic, which has answered every serious challenge this cycle with a rapid counter-release, is unlikely to cede the price-performance frontier quietly.</p><p>But the deeper story of <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> may be what it says about where the AI race has moved. For three years, the industry's scoreboard was intelligence: whose model was smartest. Musk, arriving late and battered, has chosen to compete on a different axis entirely — whose model is cheapest to actually use. It is a telling choice from a man who built his fortune not by inventing the rocket or the electric car, but by relentlessly driving down the cost of making them. If the strategy works, Musk will have done to AI what he did to spaceflight. If it doesn't, he'll have spent $60 billion to learn that in software, unlike rockets, the cheapest ride isn't always the one engineers choose.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TV show purchases on Apple TV are finally getting free 4K upgrades]]></title>
<description><![CDATA[Apple is finally bringing its free 4K upgrade policy to select TV show purchases, extending one of the Apple TV Store's biggest customer perks beyond movies for the first time.Apple TV 4KApple hasn't announced the rollout, but the change first surfaced after Apple TV researcher Sigmund Judge iden...]]></description>
<link>https://tsecurity.de/de/3655215/ios-mac-os/tv-show-purchases-on-apple-tv-are-finally-getting-free-4k-upgrades/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655215/ios-mac-os/tv-show-purchases-on-apple-tv-are-finally-getting-free-4k-upgrades/</guid>
<pubDate>Wed, 08 Jul 2026 20:39:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is finally bringing its free 4K upgrade policy to select TV show purchases, extending one of the <a href="https://appleinsider.com/inside/apple-tv" title="Apple TV" data-kpt="1">Apple TV</a> Store's biggest customer perks beyond movies for the first time.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68203-143778-Apple-TV-4K-xl.jpg" alt="Apple TV box and remote on a wooden surface beneath a television screen showing a streaming menu, with the LG logo visible on the TV frame" height="738"><span>Apple TV 4K</span></div><br>Apple hasn't announced the rollout, but the change first surfaced after Apple TV researcher Sigmund Judge identified dozens of eligible series that were automatically upgraded to 4K at no extra cost. The initial rollout includes nearly 50 series spanning dramas, documentaries, reality shows, and children's programming.<br><br>The upgraded versions currently appear in standard dynamic range rather than HDR or Dolby Vision. At least one of those titles, "Star Trek: Strange New Worlds," now displays a 4K badge on its Apple TV Store page, confirming the rollout is live.<br><br>According to Judge, the <a href="https://x.com/sigjudge/status/2073017542738579919?s=12">current list</a> of eligible TV shows includes:<br><br><br> <a href="https://appleinsider.com/articles/26/07/08/tv-show-purchases-on-apple-tv-are-finally-getting-free-4k-upgrades?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244910?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trying Season 5 Cast Guide: Every Main Actor and Character]]></title>
<description><![CDATA[Trying Season 5 brings Nikki and Jason back into a much more complicated family story, as Kat arrives in their lives and changes the balance at home. The new season premiered globally on Apple TV on July 8, 2026, with Apple listing the main Season 5 setup around Kat’s return as the biological mot...]]></description>
<link>https://tsecurity.de/de/3655008/ios-mac-os/trying-season-5-cast-guide-every-main-actor-and-character/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655008/ios-mac-os/trying-season-5-cast-guide-every-main-actor-and-character/</guid>
<pubDate>Wed, 08 Jul 2026 19:25:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trying Season 5 brings Nikki and Jason back into a much more complicated family story, as Kat arrives in their lives and changes the balance at home. The new season premiered globally on Apple TV on July 8, 2026, with Apple listing the main Season 5 setup around Kat’s return as the biological mother of Princess and Tyler.



Who Plays Kat in Trying Season 5?







Kat is played by Charlotte Riley. She becomes one of the most important characters in Season 5 because her arrival directly affects Nikki, Jason, Princess, and Tyler.



Kat is Princess and Tyler’s biological mother, and her appearance at Nikki and Jason’s doorstep brings tension into a family that had finally found some stability. Apple’s official Season 5 description names Kat as the person whose return brings “chaos” into their settled family life.



Who Plays Nikki?







Nikki is played by Esther Smith. She remains the emotional centre of Trying, especially as Season 5 asks her to deal with the fallout of Kat’s return.



Nikki has spent years building a family with Jason, and her role this season becomes more difficult because Princess and Tyler now have questions that love alone cannot answer. Smith also executive produces the new season alongside Rafe Spall.



Who Plays Jason?







Jason is played by Rafe Spall. He returns as Nikki’s husband and Princess and Tyler’s adoptive father.



Jason has always brought warmth and nervous humour to the series, but Season 5 gives him a heavier family conflict to handle. His bond with the children matters even more now because Kat’s arrival forces everyone to rethink trust, honesty, and belonging.



Who Plays Princess?







Princess is played by Scarlett Rayner. She became a major focus in Season 4 after the time jump, and Season 5 continues her emotional journey.



Princess wants answers about her biological mother, and Kat’s sudden arrival gives her the truth in the most disruptive way possible. Apple’s official cast listing includes Scarlett Rayner among the key Season 5 names.



Who Plays Tyler?







Tyler is played by Cooper Turner. Like Princess, Tyler sits at the centre of the new family conflict because Kat is also his biological mother.



Tyler’s role adds another layer to Season 5 because the story is not only about Princess getting answers. It is also about how both children process Kat’s return while Nikki and Jason try to protect the family they have built.



Other Trying Season 5 Cast Members



Trying Season 5 also features familiar and new faces, including Darren Boyd, Siân Brooke, Phil Davis, Celia Imrie, Gbemisola Ikumelo, and Colin Morgan. The eight-episode season releases weekly on Apple TV through August 26, 2026.



At its core, Season 5 uses Kat’s arrival to test every part of Nikki and Jason’s family life. The cast matters because each character now has a clear emotional stake in what happens next.]]></content:encoded>
</item>
<item>
<title><![CDATA[Trying Season 5 Episode 1 Recap and Ending Explained]]></title>
<description><![CDATA[Trying Season 5 Episode 1 brings Kat back into Nikki and Jason’s life at the worst possible time, turning their family routine into a tense emotional mess.



Trying Season 5 Episode 1 Details



DetailInformationEpisode titleRollercoasterRelease dateJuly 8, 2026PlatformApple TVGenreComedy, Drama...]]></description>
<link>https://tsecurity.de/de/3654686/ios-mac-os/trying-season-5-episode-1-recap-and-ending-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654686/ios-mac-os/trying-season-5-episode-1-recap-and-ending-explained/</guid>
<pubDate>Wed, 08 Jul 2026 16:53:11 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trying Season 5 Episode 1 brings Kat back into Nikki and Jason’s life at the worst possible time, turning their family routine into a tense emotional mess.



Trying Season 5 Episode 1 Details



DetailInformationEpisode titleRollercoasterRelease dateJuly 8, 2026PlatformApple TVGenreComedy, DramaMain castEsther Smith, Rafe Spall, Scarlett Rayner, Cooper Turner, Charlotte RileySeason format8 episodes, weekly releaseFinale dateAugust 26, 2026



Spoilers Ahead: What Happens In Trying Season 5 Episode 1?



The episode continues after Nikki’s lie about Kat comes out. Princess already knows Nikki met her biological mother, and Kat’s sudden arrival makes everything more painful. Nikki tries to hold the family together, but her fear shows clearly.



Kat’s return changes the mood inside the house. Princess is curious, hurt, and confused, while Nikki feels like she is losing control of the life she built with Jason. Jason tries to stay calm, but even he understands that Kat is no longer just a name from the past.



Kat’s Return Shakes Nikki And Jason’s Family



Kat’s arrival is the main conflict of the premiere. She is Princess and Tyler’s biological mother, so her presence carries emotional weight. For Nikki, this is not only about an old lie. It is about the fear that Princess and Tyler may see Kat as someone they need more.



The episode does not turn Kat into a simple villain. Her return creates discomfort because the family has already moved forward. Nikki and Jason have worked hard to give Princess and Tyler a stable home, but Kat brings back questions they cannot avoid.



Ending Explained: Why Princess Is So Affected



By the ending, Princess feels pulled between anger and curiosity. She knows Nikki lied, but she also wants answers about Kat. This makes the ending important because Princess is no longer just reacting to Nikki’s choices. She is starting to make sense of her own identity.



Nikki’s panic also tells us where the season is heading. She wants to protect the family, but hiding the truth has already damaged trust. Now she has to face Kat’s role in the children’s lives instead of controlling it from a distance.



What It Means For Season 5



Trying Season 5 Episode 1 sets up a more emotional season for Nikki, Jason, Princess, and Tyler. Kat’s return will test their family bond, and Nikki’s relationship with Princess needs repair.



The premiere keeps the show’s warm tone, but it also adds real tension. Kat is here now, and her presence will keep changing the family dynamic in the coming episodes.



What do you plan to watch next on Apple TV? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[My patients use ChatGPT for therapy. Now I use it too | Sarah Dargouth]]></title>
<description><![CDATA[I can’t blame my patients for turning to its straightforward assessments. But it has real risks – and care may require human messiness“Chat told me I should break up with him.”I instructed my face to remain therapist-neutral, but I must have smirked. The truth is, I was annoyed. We had been discu...]]></description>
<link>https://tsecurity.de/de/3653923/ai-nachrichten/my-patients-use-chatgpt-for-therapy-now-i-use-it-too-sarah-dargouth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653923/ai-nachrichten/my-patients-use-chatgpt-for-therapy-now-i-use-it-too-sarah-dargouth/</guid>
<pubDate>Wed, 08 Jul 2026 12:04:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I can’t blame my patients for turning to its straightforward assessments. But it has real risks – and care may require human messiness</p><p>“Chat told me I should break up with him.”</p><p>I instructed my face to remain therapist-neutral, but I must have smirked. The truth is, I was annoyed. We had been discussing the viability of this relationship for weeks, and in an instant AI had brought the answer. “How do you feel about it?” She said this had been her gut feeling all along. The following session, her relationship was over.</p> <a href="https://www.theguardian.com/commentisfree/2026/jul/08/chatgpt-ai-therapy">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic shines a light into the Claude AI black hole]]></title>
<description><![CDATA[Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. 



“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. ...]]></description>
<link>https://tsecurity.de/de/3653231/ai-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653231/ai-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</guid>
<pubDate>Wed, 08 Jul 2026 06:33:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. </p>



<p>“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. We call the collection of these patterns the J-space, named after the technique we used to find them, involving a mathematical concept called the <a href="https://www.sciencedirect.com/topics/engineering/jacobian-matrix" target="_blank" rel="noreferrer noopener">Jacobian</a>,” <a href="https://www.anthropic.com/research/global-workspace" target="_blank" rel="noreferrer noopener">Anthropic said in its post</a> about the discovery. It examines the contents of the J-space using what it calls the Jacobian lens, or J-lens.</p>



<p>“Each J-space pattern is linked to a particular word,” Anthropic said. “But when one of these patterns lights up, it doesn’t mean the model is saying that word, just that the word is on its ‘mind.’ If you’ve heard of language models having a scratchpad or chain of thought—text they write to themselves while reasoning—the J-space is something different. It operates silently, in the model’s internal neural activations, allowing the model to ‘think’ about a concept without writing it down.”</p>



<p>This new level of analytical visibility goes well beyond what Anthropic announced as an <a href="https://www.computerworld.com/article/3628817/anthropics-llms-cant-reason-but-think-they-can-even-worse-they-ignore-guardrails.html" target="_blank">internal scratchpad for its models in 2024</a>. That scratchpad revealed what the model was considering when preparing an action or delivering an answer. The new development instead focuses on something much deeper which has the potential to change how AI systems are evaluated and purchased. </p>



<p>One example in <a href="https://transformer-circuits.pub/2026/workspace/index.html" target="_blank" rel="noreferrer noopener">the paper</a> described how some models did not engage in improper behavior during tests, which would appear to be a very favorable result. But the contents of the J-space revealed that the model sometimes <em>knew </em>that it was being tested, and that awareness might have been the key reason it declined to engage in the problematic behavior, much in the way human children act when they know they are being watched. </p>



<p>“Anthropic built a lens that catches its own model quietly noticing it’s being tested, faking a result to look good, spotting a prompt injection, or sitting on a planted goal it hasn’t acted on yet,” said <a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity. “Some of that good behavior rode on the model knowing it was on stage.”</p>



<p>Customers should read their safety benchmarks with that in mind, he said. “Fitness for your project still comes from testing on your own data and your own attackers, not from a leaderboard the model knew it was sitting for.” </p>



<p>That kind of visibility is a potentially crucial tool for CIOs.</p>



<p>“A provider that can catch its own model misbehaving in silence, then publish [those results], is telling you something real about its assurance maturity. Put that in your due diligence, not just your newsfeed,” Lambros noted. “Here’s the question I’d hand every model vendor now: what can you see inside your model that I can’t see in its output, and what have you caught?”</p>



<p>Added <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520: “A model that behaves better because it knows it is being watched is not a safe model. It is a model with a poker face. We have to question every red team result, every internal pilot where the model refused something dangerous, and every ‘we tested this and it was fine’ story, because they now carry an asterisk.”</p>



<p>CIOs need to now determine whether an agent performed a function in a specific way because that is how it will always perform, or whether it was it behaving differently because it figured out you were just testing it, Kenney said. “The answer to that question should change your interpretation in a material way.”</p>



<h2 class="wp-block-heading">No J-lens for customers – yet</h2>



<p>“It is an admission that the industry’s evaluation regime is measuring something less durable than everyone assumed, and now the other frontier labs have to answer whether their own evaluations have the same problem,” Kenney said. “For CIOs, the paper is a warning about their entire model risk framework.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, said that examining the J-space can even help make models more efficient.</p>



<p>“It gives you the ability to introspect into the model and, as such, can be very useful to the user, especially in cases where explainability is important. Think regulated environments that require explainable responses and full causal analysis of them,” Villanustre said. “This can also be very helpful to users trying to fine tune their prompts, making models more efficient to optimize token cost.”</p>



<p>But currently indirect access, or future access achieved via AI vendor negotiations, is the only path for accessing the new information, though Villanustre noted that some enterprises could gain direct access to J-space by paying for <a href="https://www.cio.com/article/4167981/anthropics-financial-agents-expose-forward-deployed-engineers-as-new-ai-limiting-factor.html" target="_blank">Anthropic’s FDE program</a>. </p>



<p>“It is very useful to CIOs,” he pointed out, “but in order to make use of the capabilities offered by analysis of the J-space, they need appropriate talent that can make sense of it. The type of skills required go far beyond those of the general data analyst, or even data scientist.” </p>



<p>Today, said <a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, “enterprise customers cannot enable the Jacobian lens, cannot inspect the residual stream through the API, and cannot run the ablation studies that produced the most interesting findings in the paper.” </p>



<p>So, he said, “on the narrow question of whether a CIO can operationally use J-space monitoring in Q3 of this year to gate a production deployment, the answer is no.”</p>



<p>But Mahapatra argued that there are going to be other ways to access the information, and CIOs must insist on them.</p>



<p><strong>“</strong>Without customer-side access, this reduces to trusting Anthropic yet again, and that is exactly why enterprises should start pushing for a different assurance model industry-wide,” he said. “Model providers are converging on a posture where they inspect their own models using proprietary tooling and publish reassuring research about what they found. That is not an assurance framework any regulated industry accepts from any other vendor.”</p>



<p>He pointed out that banks do not accept “we validated our own model, trust us” from a credit scoring vendor, not does the healthcare industry accept it from a clinical decision support vendor. “There is no principled reason to accept it from a foundation model vendor either, and the J-space research crystallizes why,” he said.</p>



<h2 class="wp-block-heading">New visibility demands</h2>



<p>“The right long-term enterprise posture is to demand independent interpretability access, either through customer-facing APIs, through independent third-party auditors with privileged access, or through open interpretability standards that let a bank’s model risk management team apply the same tooling the vendor’s own safety team uses,” Mahapatra stressed. “None of that exists today. All of it should be on the roadmap CIOs are pushing for, and this research is the strongest argument yet for why.”</p>



<p>In fact, the discoveries in the research have the potential to fundamentally rewrite the AI strategy rules.</p>



<p>Mahapatra said that the single hardest problem in enterprise agentic deployment is verifying that an autonomous system’s stated reasoning matches its actual reasoning. “Until now, we could only audit what the model writes, while much of its reasoning happened silently. The J-lens attacks that gap head-on,” he noted.</p>



<p>Thus, he said, sophisticated buyers should start asking model providers during the procurement process about the interpretability tooling they offer to let customers monitor internal model state for deception, evaluation-gaming, and goal misalignment in their specific deployments.</p>



<p>“Almost no vendor can answer that today,” he said. “The CIOs who start requiring internal-state observability as a procurement criterion, even before the tooling is fully mature, will be the ones who shape how their vendors productize it, and the ones with genuine assurance when regulators start asking how they know their autonomous agents are actually doing what they claim.”</p>



<h2 class="wp-block-heading">The beginning of standards</h2>



<p>Another way that CIOs can benefit from this new visibility into Claude is to try and get that information from third-parties that already have access. The report, for example, noted that a Google AI specialist independently replicated some findings on an open-weight model.</p>



<p>That, noted <a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of Comp AI, a software development firm, “is a competitor verifying the method, not just the vendor’s own claim. It shows what’s technically possible, but it doesn’t give enterprises a way to check anything themselves.”</p>



<p>He said that it’s a pattern that compliance has seen before; SOC 2 didn’t start as an independent audit standard either. It started as vendors describing their own controls, and the market spent years building the infrastructure to verify those claims externally.</p>



<p>“Interpretability is at that same starting point now,” he noted. “It becomes meaningful for CIOs once J-lens findings show up in third-party audits, published model cards, or regulator-facing disclosures. Anything a risk team can point to that isn’t just the vendor’s word.”</p>



<h2 class="wp-block-heading">Leads to AI strategy changes</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, said he also expects this development to lead to major AI strategy changes. </p>



<p>“I can easily imagine governance platforms consuming those signals alongside prompts, outputs, identity information, policy decisions, and tool activity,” he said. “A future AI control plane could continuously evaluate whether an agent recognized an attempted prompt injection, understood that sensitive information was involved, detected conflicting objectives, or showed evidence that it was reasoning toward an unsafe action before that action was ever executed. Those signals become inputs into policy enforcement, human escalation, audit logging, and trust scoring across enterprise AI environments.”</p>



<p>This has practical implications for CIOs today, he pointed out, “because it changes how they evaluate AI vendors. A year ago, enterprises primarily asked about model accuracy, latency, security, and cost. Increasingly, procurement teams will also ask how much operational visibility vendors provide into agent behavior, reasoning quality, policy compliance, safety monitoring, and auditability.”</p>



<p>Mahapatra added that all of this could give CIOs a powerful new negotiating tactic. </p>



<p>“The renewal path is where the leverage actually sits: write contractual rights to interpretability reporting and third-party audit access into the next renewal, because those terms are free today and expensive after signature,” he said. “The CIOs who win on assurance in 2027 will be the ones who stopped accepting ‘trust us’ from their model provider in 2026 and put the right clauses in the paperwork while the vendor still needed the deal more than the customer needed the model.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4194145/anthropic-shines-a-light-into-the-claude-ai-black-hole.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic shines a light into the Claude AI black hole]]></title>
<description><![CDATA[Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. 



“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. ...]]></description>
<link>https://tsecurity.de/de/3653228/it-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653228/it-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</guid>
<pubDate>Wed, 08 Jul 2026 06:33:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. </p>



<p>“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. We call the collection of these patterns the J-space, named after the technique we used to find them, involving a mathematical concept called the <a href="https://www.sciencedirect.com/topics/engineering/jacobian-matrix" target="_blank" rel="nofollow">Jacobian</a>,” <a href="https://www.anthropic.com/research/global-workspace" target="_blank" rel="nofollow">Anthropic said in its post</a> about the discovery. It examines the contents of the J-space using what it calls the Jacobian lens, or J-lens.</p>



<p>“Each J-space pattern is linked to a particular word,” Anthropic said. “But when one of these patterns lights up, it doesn’t mean the model is saying that word, just that the word is on its ‘mind.’ If you’ve heard of language models having a scratchpad or chain of thought—text they write to themselves while reasoning—the J-space is something different. It operates silently, in the model’s internal neural activations, allowing the model to ‘think’ about a concept without writing it down.”</p>



<p>This new level of analytical visibility goes well beyond what Anthropic announced as an <a href="https://www.computerworld.com/article/3628817/anthropics-llms-cant-reason-but-think-they-can-even-worse-they-ignore-guardrails.html" target="_blank">internal scratchpad for its models in 2024</a>. That scratchpad revealed what the model was considering when preparing an action or delivering an answer. The new development instead focuses on something much deeper which has the potential to change how AI systems are evaluated and purchased. </p>



<p>One example in <a href="https://transformer-circuits.pub/2026/workspace/index.html" target="_blank" rel="nofollow">the paper</a> described how some models did not engage in improper behavior during tests, which would appear to be a very favorable result. But the contents of the J-space revealed that the model sometimes <em>knew </em>that it was being tested, and that awareness might have been the key reason it declined to engage in the problematic behavior, much in the way human children act when they know they are being watched. </p>



<p>“Anthropic built a lens that catches its own model quietly noticing it’s being tested, faking a result to look good, spotting a prompt injection, or sitting on a planted goal it hasn’t acted on yet,” said <a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="nofollow">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity. “Some of that good behavior rode on the model knowing it was on stage.”</p>



<p>Customers should read their safety benchmarks with that in mind, he said. “Fitness for your project still comes from testing on your own data and your own attackers, not from a leaderboard the model knew it was sitting for.” </p>



<p>That kind of visibility is a potentially crucial tool for CIOs.</p>



<p>“A provider that can catch its own model misbehaving in silence, then publish [those results], is telling you something real about its assurance maturity. Put that in your due diligence, not just your newsfeed,” Lambros noted. “Here’s the question I’d hand every model vendor now: what can you see inside your model that I can’t see in its output, and what have you caught?”</p>



<p>Added <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="nofollow">Noah Kenney</a>, principal consultant at Digital 520: “A model that behaves better because it knows it is being watched is not a safe model. It is a model with a poker face. We have to question every red team result, every internal pilot where the model refused something dangerous, and every ‘we tested this and it was fine’ story, because they now carry an asterisk.”</p>



<p>CIOs need to now determine whether an agent performed a function in a specific way because that is how it will always perform, or whether it was it behaving differently because it figured out you were just testing it, Kenney said. “The answer to that question should change your interpretation in a material way.”</p>



<h2 class="wp-block-heading">No J-lens for customers – yet</h2>



<p>“It is an admission that the industry’s evaluation regime is measuring something less durable than everyone assumed, and now the other frontier labs have to answer whether their own evaluations have the same problem,” Kenney said. “For CIOs, the paper is a warning about their entire model risk framework.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="nofollow">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, said that examining the J-space can even help make models more efficient.</p>



<p>“It gives you the ability to introspect into the model and, as such, can be very useful to the user, especially in cases where explainability is important. Think regulated environments that require explainable responses and full causal analysis of them,” Villanustre said. “This can also be very helpful to users trying to fine tune their prompts, making models more efficient to optimize token cost.”</p>



<p>But currently indirect access, or future access achieved via AI vendor negotiations, is the only path for accessing the new information, though Villanustre noted that some enterprises could gain direct access to J-space by paying for <a href="https://www.cio.com/article/4167981/anthropics-financial-agents-expose-forward-deployed-engineers-as-new-ai-limiting-factor.html" target="_blank">Anthropic’s FDE program</a>. </p>



<p>“It is very useful to CIOs,” he pointed out, “but in order to make use of the capabilities offered by analysis of the J-space, they need appropriate talent that can make sense of it. The type of skills required go far beyond those of the general data analyst, or even data scientist.” </p>



<p>Today, said <a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="nofollow">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, “enterprise customers cannot enable the Jacobian lens, cannot inspect the residual stream through the API, and cannot run the ablation studies that produced the most interesting findings in the paper.” </p>



<p>So, he said, “on the narrow question of whether a CIO can operationally use J-space monitoring in Q3 of this year to gate a production deployment, the answer is no.”</p>



<p>But Mahapatra argued that there are going to be other ways to access the information, and CIOs must insist on them.</p>



<p><strong>“</strong>Without customer-side access, this reduces to trusting Anthropic yet again, and that is exactly why enterprises should start pushing for a different assurance model industry-wide,” he said. “Model providers are converging on a posture where they inspect their own models using proprietary tooling and publish reassuring research about what they found. That is not an assurance framework any regulated industry accepts from any other vendor.”</p>



<p>He pointed out that banks do not accept “we validated our own model, trust us” from a credit scoring vendor, not does the healthcare industry accept it from a clinical decision support vendor. “There is no principled reason to accept it from a foundation model vendor either, and the J-space research crystallizes why,” he said.</p>



<h2 class="wp-block-heading">New visibility demands</h2>



<p>“The right long-term enterprise posture is to demand independent interpretability access, either through customer-facing APIs, through independent third-party auditors with privileged access, or through open interpretability standards that let a bank’s model risk management team apply the same tooling the vendor’s own safety team uses,” Mahapatra stressed. “None of that exists today. All of it should be on the roadmap CIOs are pushing for, and this research is the strongest argument yet for why.”</p>



<p>In fact, the discoveries in the research have the potential to fundamentally rewrite the AI strategy rules.</p>



<p>Mahapatra said that the single hardest problem in enterprise agentic deployment is verifying that an autonomous system’s stated reasoning matches its actual reasoning. “Until now, we could only audit what the model writes, while much of its reasoning happened silently. The J-lens attacks that gap head-on,” he noted.</p>



<p>Thus, he said, sophisticated buyers should start asking model providers during the procurement process about the interpretability tooling they offer to let customers monitor internal model state for deception, evaluation-gaming, and goal misalignment in their specific deployments.</p>



<p>“Almost no vendor can answer that today,” he said. “The CIOs who start requiring internal-state observability as a procurement criterion, even before the tooling is fully mature, will be the ones who shape how their vendors productize it, and the ones with genuine assurance when regulators start asking how they know their autonomous agents are actually doing what they claim.”</p>



<h2 class="wp-block-heading">The beginning of standards</h2>



<p>Another way that CIOs can benefit from this new visibility into Claude is to try and get that information from third-parties that already have access. The report, for example, noted that a Google AI specialist independently replicated some findings on an open-weight model.</p>



<p>That, noted <a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="nofollow">Lewis Carhart</a>, CEO of Comp AI, a software development firm, “is a competitor verifying the method, not just the vendor’s own claim. It shows what’s technically possible, but it doesn’t give enterprises a way to check anything themselves.”</p>



<p>He said that it’s a pattern that compliance has seen before; SOC 2 didn’t start as an independent audit standard either. It started as vendors describing their own controls, and the market spent years building the infrastructure to verify those claims externally.</p>



<p>“Interpretability is at that same starting point now,” he noted. “It becomes meaningful for CIOs once J-lens findings show up in third-party audits, published model cards, or regulator-facing disclosures. Anything a risk team can point to that isn’t just the vendor’s word.”</p>



<h2 class="wp-block-heading">Leads to AI strategy changes</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="nofollow">Justin Greis</a>, CEO of consulting firm Acceligence, said he also expects this development to lead to major AI strategy changes. </p>



<p>“I can easily imagine governance platforms consuming those signals alongside prompts, outputs, identity information, policy decisions, and tool activity,” he said. “A future AI control plane could continuously evaluate whether an agent recognized an attempted prompt injection, understood that sensitive information was involved, detected conflicting objectives, or showed evidence that it was reasoning toward an unsafe action before that action was ever executed. Those signals become inputs into policy enforcement, human escalation, audit logging, and trust scoring across enterprise AI environments.”</p>



<p>This has practical implications for CIOs today, he pointed out, “because it changes how they evaluate AI vendors. A year ago, enterprises primarily asked about model accuracy, latency, security, and cost. Increasingly, procurement teams will also ask how much operational visibility vendors provide into agent behavior, reasoning quality, policy compliance, safety monitoring, and auditability.”</p>



<p>Mahapatra added that all of this could give CIOs a powerful new negotiating tactic. </p>



<p>“The renewal path is where the leverage actually sits: write contractual rights to interpretability reporting and third-party audit access into the next renewal, because those terms are free today and expensive after signature,” he said. “The CIOs who win on assurance in 2027 will be the ones who stopped accepting ‘trust us’ from their model provider in 2026 and put the right clauses in the paperwork while the vendor still needed the deal more than the customer needed the model.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sleeping Driver on Tesla FSD Filmed in Canada]]></title>
<description><![CDATA[Castanet News has posted a video of a Tesla at highway speed near Revelstoke, British Columbia with a sleeping driver at the wheel, and two children in the backseat. ​While Tesla Full Self Driving (Supervised) is currently available in Canada, in B.C., the Motor Vehicle Act prohibits anyone from ...]]></description>
<link>https://tsecurity.de/de/3652817/it-security-nachrichten/sleeping-driver-on-tesla-fsd-filmed-in-canada/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652817/it-security-nachrichten/sleeping-driver-on-tesla-fsd-filmed-in-canada/</guid>
<pubDate>Tue, 07 Jul 2026 23:53:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Castanet News has posted a video of a Tesla at highway speed near Revelstoke, British Columbia with a sleeping driver at the wheel, and two children in the backseat. ​While Tesla Full Self Driving (Supervised) is currently available in Canada, in B.C., the Motor Vehicle Act prohibits anyone from driving, or permitting the driving of, … <a href="https://www.flyingpenguin.com/sleeping-driver-on-tesla-fsd-filmed-in-canada/" class="more-link">Continue reading <span class="screen-reader-text">Sleeping Driver on Tesla FSD Filmed in Canada</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SINEC OS]]></title>
<description><![CDATA[View CSAF
Summary
SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.
The following versions of Siemens SINEC OS are affected:

RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/cork. The "*...]]></description>
<link>https://tsecurity.de/de/3652271/it-security-nachrichten/siemens-sinec-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652271/it-security-nachrichten/siemens-sinec-os/</guid>
<pubDate>Tue, 07 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-05.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.</strong></p>
<p>The following versions of Siemens SINEC OS are affected:</p>
<ul>
<li>RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/&lt;4.0 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>Siemens</td>
<td>Siemens SINEC OS</td>
<td>Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Resource Shutdown or Release, Integer Overflow or Wraparound, Stack-based Buffer Overflow, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Uncontrolled Recursion, Out-of-bounds Read, Covert Timing Channel, Improper Input Validation, Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Improper Update of Reference Count, Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), Multiple Releases of Same Resource or Handle, Permissive Regular Expression, Expired Pointer Dereference, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, User Interface (UI) Misrepresentation of Critical Information, Improper Access Control, Insertion of Sensitive Information Into Sent Data, Inefficient Algorithmic Complexity, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Authentication Bypass by Primary Weakness, NULL Pointer Dereference, Active Debug Code, Loop with Unreachable Exit Condition ('Infinite Loop'), Missing Synchronization, External Control of File Name or Path, Privilege Dropping / Lowering Errors, Use of Web Browser Cache Containing Sensitive Information</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1352</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1352">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1376</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1376">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404 Improper Resource Shutdown or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.5</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6052</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6052">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6141</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6141">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6170</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6170">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.5</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-7039</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-7039">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-8732</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-8732">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9086</a></h3>
<div class="csaf-accordion-content">
<p>1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path=\"/\",`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9230</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9231</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timing measurements, we consider this to be a Moderate severity issue. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as SM2 is not an approved algorithm.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/385.html">CWE-385 Covert Timing Channel</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9232</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9232">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-10966</a></h3>
<div class="csaf-accordion-content">
<p>curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-10966">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13465</a></h3>
<div class="csaf-accordion-content">
<p>Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13465">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1321.html">CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13601</a></h3>
<div class="csaf-accordion-content">
<p>A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13601">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39913</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock-&gt;cork. syzbot reported the splat below. [0] The repro does the following: 1. Load a sk_msg prog that calls bpf_msg_cork_bytes(msg, cork_bytes) 2. Attach the prog to a SOCKMAP 3. Add a socket to the SOCKMAP 4. Activate fault injection 5. Send data less than cork_bytes At 5., the data is carried over to the next sendmsg() as it is smaller than the cork_bytes specified by bpf_msg_cork_bytes(). Then, tcp_bpf_send_verdict() tries to allocate psock-&gt;cork to hold the data, but this fails silently due to fault injection + __GFP_NOWARN. If the allocation fails, we need to revert the sk-&gt;sk_forward_alloc change done by sk_msg_alloc(). Let's call sk_msg_free() when tcp_bpf_send_verdict fails to allocate psock-&gt;cork. The "*copied" also needs to be updated such that a proper error can be returned to the caller, sendmsg. It fails to allocate psock-&gt;cork. Nothing has been corked so far, so this patch simply sets "*copied" to 0. [0]: WARNING: net/ipv4/af_inet.c:156 at inet_sock_destruct+0x623/0x730 net/ipv4/af_inet.c:156, CPU#1: syz-executor/5983 Modules linked in: CPU: 1 UID: 0 PID: 5983 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025 RIP: 0010:inet_sock_destruct+0x623/0x730 net/ipv4/af_inet.c:156 Code: 0f 0b 90 e9 62 fe ff ff e8 7a db b5 f7 90 0f 0b 90 e9 95 fe ff ff e8 6c db b5 f7 90 0f 0b 90 e9 bb fe ff ff e8 5e db b5 f7 90 &lt;0f&gt; 0b 90 e9 e1 fe ff ff 89 f9 80 e1 07 80 c1 03 38 c1 0f 8c 9f fc RSP: 0018:ffffc90000a08b48 EFLAGS: 00010246 RAX: ffffffff8a09d0b2 RBX: dffffc0000000000 RCX: ffff888024a23c80 RDX: 0000000000000100 RSI: 0000000000000fff RDI: 0000000000000000 RBP: 0000000000000fff R08: ffff88807e07c627 R09: 1ffff1100fc0f8c4 R10: dffffc0000000000 R11: ffffed100fc0f8c5 R12: ffff88807e07c380 R13: dffffc0000000000 R14: ffff88807e07c60c R15: 1ffff1100fc0f872 FS: 00005555604c4500(0000) GS:ffff888125af1000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005555604df5c8 CR3: 0000000032b06000 CR4: 00000000003526f0 Call Trace: __sk_destruct+0x86/0x660 net/core/sock.c:2339 rcu_do_batch kernel/rcu/tree.c:2605 [inline] rcu_core+0xca8/0x1770 kernel/rcu/tree.c:2861 handle_softirqs+0x286/0x870 kernel/softirq.c:579 __do_softirq kernel/softirq.c:613 [inline] invoke_softirq kernel/softirq.c:453 [inline] __irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680 irq_exit_rcu+0x9/0x30 kernel/softirq.c:696 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1052 [inline] sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1052</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39913">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40214</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight socket, with a nice repro. The repro consists of three stages. 1) 1-a. Create a single cyclic reference with many sockets 1-b. close() all sockets 1-c. Trigger GC 2) 2-a. Pass sk-A to an embryo sk-B 2-b. Pass sk-X to sk-X 2-c. Trigger GC 3) 3-a. accept() the embryo sk-B 3-b. Pass sk-B to sk-C 3-c. close() the in-flight sk-A 3-d. Trigger GC As of 2-c, sk-A and sk-X are linked to unix_unvisited_vertices, and unix_walk_scc() groups them into two different SCCs: unix_sk(sk-A)-&gt;vertex-&gt;scc_index = 2 (UNIX_VERTEX_INDEX_START) unix_sk(sk-X)-&gt;vertex-&gt;scc_index = 3 Once GC completes, unix_graph_grouped is set to true. Also, unix_graph_maybe_cyclic is set to true due to sk-X's cyclic self-reference, which makes close() trigger GC. At 3-b, unix_add_edge() allocates unix_sk(sk-B)-&gt;vertex and links it to unix_unvisited_vertices. unix_update_graph() is called at 3-a. and 3-b., but neither unix_graph_grouped nor unix_graph_maybe_cyclic is changed because both sk-B's listener and sk-C are not in-flight. 3-c decrements sk-A's file refcnt to 1. Since unix_graph_grouped is true at 3-d, unix_walk_scc_fast() is finally called and iterates 3 sockets sk-A, sk-B, and sk-X: sk-A -&gt; sk-B (-&gt; sk-C) sk-X -&gt; sk-X This is totally fine. All of them are not yet close()d and should be grouped into different SCCs. However, unix_vertex_dead() misjudges that sk-A and sk-B are in the same SCC and sk-A is dead. unix_sk(sk-A)-&gt;scc_index == unix_sk(sk-B)-&gt;scc_index &lt;-- Wrong! &amp;&amp; sk-A's file refcnt == unix_sk(sk-A)-&gt;vertex-&gt;out_degree ^-- 1 in-flight count for sk-B -&gt; sk-A is dead !? The problem is that unix_add_edge() does not initialise scc_index. Stage 1) is used for heap spraying, making a newly allocated vertex have vertex-&gt;scc_index == 2 (UNIX_VERTEX_INDEX_START) set by unix_walk_scc() at 1-c. Let's track the max SCC index from the previous unix_walk_scc() call and assign the max + 1 to a new vertex's scc_index. This way, we can continue to avoid Tarjan's algorithm while preventing misjudgments.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40214">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40248</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if already established During connect(), acting on a signal/timeout by disconnecting an already established socket leads to several issues: 1. connect() invoking vsock_transport_cancel_pkt() -&gt; virtio_transport_purge_skbs() may race with sendmsg() invoking virtio_transport_get_credit(). This results in a permanently elevated `vvs-&gt;bytes_unsent`. Which, in turn, confuses the SOCK_LINGER handling. 2. connect() resetting a connected socket's state may race with socket being placed in a sockmap. A disconnected socket remaining in a sockmap breaks sockmap's assumptions. And gives rise to WARNs. 3. connect() transitioning SS_CONNECTED -&gt; SS_UNCONNECTED allows for a transport change/drop after TCP_ESTABLISHED. Which poses a problem for any simultaneous sendmsg() or connect() and may result in a use-after-free/null-ptr-deref. Do not disconnect socket on signal/timeout. Keep the logic for unconnected sockets: they don't linger, can't be placed in a sockmap, are rejected by sendmsg().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40248">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40250</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq() failure The mlx5_irq_alloc() function can inadvertently free the entire rmap and end up in a crash[1] when the other threads tries to access this, when request_irq() fails due to exhausted IRQ vectors. This commit modifies the cleanup to remove only the specific IRQ mapping that was just added. This prevents removal of other valid mappings and ensures precise cleanup of the failed IRQ allocation's associated glue object. Note: This error is observed when both fwctl and rds configs are enabled. [1] mlx5_core 0000:05:00.0: Successfully registered panic handler for port 1 mlx5_core 0000:05:00.0: mlx5_irq_alloc:293:(pid 66740): Failed to request irq. err = -28 infiniband mlx5_0: mlx5_ib_test_wc:290:(pid 66740): Error -28 while trying to test write-combining support mlx5_core 0000:05:00.0: Successfully unregistered panic handler for port 1 mlx5_core 0000:06:00.0: Successfully registered panic handler for port 1 mlx5_core 0000:06:00.0: mlx5_irq_alloc:293:(pid 66740): Failed to request irq. err = -28 infiniband mlx5_0: mlx5_ib_test_wc:290:(pid 66740): Error -28 while trying to test write-combining support mlx5_core 0000:06:00.0: Successfully unregistered panic handler for port 1 mlx5_core 0000:03:00.0: mlx5_irq_alloc:293:(pid 28895): Failed to request irq. err = -28 mlx5_core 0000:05:00.0: mlx5_irq_alloc:293:(pid 28895): Failed to request irq. err = -28 general protection fault, probably for non-canonical address 0xe277a58fde16f291: 0000 [#1] SMP NOPTI RIP: 0010:free_irq_cpu_rmap+0x23/0x7d Call Trace: ? show_trace_log_lvl+0x1d6/0x2f9 ? show_trace_log_lvl+0x1d6/0x2f9 ? mlx5_irq_alloc.cold+0x5d/0xf3 [mlx5_core] ? __die_body.cold+0x8/0xa ? die_addr+0x39/0x53 ? exc_general_protection+0x1c4/0x3e9 ? dev_vprintk_emit+0x5f/0x90 ? asm_exc_general_protection+0x22/0x27 ? free_irq_cpu_rmap+0x23/0x7d mlx5_irq_alloc.cold+0x5d/0xf3 [mlx5_core] irq_pool_request_vector+0x7d/0x90 [mlx5_core] mlx5_irq_request+0x2e/0xe0 [mlx5_core] mlx5_irq_request_vector+0xad/0xf7 [mlx5_core] comp_irq_request_pci+0x64/0xf0 [mlx5_core] create_comp_eq+0x71/0x385 [mlx5_core] ? mlx5e_open_xdpsq+0x11c/0x230 [mlx5_core] mlx5_comp_eqn_get+0x72/0x90 [mlx5_core] ? xas_load+0x8/0x91 mlx5_comp_irqn_get+0x40/0x90 [mlx5_core] mlx5e_open_channel+0x7d/0x3c7 [mlx5_core] mlx5e_open_channels+0xad/0x250 [mlx5_core] mlx5e_open_locked+0x3e/0x110 [mlx5_core] mlx5e_open+0x23/0x70 [mlx5_core] __dev_open+0xf1/0x1a5 __dev_change_flags+0x1e1/0x249 dev_change_flags+0x21/0x5c do_setlink+0x28b/0xcc4 ? __nla_parse+0x22/0x3d ? inet6_validate_link_af+0x6b/0x108 ? cpumask_next+0x1f/0x35 ? __snmp6_fill_stats64.constprop.0+0x66/0x107 ? __nla_validate_parse+0x48/0x1e6 __rtnl_newlink+0x5ff/0xa57 ? kmem_cache_alloc_trace+0x164/0x2ce rtnl_newlink+0x44/0x6e rtnetlink_rcv_msg+0x2bb/0x362 ? __netlink_sendskb+0x4c/0x6c ? netlink_unicast+0x28f/0x2ce ? rtnl_calcit.isra.0+0x150/0x146 netlink_rcv_skb+0x5f/0x112 netlink_unicast+0x213/0x2ce netlink_sendmsg+0x24f/0x4d9 __sock_sendmsg+0x65/0x6a ____sys_sendmsg+0x28f/0x2c9 ? import_iovec+0x17/0x2b ___sys_sendmsg+0x97/0xe0 __sys_sendmsg+0x81/0xd8 do_syscall_64+0x35/0x87 entry_SYSCALL_64_after_hwframe+0x6e/0x0 RIP: 0033:0x7fc328603727 Code: c3 66 90 41 54 41 89 d4 55 48 89 f5 53 89 fb 48 83 ec 10 e8 0b ed ff ff 44 89 e2 48 89 ee 89 df 41 89 c0 b8 2e 00 00 00 0f 05 &lt;48&gt; 3d 00 f0 ff ff 77 35 44 89 c7 48 89 44 24 08 e8 44 ed ff ff 48 RSP: 002b:00007ffe8eb3f1a0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 000000000000000d RCX: 00007fc328603727 RDX: 0000000000000000 RSI: 00007ffe8eb3f1f0 RDI: 000000000000000d RBP: 00007ffe8eb3f1f0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000 R13: 00000000000 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40250">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40251</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy The function devl_rate_nodes_destroy is documented to "Unset parent for all rate objects". However, it was only calling the driver-specific `rate_leaf_parent_set` or `rate_node_parent_set` ops and decrementing the parent's refcount, without actually setting the `devlink_rate-&gt;parent` pointer to NULL. This leaves a dangling pointer in the `devlink_rate` struct, which cause refcount error in netdevsim[1] and mlx5[2]. In addition, this is inconsistent with the behavior of `devlink_nl_rate_parent_node_set`, where the parent pointer is correctly cleared. This patch fixes the issue by explicitly setting `devlink_rate-&gt;parent` to NULL after notifying the driver, thus fulfilling the function's documented behavior for all rate objects. [1] repro steps: echo 1 &gt; /sys/bus/netdevsim/new_device devlink dev eswitch set netdevsim/netdevsim1 mode switchdev echo 1 &gt; /sys/bus/netdevsim/devices/netdevsim1/sriov_numvfs devlink port function rate add netdevsim/netdevsim1/test_node devlink port function rate set netdevsim/netdevsim1/128 parent test_node echo 1 &gt; /sys/bus/netdevsim/del_device dmesg: refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 8 PID: 1530 at lib/refcount.c:31 refcount_warn_saturate+0x42/0xe0 CPU: 8 UID: 0 PID: 1530 Comm: bash Not tainted 6.18.0-rc4+ #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:refcount_warn_saturate+0x42/0xe0 Call Trace: devl_rate_leaf_destroy+0x8d/0x90 __nsim_dev_port_del+0x6c/0x70 [netdevsim] nsim_dev_reload_destroy+0x11c/0x140 [netdevsim] nsim_drv_remove+0x2b/0xb0 [netdevsim] device_release_driver_internal+0x194/0x1f0 bus_remove_device+0xc6/0x130 device_del+0x159/0x3c0 device_unregister+0x1a/0x60 del_device_store+0x111/0x170 [netdevsim] kernfs_fop_write_iter+0x12e/0x1e0 vfs_write+0x215/0x3d0 ksys_write+0x5f/0xd0 do_syscall_64+0x55/0x10f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 [2] devlink dev eswitch set pci/0000:08:00.0 mode switchdev devlink port add pci/0000:08:00.0 flavour pcisf pfnum 0 sfnum 1000 devlink port function rate add pci/0000:08:00.0/group1 devlink port function rate set pci/0000:08:00.0/32768 parent group1 modprobe -r mlx5_ib mlx5_fwctl mlx5_core dmesg: refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 7 PID: 16151 at lib/refcount.c:31 refcount_warn_saturate+0x42/0xe0 CPU: 7 UID: 0 PID: 16151 Comm: bash Not tainted 6.17.0-rc7_for_upstream_min_debug_2025_10_02_12_44 #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 RIP: 0010:refcount_warn_saturate+0x42/0xe0 Call Trace: devl_rate_leaf_destroy+0x8d/0x90 mlx5_esw_offloads_devlink_port_unregister+0x33/0x60 [mlx5_core] mlx5_esw_offloads_unload_rep+0x3f/0x50 [mlx5_core] mlx5_eswitch_unload_sf_vport+0x40/0x90 [mlx5_core] mlx5_sf_esw_event+0xc4/0x120 [mlx5_core] notifier_call_chain+0x33/0xa0 blocking_notifier_call_chain+0x3b/0x50 mlx5_eswitch_disable_locked+0x50/0x110 [mlx5_core] mlx5_eswitch_disable+0x63/0x90 [mlx5_core] mlx5_unload+0x1d/0x170 [mlx5_core] mlx5_uninit_one+0xa2/0x130 [mlx5_core] remove_one+0x78/0xd0 [mlx5_core] pci_device_remove+0x39/0xa0 device_release_driver_internal+0x194/0x1f0 unbind_store+0x99/0xa0 kernfs_fop_write_iter+0x12e/0x1e0 vfs_write+0x215/0x3d0 ksys_write+0x5f/0xd0 do_syscall_64+0x53/0x1f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40251">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40252</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede_tpa_end()', iterate over 'cqe-&gt;len_list[]' using only a zero-length terminator as the stopping condition. If the terminator was missing or malformed, the loop could run past the end of the fixed-size array. Add an explicit bound check using ARRAY_SIZE() in both loops to prevent a potential out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with SVACE.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40252">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40254</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The validation of the set(nsh(...)) action is completely wrong. It runs through the nsh_key_put_from_nlattr() function that is the same function that validates NSH keys for the flow match and the push_nsh() action. However, the set(nsh(...)) has a very different memory layout. Nested attributes in there are doubled in size in case of the masked set(). That makes proper validation impossible. There is also confusion in the code between the 'masked' flag, that says that the nested attributes are doubled in size containing both the value and the mask, and the 'is_mask' that says that the value we're parsing is the mask. This is causing kernel crash on trying to write into mask part of the match with SW_FLOW_KEY_PUT() during validation, while validate_nsh() doesn't allocate any memory for it: BUG: kernel NULL pointer dereference, address: 0000000000000018 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary) RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch] Call Trace: validate_nsh+0x60/0x90 [openvswitch] validate_set.constprop.0+0x270/0x3c0 [openvswitch] __ovs_nla_copy_actions+0x477/0x860 [openvswitch] ovs_nla_copy_actions+0x8d/0x100 [openvswitch] ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch] genl_family_rcv_msg_doit+0xdb/0x130 genl_family_rcv_msg+0x14b/0x220 genl_rcv_msg+0x47/0xa0 netlink_rcv_skb+0x53/0x100 genl_rcv+0x24/0x40 netlink_unicast+0x280/0x3b0 netlink_sendmsg+0x1f7/0x430 ____sys_sendmsg+0x36b/0x3a0 ___sys_sendmsg+0x87/0xd0 __sys_sendmsg+0x6d/0xd0 do_syscall_64+0x7b/0x2c0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The third issue with this process is that while trying to convert the non-masked set into masked one, validate_set() copies and doubles the size of the OVS_KEY_ATTR_NSH as if it didn't have any nested attributes. It should be copying each nested attribute and doubling them in size independently. And the process must be properly reversed during the conversion back from masked to a non-masked variant during the flow dump. In the end, the only two outcomes of trying to use this action are either validation failure or a kernel crash. And if somehow someone manages to install a flow with such an action, it will most definitely not do what it is supposed to, since all the keys and the masks are mixed up. Fixing all the issues is a complex task as it requires re-writing most of the validation code. Given that and the fact that this functionality never worked since introduction, let's just remove it altogether. It's better to re-introduce it later with a proper implementation instead of trying to fix it in stable releases.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40254">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40257</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call sk_stop_timer_sync(sk, &amp;entry-&gt;add_timer) while another might have free entry already, as reported by syzbot. Add RCU protection to fix this issue. Also change confusing add_timer variable with stop_timer boolean. syzbot report: BUG: KASAN: slab-use-after-free in __timer_delete_sync+0x372/0x3f0 kernel/time/timer.c:1616 Read of size 4 at addr ffff8880311e4150 by task kworker/1:1/44 CPU: 1 UID: 0 PID: 44 Comm: kworker/1:1 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Workqueue: events mptcp_worker Call Trace: dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 __timer_delete_sync+0x372/0x3f0 kernel/time/timer.c:1616 sk_stop_timer_sync+0x1b/0x90 net/core/sock.c:3631 mptcp_pm_del_add_timer+0x283/0x310 net/mptcp/pm.c:362 mptcp_incoming_options+0x1357/0x1f60 net/mptcp/options.c:1174 tcp_data_queue+0xca/0x6450 net/ipv4/tcp_input.c:5361 tcp_rcv_established+0x1335/0x2670 net/ipv4/tcp_input.c:6441 tcp_v4_do_rcv+0x98b/0xbf0 net/ipv4/tcp_ipv4.c:1931 tcp_v4_rcv+0x252a/0x2dc0 net/ipv4/tcp_ipv4.c:2374 ip_protocol_deliver_rcu+0x221/0x440 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:239 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318 __netif_receive_skb_one_core net/core/dev.c:6079 [inline] __netif_receive_skb+0x143/0x380 net/core/dev.c:6192 process_backlog+0x31e/0x900 net/core/dev.c:6544 __napi_poll+0xb6/0x540 net/core/dev.c:7594 napi_poll net/core/dev.c:7657 [inline] net_rx_action+0x5f7/0xda0 net/core/dev.c:7784 handle_softirqs+0x22f/0x710 kernel/softirq.c:622 __do_softirq kernel/softirq.c:656 [inline] __local_bh_enable_ip+0x1a0/0x2e0 kernel/softirq.c:302 mptcp_pm_send_ack net/mptcp/pm.c:210 [inline] mptcp_pm_addr_send_ack+0x41f/0x500 net/mptcp/pm.c:-1 mptcp_pm_worker+0x174/0x320 net/mptcp/pm.c:1002 mptcp_worker+0xd5/0x1170 net/mptcp/protocol.c:2762 process_one_work kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3427 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Allocated by task 44: kasan_save_stack mm/kasan/common.c:56 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:77 poison_kmalloc_redzone mm/kasan/common.c:400 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:417 kasan_kmalloc include/linux/kasan.h:262 [inline] __kmalloc_cache_noprof+0x1ef/0x6c0 mm/slub.c:5748 kmalloc_noprof include/linux/slab.h:957 [inline] mptcp_pm_alloc_anno_list+0x104/0x460 net/mptcp/pm.c:385 mptcp_pm_create_subflow_or_signal_addr+0xf9d/0x1360 net/mptcp/pm_kernel.c:355 mptcp_pm_nl_fully_established net/mptcp/pm_kernel.c:409 [inline] __mptcp_pm_kernel_worker+0x417/0x1ef0 net/mptcp/pm_kernel.c:1529 mptcp_pm_worker+0x1ee/0x320 net/mptcp/pm.c:1008 mptcp_worker+0xd5/0x1170 net/mptcp/protocol.c:2762 process_one_work kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3427 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Freed by task 6630: kasan_save_stack mm/kasan/common.c:56 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:77 __kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:587 kasan_save_free_info mm/kasan/kasan.h:406 [inline] poison_slab_object m ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40257">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40258</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-free in mptcp_schedule_work() [1] Issue here is that mptcp_schedule_work() schedules a work, then gets a refcount on sk-&gt;sk_refcnt if the work was scheduled. This refcount will be released by mptcp_worker(). [A] if (schedule_work(...)) { [B] sock_hold(sk); return true; } Problem is that mptcp_worker() can run immediately and complete before [B] We need instead : sock_hold(sk); if (schedule_work(...)) return true; sock_put(sk); [1] refcount_t: addition on 0; use-after-free. WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25 Call Trace: __refcount_add include/linux/refcount.h:-1 [inline] __refcount_inc include/linux/refcount.h:366 [inline] refcount_inc include/linux/refcount.h:383 [inline] sock_hold include/net/sock.h:816 [inline] mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943 mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316 call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747 expire_timers kernel/time/timer.c:1798 [inline] __run_timers kernel/time/timer.c:2372 [inline] __run_timer_base+0x648/0x970 kernel/time/timer.c:2384 run_timer_base kernel/time/timer.c:2393 [inline] run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403 handle_softirqs+0x22f/0x710 kernel/softirq.c:622 __do_softirq kernel/softirq.c:656 [inline] run_ktimerd+0xcf/0x190 kernel/softirq.c:1138 smpboot_thread_fn+0x542/0xa60 kernel/smpboot.c:160 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40258">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40261</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure -&gt;ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to complete before returning, and an error can cause -&gt;ioerr_work to be queued after cancel_work_sync() had been called. Move the call to cancel_work_sync() to be after nvme_fc_delete_association() to ensure -&gt;ioerr_work is not running when the nvme_fc_ctrl object is freed. Otherwise the following can occur: [ 1135.911754] list_del corruption, ff2d24c8093f31f8-&gt;next is NULL [ 1135.917705] ------------[ cut here ]------------ [ 1135.922336] kernel BUG at lib/list_debug.c:52! [ 1135.926784] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 1135.931851] CPU: 48 UID: 0 PID: 726 Comm: kworker/u449:23 Kdump: loaded Not tainted 6.12.0 #1 PREEMPT(voluntary) [ 1135.943490] Hardware name: Dell Inc. PowerEdge R660/0HGTK9, BIOS 2.5.4 01/16/2025 [ 1135.950969] Workqueue: 0x0 (nvme-wq) [ 1135.954673] RIP: 0010:__list_del_entry_valid_or_report.cold+0xf/0x6f [ 1135.961041] Code: c7 c7 98 68 72 94 e8 26 45 fe ff 0f 0b 48 c7 c7 70 68 72 94 e8 18 45 fe ff 0f 0b 48 89 fe 48 c7 c7 80 69 72 94 e8 07 45 fe ff &lt;0f&gt; 0b 48 89 d1 48 c7 c7 a0 6a 72 94 48 89 c2 e8 f3 44 fe ff 0f 0b [ 1135.979788] RSP: 0018:ff579b19482d3e50 EFLAGS: 00010046 [ 1135.985015] RAX: 0000000000000033 RBX: ff2d24c8093f31f0 RCX: 0000000000000000 [ 1135.992148] RDX: 0000000000000000 RSI: ff2d24d6bfa1d0c0 RDI: ff2d24d6bfa1d0c0 [ 1135.999278] RBP: ff2d24c8093f31f8 R08: 0000000000000000 R09: ffffffff951e2b08 [ 1136.006413] R10: ffffffff95122ac8 R11: 0000000000000003 R12: ff2d24c78697c100 [ 1136.013546] R13: fffffffffffffff8 R14: 0000000000000000 R15: ff2d24c78697c0c0 [ 1136.020677] FS: 0000000000000000(0000) GS:ff2d24d6bfa00000(0000) knlGS:0000000000000000 [ 1136.028765] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1136.034510] CR2: 00007fd207f90b80 CR3: 000000163ea22003 CR4: 0000000000f73ef0 [ 1136.041641] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1136.048776] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 1136.055910] PKRU: 55555554 [ 1136.058623] Call Trace: [ 1136.061074] [ 1136.063179] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.067540] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.071898] ? move_linked_works+0x4a/0xa0 [ 1136.075998] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.081744] ? __die_body.cold+0x8/0x12 [ 1136.085584] ? die+0x2e/0x50 [ 1136.088469] ? do_trap+0xca/0x110 [ 1136.091789] ? do_error_trap+0x65/0x80 [ 1136.095543] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.101289] ? exc_invalid_op+0x50/0x70 [ 1136.105127] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.110874] ? asm_exc_invalid_op+0x1a/0x20 [ 1136.115059] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.120806] move_linked_works+0x4a/0xa0 [ 1136.124733] worker_thread+0x216/0x3a0 [ 1136.128485] ? __pfx_worker_thread+0x10/0x10 [ 1136.132758] kthread+0xfa/0x240 [ 1136.135904] ? __pfx_kthread+0x10/0x10 [ 1136.139657] ret_from_fork+0x31/0x50 [ 1136.143236] ? __pfx_kthread+0x10/0x10 [ 1136.146988] ret_from_fork_asm+0x1a/0x30 [ 1136.150915]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40261">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1341.html">CWE-1341 Multiple Releases of Same Resource or Handle</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40262</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&amp;priv" which is an address in the stack and so it will lead to memory corruption when the imx_sc_key_action() function is called. Remove the &amp;.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40262">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40263</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`) in cros_ec_keyb_probe(), `ckdev-&gt;idev` remains NULL. An invalid memory access is observed in cros_ec_keyb_process() when receiving an EC_MKBP_EVENT_KEY_MATRIX event in cros_ec_keyb_work() in such case. Unable to handle kernel read from unreadable memory at virtual address 0000000000000028 ... x3 : 0000000000000000 x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: input_event cros_ec_keyb_work blocking_notifier_call_chain ec_irq_thread It's still unknown about why the kernel receives such malformed event, in any cases, the kernel shouldn't access `ckdev-&gt;idev` and friends if the driver doesn't intend to initialize them.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40263">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40264</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site.  This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40264">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40271</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access. We should use RB_CLEAR_NODE() set the erased node to EMPTY, then pde_subdir_next() will return NULL to avoid uaf access. We found an uaf issue while using stress-ng testing, need to run testcase getdent and tun in the same time. The steps of the issue is as follows: 1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current pde is tun3; 2) in the [time windows] unregister netdevice tun3 and tun2, and erase them from rbtree. erase tun3 first, and then erase tun2. the pde(tun2) will be released to slab; 3) continue to getdent process, then pde_subdir_next() will return pde(tun2) which is released, it will case uaf access. CPU 0 | CPU 1 ------------------------------------------------------------------------- traverse dir /proc/pid/net/dev_snmp6/ | unregister_netdevice(tun-&gt;dev) //tun3 tun2 sys_getdents64() | iterate_dir() | proc_readdir() | proc_readdir_de() | snmp6_unregister_dev() pde_get(de); | proc_remove() read_unlock(&amp;proc_subdir_lock); | remove_proc_subtree() | write_lock(&amp;proc_subdir_lock); [time window] | rb_erase(&amp;root-&gt;subdir_node, &amp;parent-&gt;subdir); | write_unlock(&amp;proc_subdir_lock); read_lock(&amp;proc_subdir_lock); | next = pde_subdir_next(de); | pde_put(de); | de = next; //UAF | rbtree of dev_snmp6 | pde(tun3) / \ NULL pde(tun2)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40271">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/625.html">CWE-625 Permissive Regular Expression</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40278</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak Fix a KMSAN kernel-infoleak detected by the syzbot . [net?] KMSAN: kernel-infoleak in __skb_datagram_iter In tcf_ife_dump(), the variable 'opt' was partially initialized using a designatied initializer. While the padding bytes are reamined uninitialized. nla_put() copies the entire structure into a netlink message, these uninitialized bytes leaked to userspace. Initialize the structure with memset before assigning its fields to ensure all members and padding are cleared prior to beign copied. This change silences the KMSAN report and prevents potential information leaks from the kernel memory. This fix has been tested and validated by syzbot. This patch closes the bug reported at the following syzkaller link and ensures no infoleak.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40278">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40280</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). syzbot reported use-after-free of tipc_net(net)-&gt;monitors[] in tipc_mon_reinit_self(). [0] The array is protected by RTNL, but tipc_mon_reinit_self() iterates over it without RTNL. tipc_mon_reinit_self() is called from tipc_net_finalize(), which is always under RTNL except for tipc_net_finalize_work(). Let's hold RTNL in tipc_net_finalize_work(). [0]: BUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162 Read of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989 CPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025 Workqueue: events tipc_net_finalize_work Call Trace: dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568 kasan_check_byte include/linux/kasan.h:399 [inline] lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162 rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline] rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline] rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244 rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243 write_lock_bh include/linux/rwlock_rt.h:99 [inline] tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718 tipc_net_finalize+0x115/0x190 net/tipc/net.c:140 process_one_work kernel/workqueue.c:3236 [inline] process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400 kthread+0x70e/0x8a0 kernel/kthread.c:463 ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Allocated by task 6089: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:68 poison_kmalloc_redzone mm/kasan/common.c:388 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405 kasan_kmalloc include/linux/kasan.h:260 [inline] __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407 kmalloc_noprof include/linux/slab.h:905 [inline] kzalloc_noprof include/linux/slab.h:1039 [inline] tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657 tipc_enable_bearer net/tipc/bearer.c:357 [inline] __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047 __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline] tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393 tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline] tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321 genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115 genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline] genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210 netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552 genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219 netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline] netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346 netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896 sock_sendmsg_nosec net/socket.c:714 [inline] __sock_sendmsg+0x21c/0x270 net/socket.c:729 ____sys_sendmsg+0x508/0x820 net/socket.c:2614 ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668 __sys_sendmsg net/socket.c:2700 [inline] __do_sys_sendmsg net/socket.c:2705 [inline] __se_sys_sendmsg net/socket.c:2703 [inline] __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/ ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40280">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40281</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are setting very large rto_alpha and/or rto_beta. In order to prevent user regression, perform the test at run time. Also add READ_ONCE() annotations as sysctl values can change under us. [1] UBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41 shift exponent 64 is too large for 32-bit type 'unsigned int' CPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:233 [inline] __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494 sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509 sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502 sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338 sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline] sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40281">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1335.html">CWE-1335 Incorrect Bitwise Shift of Integer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40345</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba Discovered by Atuin - Automated Vulnerability Discovery Engine. new_pba comes from the status packet returned after each write. A bogus device could report values beyond the block count derived from info-&gt;capacity, letting the driver walk off the end of pba_to_lba[] and corrupt heap memory. Reject PBAs that exceed the computed block count and fail the transfer so we avoid touching out-of-range mapping entries.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40345">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-46394</a></h3>
<div class="csaf-accordion-content">
<p>In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-46394">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/451.html">CWE-451 User Interface (UI) Misrepresentation of Critical Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.2</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49794</a></h3>
<div class="csaf-accordion-content">
<p>A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49794">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49795</a></h3>
<div class="csaf-accordion-content">
<p>A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49795">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49796</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49796">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-60876</a></h3>
<div class="csaf-accordion-content">
<p>BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-60876">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66035</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66035">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/201.html">CWE-201 Insertion of Sensitive Information Into Sent Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66382</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66382">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/407.html">CWE-407 Inefficient Algorithmic Complexity</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.9</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66412</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66412">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-69720</a></h3>
<div class="csaf-accordion-content">
<p>The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-69720">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71185</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation Make sure to drop the reference taken when looking up the crossbar platform device during am335x route allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71185">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71186</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71186">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71188</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71188">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71189</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the reference taken to the DMA master OF node also on late route allocation failures.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71189">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71190</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe Make sure to drop the reference taken when looking up the mailbox device during probe on probe failures and on driver unbind.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71190">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71191</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlate() Make sure to drop the reference taken when looking up the DMA platform device during of_dma_xlate() when releasing channel resources. Note that commit 3832b78b3ec2 ("dmaengine: at_hdmac: add missing put_device() call in at_dma_xlate()") fixed the leak in a couple of error paths but the reference is still leaking on successful allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71191">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-1484</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-1484">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.2</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-1489</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-1489">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-3784</a></h3>
<div class="csaf-accordion-content">
<p>curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-3784">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/305.html">CWE-305 Authentication Bypass by Primary Weakness</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22610</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22610">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22976</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset `qfq_class-&gt;leaf_qdisc-&gt;q.qlen &gt; 0` does not imply that the class itself is active. Two qfq_class objects may point to the same leaf_qdisc. This happens when: 1. one QFQ qdisc is attached to the dev as the root qdisc, and 2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get() / qdisc_put()) and is pending to be destroyed, as in function tc_new_tfilter. When packets are enqueued through the root QFQ qdisc, the shared leaf_qdisc-&gt;q.qlen increases. At the same time, the second QFQ qdisc triggers qdisc_put and qdisc_destroy: the qdisc enters qfq_reset() with its own q-&gt;q.qlen == 0, but its class's leaf qdisc-&gt;q.qlen &gt; 0. Therefore, the qfq_reset would wrongly deactivate an inactive aggregate and trigger a null-deref in qfq_deactivate_agg: [ 0.903172] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 0.903571] #PF: supervisor write access in kernel mode [ 0.903860] #PF: error_code(0x0002) - not-present page [ 0.904177] PGD 10299b067 P4D 10299b067 PUD 10299c067 PMD 0 [ 0.904502] Oops: Oops: 0002 [#1] SMP NOPTI [ 0.904737] CPU: 0 UID: 0 PID: 135 Comm: exploit Not tainted 6.19.0-rc3+ #2 NONE [ 0.905157] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [ 0.905754] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:992 (discriminator 2) include/linux/list.h:1006 (discriminator 2) net/sched/sch_qfq.c:1367 (discriminator 2) net/sched/sch_qfq.c:1393 (discriminator 2)) [ 0.906046] Code: 0f 84 4d 01 00 00 48 89 70 18 8b 4b 10 48 c7 c2 ff ff ff ff 48 8b 78 08 48 d3 e2 48 21 f2 48 2b 13 48 8b 30 48 d3 ea 8b 4b 18 0 Code starting with the faulting instruction =========================================== 0: 0f 84 4d 01 00 00 je 0x153 6: 48 89 70 18 mov %rsi,0x18(%rax) a: 8b 4b 10 mov 0x10(%rbx),%ecx d: 48 c7 c2 ff ff ff ff mov $0xffffffffffffffff,%rdx 14: 48 8b 78 08 mov 0x8(%rax),%rdi 18: 48 d3 e2 shl %cl,%rdx 1b: 48 21 f2 and %rsi,%rdx 1e: 48 2b 13 sub (%rbx),%rdx 21: 48 8b 30 mov (%rax),%rsi 24: 48 d3 ea shr %cl,%rdx 27: 8b 4b 18 mov 0x18(%rbx),%ecx ... [ 0.907095] RSP: 0018:ffffc900004a39a0 EFLAGS: 00010246 [ 0.907368] RAX: ffff8881043a0880 RBX: ffff888102953340 RCX: 0000000000000000 [ 0.907723] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 [ 0.908100] RBP: ffff888102952180 R08: 0000000000000000 R09: 0000000000000000 [ 0.908451] R10: ffff8881043a0000 R11: 0000000000000000 R12: ffff888102952000 [ 0.908804] R13: ffff888102952180 R14: ffff8881043a0ad8 R15: ffff8881043a0880 [ 0.909179] FS: 000000002a1a0380(0000) GS:ffff888196d8d000(0000) knlGS:0000000000000000 [ 0.909572] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 0.909857] CR2: 0000000000000000 CR3: 0000000102993002 CR4: 0000000000772ef0 [ 0.910247] PKRU: 55555554 [ 0.910391] Call Trace: [ 0.910527] [ 0.910638] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1485) [ 0.910826] qdisc_reset (include/linux/skbuff.h:2195 include/linux/skbuff.h:2501 include/linux/skbuff.h:3424 include/linux/skbuff.h:3430 net/sched/sch_generic.c:1036) [ 0.911040] __qdisc_destroy (net/sched/sch_generic.c:1076) [ 0.911236] tc_new_tfilter (net/sched/cls_api.c:2447) [ 0.911447] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958) [ 0.911663] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6861) [ 0.911894] netlink_rcv_skb (net/netlink/af_netlink.c:2550) [ 0.912100] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) [ 0.912296] ? __alloc_skb (net/core/skbuff.c:706) [ 0.912484] netlink_sendmsg (net/netlink/af ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22976">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22977</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, [1] unlike skbuff_head_cache which properly whitelists the cb[] field. [2] This causes a usercopy BUG() when CONFIG_HARDENED_USERCOPY is enabled and the kernel attempts to copy sk_buff.cb data to userspace via sock_recv_errqueue() -&gt; put_cmsg(). The crash occurs when: 1. TCP allocates an skb using alloc_skb_fclone() (from skbuff_fclone_cache) [1] 2. The skb is cloned via skb_clone() using the pre-allocated fclone [3] 3. The cloned skb is queued to sk_error_queue for timestamp reporting 4. Userspace reads the error queue via recvmsg(MSG_ERRQUEUE) 5. sock_recv_errqueue() calls put_cmsg() to copy serr-&gt;ee from skb-&gt;cb [4] 6. __check_heap_object() fails because skbuff_fclone_cache has no usercopy whitelist [5] When cloned skbs allocated from skbuff_fclone_cache are used in the socket error queue, accessing the sock_exterr_skb structure in skb-&gt;cb via put_cmsg() triggers a usercopy hardening violation: [ 5.379589] usercopy: Kernel memory exposure attempt detected from SLUB object 'skbuff_fclone_cache' (offset 296, size 16)! [ 5.382796] kernel BUG at mm/usercopy.c:102! [ 5.383923] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI [ 5.384903] CPU: 1 UID: 0 PID: 138 Comm: poc_put_cmsg Not tainted 6.12.57 #7 [ 5.384903] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 5.384903] RIP: 0010:usercopy_abort+0x6c/0x80 [ 5.384903] Code: 1a 86 51 48 c7 c2 40 15 1a 86 41 52 48 c7 c7 c0 15 1a 86 48 0f 45 d6 48 c7 c6 80 15 1a 86 48 89 c1 49 0f 45 f3 e8 84 27 88 ff &lt;0f&gt; 0b 490 [ 5.384903] RSP: 0018:ffffc900006f77a8 EFLAGS: 00010246 [ 5.384903] RAX: 000000000000006f RBX: ffff88800f0ad2a8 RCX: 1ffffffff0f72e74 [ 5.384903] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffffffff87b973a0 [ 5.384903] RBP: 0000000000000010 R08: 0000000000000000 R09: fffffbfff0f72e74 [ 5.384903] R10: 0000000000000003 R11: 79706f6372657375 R12: 0000000000000001 [ 5.384903] R13: ffff88800f0ad2b8 R14: ffffea00003c2b40 R15: ffffea00003c2b00 [ 5.384903] FS: 0000000011bc4380(0000) GS:ffff8880bf100000(0000) knlGS:0000000000000000 [ 5.384903] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 5.384903] CR2: 000056aa3b8e5fe4 CR3: 000000000ea26004 CR4: 0000000000770ef0 [ 5.384903] PKRU: 55555554 [ 5.384903] Call Trace: [ 5.384903] [ 5.384903] __check_heap_object+0x9a/0xd0 [ 5.384903] __check_object_size+0x46c/0x690 [ 5.384903] put_cmsg+0x129/0x5e0 [ 5.384903] sock_recv_errqueue+0x22f/0x380 [ 5.384903] tls_sw_recvmsg+0x7ed/0x1960 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? schedule+0x6d/0x270 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? mutex_unlock+0x81/0xd0 [ 5.384903] ? __pfx_mutex_unlock+0x10/0x10 [ 5.384903] ? __pfx_tls_sw_recvmsg+0x10/0x10 [ 5.384903] ? _raw_spin_lock_irqsave+0x8f/0xf0 [ 5.384903] ? _raw_read_unlock_irqrestore+0x20/0x40 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 The crash offset 296 corresponds to skb2-&gt;cb within skbuff_fclones: - sizeof(struct sk_buff) = 232 - offsetof(struct sk_buff, cb) = 40 - offset of skb2.cb in fclones = 232 + 40 = 272 - crash offset 296 = 272 + 24 (inside sock_exterr_skb.ee) This patch uses a local stack variable as a bounce buffer to avoid the hardened usercopy check failure. [1] https://elixir.bootlin.com/linux/v6.12.62/source/net/ipv4/tcp.c#L885 [2] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5104 [3] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5566 [4] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5491 [5] https://elixir.bootlin.com/linux/v6.12.62/source/mm/slub.c#L5719</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22977">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/489.html">CWE-489 Active Debug Code</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23025</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n The kernel test robot has reported: BUG: spinlock trylock failure on UP on CPU#0, kcompactd0/28 lock: 0xffff888807e35ef0, .magic: dead4ead, .owner: kcompactd0/28, .owner_cpu: 0 CPU: 0 UID: 0 PID: 28 Comm: kcompactd0 Not tainted 6.18.0-rc5-00127-ga06157804399 #1 PREEMPT 8cc09ef94dcec767faa911515ce9e609c45db470 Call Trace: __dump_stack (lib/dump_stack.c:95) dump_stack_lvl (lib/dump_stack.c:123) dump_stack (lib/dump_stack.c:130) spin_dump (kernel/locking/spinlock_debug.c:71) do_raw_spin_trylock (kernel/locking/spinlock_debug.c:?) _raw_spin_trylock (include/linux/spinlock_api_smp.h:89 kernel/locking/spinlock.c:138) __free_frozen_pages (mm/page_alloc.c:2973) ___free_pages (mm/page_alloc.c:5295) __free_pages (mm/page_alloc.c:5334) tlb_remove_table_rcu (include/linux/mm.h:? include/linux/mm.h:3122 include/asm-generic/tlb.h:220 mm/mmu_gather.c:227 mm/mmu_gather.c:290) ? __cfi_tlb_remove_table_rcu (mm/mmu_gather.c:289) ? rcu_core (kernel/rcu/tree.c:?) rcu_core (include/linux/rcupdate.h:341 kernel/rcu/tree.c:2607 kernel/rcu/tree.c:2861) rcu_core_si (kernel/rcu/tree.c:2879) handle_softirqs (arch/x86/include/asm/jump_label.h:36 include/trace/events/irq.h:142 kernel/softirq.c:623) __irq_exit_rcu (arch/x86/include/asm/jump_label.h:36 kernel/softirq.c:725) irq_exit_rcu (kernel/softirq.c:741) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1052) RIP: 0010:_raw_spin_unlock_irqrestore (arch/x86/include/asm/preempt.h:95 include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) free_pcppages_bulk (mm/page_alloc.c:1494) drain_pages_zone (include/linux/spinlock.h:391 mm/page_alloc.c:2632) __drain_all_pages (mm/page_alloc.c:2731) drain_all_pages (mm/page_alloc.c:2747) kcompactd (mm/compaction.c:3115) kthread (kernel/kthread.c:465) ? __cfi_kcompactd (mm/compaction.c:3166) ? __cfi_kthread (kernel/kthread.c:412) ret_from_fork (arch/x86/kernel/process.c:164) ? __cfi_kthread (kernel/kthread.c:412) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Matthew has analyzed the report and identified that in drain_page_zone() we are in a section protected by spin_lock(&amp;pcp-&gt;lock) and then get an interrupt that attempts spin_trylock() on the same lock. The code is designed to work this way without disabling IRQs and occasionally fail the trylock with a fallback. However, the SMP=n spinlock implementation assumes spin_trylock() will always succeed, and thus it's normally a no-op. Here the enabled lock debugging catches the problem, but otherwise it could cause a corruption of the pcp structure. The problem has been introduced by commit 574907741599 ("mm/page_alloc: leave IRQs enabled for per-cpu page allocations"). The pcp locking scheme recognizes the need for disabling IRQs to prevent nesting spin_trylock() sections on SMP=n, but the need to prevent the nesting in spin_lock() has not been recognized. Fix it by introducing local wrappers that change the spin_lock() to spin_lock_iqsave() with SMP=n and use them in all places that do spin_lock(&amp;pcp-&gt;lock). [vbabka@suse.cz: add pcp_ prefix to the spin_lock_irqsave wrappers, per Steven]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23025">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23026</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan-&gt;config could be lost if krealloc() fails. The issue occurs when: 1. gchan-&gt;config points to previously allocated memory 2. krealloc() fails and returns NULL 3. The function directly assigns NULL to gchan-&gt;config, losing the reference to the original memory 4. The original memory becomes unreachable and cannot be freed Fix this by using a temporary variable to hold the krealloc() result and only updating gchan-&gt;config when the allocation succeeds. Found via static analysis and code review.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23026">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23030</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe() The for_each_available_child_of_node() calls of_node_put() to release child_np in each success loop. After breaking from the loop with the child_np has been released, the code will jump to the put_child label and will call the of_node_put() again if the devm_request_threaded_irq() fails. These cause a double free bug. Fix by returning directly to avoid the duplicate of_node_put().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23030">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23031</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak In gs_can_open(), the URBs for USB-in transfers are allocated, added to the parent-&gt;rx_submitted anchor and submitted. In the complete callback gs_usb_receive_bulk_callback(), the URB is processed and resubmitted. In gs_can_close() the URBs are freed by calling usb_kill_anchored_urbs(parent-&gt;rx_submitted). However, this does not take into account that the USB framework unanchors the URB before the complete function is called. This means that once an in-URB has been completed, it is no longer anchored and is ultimately not released in gs_can_close(). Fix the memory leak by anchoring the URB in the gs_usb_receive_bulk_callback() to the parent-&gt;rx_submitted anchor.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23031">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23032</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When CONFIG_BLK_DEV_NULL_BLK_FAULT_INJECTION is enabled, the null-blk driver sets up fault injection support by creating the timeout_inject, requeue_inject, and init_hctx_fault_inject configfs items as children of the top-level nullbX configfs group. However, when the nullbX device is removed, the references taken to these fault-config configfs items are not released. As a result, kmemleak reports a memory leak, for example: unreferenced object 0xc00000021ff25c40 (size 32): comm "mkdir", pid 10665, jiffies 4322121578 hex dump (first 32 bytes): 69 6e 69 74 5f 68 63 74 78 5f 66 61 75 6c 74 5f init_hctx_fault_ 69 6e 6a 65 63 74 00 88 00 00 00 00 00 00 00 00 inject.......... backtrace (crc 1a018c86): __kmalloc_node_track_caller_noprof+0x494/0xbd8 kvasprintf+0x74/0xf4 config_item_set_name+0xf0/0x104 config_group_init_type_name+0x48/0xfc fault_config_init+0x48/0xf0 0xc0080000180559e4 configfs_mkdir+0x304/0x814 vfs_mkdir+0x49c/0x604 do_mkdirat+0x314/0x3d0 sys_mkdir+0xa0/0xd8 system_call_exception+0x1b0/0x4f0 system_call_vectored_common+0x15c/0x2ec Fix this by explicitly releasing the references to the fault-config configfs items when dropping the reference to the top-level nullbX configfs group.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23032">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23033</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: omap-dma: fix dma_pool resource leak in error paths The dma_pool created by dma_pool_create() is not destroyed when dma_async_device_register() or of_dma_controller_register() fails, causing a resource leak in the probe error paths. Add dma_pool_destroy() in both error paths to properly release the allocated dma_pool resource.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23033">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23037</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow partial RX URB allocation to succeed When es58x_alloc_rx_urbs() fails to allocate the requested number of URBs but succeeds in allocating some, it returns an error code. This causes es58x_open() to return early, skipping the cleanup label 'free_urbs', which leads to the anchored URBs being leaked. As pointed out by maintainer Vincent Mailhol, the driver is designed to handle partial URB allocation gracefully. Therefore, partial allocation should not be treated as a fatal error. Modify es58x_alloc_rx_urbs() to return 0 if at least one URB has been allocated, restoring the intended behavior and preventing the leak in es58x_open().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23037">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23038</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23038">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23111</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. nft_map_catchall_activate() is called from the abort path to re-activate catchall map elements that were deactivated during a failed transaction. It should skip elements that are already active (they don't need re-activation) and process elements that are inactive (they need to be restored). Instead, the current code does the opposite: it skips inactive elements and processes active ones. Compare the non-catchall activate callback, which is correct: nft_mapelem_activate(): if (nft_set_elem_active(ext, iter-&gt;genmask)) return 0; /* skip active, process inactive */ With the buggy catchall version: nft_map_catchall_activate(): if (!nft_set_elem_active(ext, genmask)) continue; /* skip inactive, process active */ The consequence is that when a DELSET operation is aborted, nft_setelem_data_activate() is never called for the catchall element. For NFT_GOTO verdict elements, this means nft_data_hold() is never called to restore the chain-&gt;use reference count. Each abort cycle permanently decrements chain-&gt;use. Once chain-&gt;use reaches zero, DELCHAIN succeeds and frees the chain while catchall verdict elements still reference it, resulting in a use-after-free. This is exploitable for local privilege escalation from an unprivileged user via user namespaces + nftables on distributions that enable CONFIG_USER_NS and CONFIG_NF_TABLES. Fix by removing the negation so the check matches nft_mapelem_activate(): skip active elements, process inactive ones.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23111">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23112</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd-&gt;req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg-&gt;length/offset values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining entries, and sg-&gt;length/offset before building the bvec.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23112">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23220</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths The problem occurs when a signed request fails smb2 signature verification check. In __process_request(), if check_sign_req() returns an error, set_smb2_rsp_status(work, STATUS_ACCESS_DENIED) is called. set_smb2_rsp_status() set work-&gt;next_smb2_rcv_hdr_off as zero. By resetting next_smb2_rcv_hdr_off to zero, the pointer to the next command in the chain is lost. Consequently, is_chained_smb2_message() continues to point to the same request header instead of advancing. If the header's NextCommand field is non-zero, the function returns true, causing __handle_ksmbd_work() to repeatedly process the same failed request in an infinite loop. This results in the kernel log being flooded with "bad smb2 signature" messages and high CPU usage. This patch fixes the issue by changing the return value from SERVER_HANDLER_CONTINUE to SERVER_HANDLER_ABORT. This ensures that the processing loop terminates immediately rather than attempting to continue from an invalidated offset.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23220">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23222</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy_sg_lists() was allocating an array of scatterlist pointers, not scatterlist objects, resulting in a 4x too small allocation. Use sizeof(*new_sg) to get the correct object size.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23222">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23228</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() On kthread_run() failure in ksmbd_tcp_new_connection(), the transport is freed via free_transport(), which does not decrement active_num_conn, leaking this counter. Replace free_transport() with ksmbd_tcp_disconnect().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23228">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23229</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - Add spinlock protection with virtqueue notification When VM boots with one virtio-crypto PCI device and builtin backend, run openssl benchmark command with multiple processes, such as openssl speed -evp aes-128-cbc -engine afalg -seconds 10 -multi 32 openssl processes will hangup and there is error reported like this: virtio_crypto virtio0: dataq.0:id 3 is not a head! It seems that the data virtqueue need protection when it is handled for virtio done notification. If the spinlock protection is added in virtcrypto_done_task(), openssl benchmark with multiple processes works well.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23229">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/820.html">CWE-820 Missing Synchronization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23230</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitfield byte in struct cached_fid but are updated in different code paths that may run concurrently. Bitfield assignments generate byte read–modify–write operations (e.g. `orb $mask, addr` on x86_64), so updating one flag can restore stale values of the others. A possible interleaving is: CPU1: load old byte (has_lease=1, on_list=1) CPU2: clear both flags (store 0) CPU1: RMW store (old | IS_OPEN) -&gt; reintroduces cleared bits To avoid this class of races, convert these flags to separate bool fields.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23231</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table-&gt;chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then fails, the error path calls nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy() with no RCU grace period in between. This creates two use-after-free conditions: 1) Control-plane: nf_tables_dump_chains() traverses table-&gt;chains under rcu_read_lock(). A concurrent dump can still be walking the chain when the error path frees it. 2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly installs the IPv4 hook before IPv6 registration fails. Packets entering nft_do_chain() via the transient IPv4 hook can still be dereferencing chain-&gt;blob_gen_X when the error path frees the chain. Add synchronize_rcu() between nft_chain_del() and the chain destroy so that all RCU readers -- both dump threads and in-flight packet evaluation -- have finished before the chain is freed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23236</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace. Fix this all up by correctly copying the memory before accessing it within the kernel.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23236">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23238</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: romfs: check sb_set_blocksize() return value romfs_fill_super() ignores the return value of sb_set_blocksize(), which can fail if the requested block size is incompatible with the block device's configuration. This can be triggered by setting a loop device's block size larger than PAGE_SIZE using ioctl(LOOP_SET_BLOCK_SIZE, 32768), then mounting a romfs filesystem on that device. When sb_set_blocksize(sb, ROMBSIZE) is called with ROMBSIZE=4096 but the device has logical_block_size=32768, bdev_validate_blocksize() fails because the requested size is smaller than the device's logical block size. sb_set_blocksize() returns 0 (failure), but romfs ignores this and continues mounting. The superblock's block size remains at the device's logical block size (32768). Later, when sb_bread() attempts I/O with this oversized block size, it triggers a kernel BUG in folio_set_bh(): kernel BUG at fs/buffer.c:1582! BUG_ON(size &gt; PAGE_SIZE); Fix by checking the return value of sb_set_blocksize() and failing the mount with -EINVAL if it returns 0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23238">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24515</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-24515">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.9</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25210</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-25210">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-26157</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-26157">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/73.html">CWE-73 External Control of File Name or Path</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-26158</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-26158">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/73.html">CWE-73 External Control of File Name or Path</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-35535</a></h3>
<div class="csaf-accordion-content">
<p>In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-35535">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/271.html">CWE-271 Privilege Dropping / Lowering Errors</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.4</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-41918</a></h3>
<div class="csaf-accordion-content">
<p>The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-41918">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/525.html">CWE-525 Use of Web Browser Cache Containing Sensitive Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>General Recommendations</h2>
<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>
<hr>
<h2>Additional Resources</h2>
<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>
<hr>
<h2>Terms of Use</h2>
<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-253495 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-02</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-02</td>
<td>1</td>
<td>Publication Date</td>
</tr>
<tr>
<td>2026-07-07</td>
<td>2</td>
<td>Initial CISA Republication of Siemens ProductCERT SSA-253495 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub Thumbs Nose At Sony's Controversial End to Physical Media With Its Introduction of Repo CDs]]></title>
<description><![CDATA[GitHub is offering a limited run of 1,000 CD-ROM copies of public repositories as a pro-physical-media jab at Sony's plan to stop producing PlayStation game discs in 2028. Tom's Hardware reports: The coding and collaboration platform, owned by Microsoft, states that "In light of recent developmen...]]></description>
<link>https://tsecurity.de/de/3650725/it-security-nachrichten/github-thumbs-nose-at-sonys-controversial-end-to-physical-media-with-its-introduction-of-repo-cds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650725/it-security-nachrichten/github-thumbs-nose-at-sonys-controversial-end-to-physical-media-with-its-introduction-of-repo-cds/</guid>
<pubDate>Tue, 07 Jul 2026 09:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GitHub is offering a limited run of 1,000 CD-ROM copies of public repositories as a pro-physical-media jab at Sony's plan to stop producing PlayStation game discs in 2028. Tom's Hardware reports: The coding and collaboration platform, owned by Microsoft, states that "In light of recent developments in physical media, GitHub is proud to announce that you can now obtain your public repo on CD-ROM." Moreover, it appeals to the human side of computing, adding the emotive line "Keep it. Lend it to friends. Pass it on to your children." It isn't April 1st, so thankfully this is no joke. However, if you check out the above-linked GitHub Your Code, On a CD offer page, it quickly becomes clear this is a very limited in time/scope stunt.
 
"Order a burned CD of your own public GitHub repo. Yes, a real physical disc you can hold in your hands, no download required," begins the spiel. But this is a very limited run of 1,000 discs, with applications required between July 2 and July 6 (inclusive). Limit one per person, with availability varying between country/region.
 
"Your code is physically yours, forever. Until you lose it, let's be real," says GitHub. At best, these CDs will be framed and put on a wall, some becoming collector's items or eBay money spinners (discs like 0001 or 0888 would be good ones, if they are numbered). Also, many will be lost or eventually/accidentally discarded, as GitHub seems to know. So this 'protest' is arguably 1,000 doses of expensively shipped e-waste.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GitHub+Thumbs+Nose+At+Sony's+Controversial+End+to+Physical+Media+With+Its+Introduction+of+Repo+CDs%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F07%2F0027252%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F07%2F0027252%2Fgithub-thumbs-nose-at-sonys-controversial-end-to-physical-media-with-its-introduction-of-repo-cds%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/07/07/0027252/github-thumbs-nose-at-sonys-controversial-end-to-physical-media-with-its-introduction-of-repo-cds?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Are Safe A.I. Use Cases for Toddlers?]]></title>
<description><![CDATA[“Use it to enhance, not replace,” advises Dr. Dana Suskind, an early learning specialist who appeared on the “Hard Fork” podcast to share her advice on using A.I. to parent young children.]]></description>
<link>https://tsecurity.de/de/3649517/ai-nachrichten/what-are-safe-ai-use-cases-for-toddlers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649517/ai-nachrichten/what-are-safe-ai-use-cases-for-toddlers/</guid>
<pubDate>Mon, 06 Jul 2026 19:48:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[“Use it to enhance, not replace,” advises Dr. Dana Suskind, an early learning specialist who appeared on the “Hard Fork” podcast to share her advice on using A.I. to parent young children.]]></content:encoded>
</item>
<item>
<title><![CDATA[Fines Doubled As Teens Outsmart Australia's Social Media Ban]]></title>
<description><![CDATA[Australia plans to double fines for social media platforms that fail to keep under-16s off restricted services, after regulators found 70% of children with accounts remained active three months after the ban took effect. The government says the changes will also give the eSafety Commissioner more...]]></description>
<link>https://tsecurity.de/de/3649153/it-security-nachrichten/fines-doubled-as-teens-outsmart-australias-social-media-ban/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649153/it-security-nachrichten/fines-doubled-as-teens-outsmart-australias-social-media-ban/</guid>
<pubDate>Mon, 06 Jul 2026 17:08:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Australia plans to double fines for social media platforms that fail to keep under-16s off restricted services, after regulators found 70% of children with accounts remained active three months after the ban took effect. The government says the changes will also give the eSafety Commissioner more power to demand information from platforms and age-assurance providers as teens continue finding ways around the law. Euronews reports: The government said Sunday it would introduce draft legislation this week doubling the maximum penalty to 99 million Australian dollars (63 million euros) for platforms -- including Facebook, Instagram, Snapchat and TikTok -- that do not take reasonable steps to comply with the ban, which became law on 10 December. Communications Minister Anika Wells blamed the platforms directly. "We can all agree we would like the scheme to work better than it is currently, but that is on Big Tech taking the Mickey," she said, speaking to the Australian Broadcasting Corp on Monday. Wells added that she had received monthly updates from the online safety regulator since March and "we are not seeing improvements."
 
The amendments would also expand the powers of eSafety Commissioner Julie Inman Grant to demand information and documents from platforms -- and from third parties such as age assurance technology providers -- to test claims made by companies about how under-16s continued to circumvent the ban. The government had initially reported more than 5 million children had accounts removed, deactivated or restricted after the legislation passed. But eSafety found in March that 70% of children who held accounts on restricted platforms on the day the ban took effect remained active on Facebook, Instagram, Snapchat and TikTok.
 
Inman Grant said in April she was considering court action against those platforms and YouTube, alleging they were not taking reasonable steps to exclude children. She said she was satisfied with progress made by the remaining restricted platforms: X, Kick, Reddit, Threads and Twitch. Senior opposition lawmaker Jane Hume said her party would consider supporting the reforms, but pinned blame on the original legislation. "The legislation was clearly undercooked in the first place. The eSafety Commissioner wasn't given the powers to be able to pursue these Big Tech companies," she said.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Fines+Doubled+As+Teens+Outsmart+Australia's+Social+Media+Ban%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F06%2F0459219%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F06%2F0459219%2Ffines-doubled-as-teens-outsmart-australias-social-media-ban%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/06/0459219/fines-doubled-as-teens-outsmart-australias-social-media-ban?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The one change that worked: I banned myself from social media – and my children have never been happier]]></title>
<description><![CDATA[I used to think my phone helped me to relax. But setting strict limits on my usage has improved my mood and my relationshipsI am a psychotherapist who works with frazzled, snappy parents, and spend my days writing about why we struggle to find calm. I also used to pick up my phone hundreds of tim...]]></description>
<link>https://tsecurity.de/de/3648438/it-nachrichten/the-one-change-that-worked-i-banned-myself-from-social-media-and-my-children-have-never-been-happier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648438/it-nachrichten/the-one-change-that-worked-i-banned-myself-from-social-media-and-my-children-have-never-been-happier/</guid>
<pubDate>Mon, 06 Jul 2026 12:18:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I used to think my phone helped me to relax. But setting strict limits on my usage has improved my mood and my relationships</p><p>I am a psychotherapist who works with frazzled, snappy parents, and spend my days writing about why we struggle to find calm. I also used to pick up my phone hundreds of times a day, failing to realise that it was making me a snappier, more irritable, less present mother.</p><p>My phone was my office, my income, my means of communication. Every time I checked it, there was something to action, a notification of something new, something that told me I was useful and productive, giving me dopamine hits that motherhood didn’t offer. It had become my coping mechanism.</p> <a href="https://www.theguardian.com/lifeandstyle/2026/jul/06/the-one-change-that-worked-i-banned-myself-from-social-media-and-my-children-have-never-been-happier">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Boston Children’s uses AI to unlock new diagnoses]]></title>
<description><![CDATA[Boston Children’s Hospital uses OpenAI technology to improve patient care, reduce operational burden, and help diagnose more than 40 rare disease cases.]]></description>
<link>https://tsecurity.de/de/3647665/ai-nachrichten/boston-childrens-uses-ai-to-unlock-new-diagnoses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647665/ai-nachrichten/boston-childrens-uses-ai-to-unlock-new-diagnoses/</guid>
<pubDate>Mon, 06 Jul 2026 05:03:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Boston Children’s Hospital uses OpenAI technology to improve patient care, reduce operational burden, and help diagnose more than 40 rare disease cases.]]></content:encoded>
</item>
<item>
<title><![CDATA[Using AI to help physicians diagnose rare genetic diseases affecting children]]></title>
<description><![CDATA[Researchers used an OpenAI reasoning model to help diagnose rare diseases, identifying 18 new diagnoses in previously unsolved cases.]]></description>
<link>https://tsecurity.de/de/3647633/ai-nachrichten/using-ai-to-help-physicians-diagnose-rare-genetic-diseases-affecting-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647633/ai-nachrichten/using-ai-to-help-physicians-diagnose-rare-genetic-diseases-affecting-children/</guid>
<pubDate>Mon, 06 Jul 2026 05:02:54 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers used an OpenAI reasoning model to help diagnose rare diseases, identifying 18 new diagnoses in previously unsolved cases.]]></content:encoded>
</item>
<item>
<title><![CDATA[Trying Season 5 Release Date, Cast and Story: Nikki and Jason Return This Week]]></title>
<description><![CDATA[Trying Season 5 brings Nikki and Jason back this week with a new family problem that can change their home life again. The Apple TV comedy returns on Wednesday, July 8, 2026, and this season follows the couple after Princess and Tyler’s biological mother, Kat, arrives at their doorstep.



Releas...]]></description>
<link>https://tsecurity.de/de/3647010/ios-mac-os/trying-season-5-release-date-cast-and-story-nikki-and-jason-return-this-week/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647010/ios-mac-os/trying-season-5-release-date-cast-and-story-nikki-and-jason-return-this-week/</guid>
<pubDate>Sun, 05 Jul 2026 19:07:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trying Season 5 brings Nikki and Jason back this week with a new family problem that can change their home life again. The Apple TV comedy returns on Wednesday, July 8, 2026, and this season follows the couple after Princess and Tyler’s biological mother, Kat, arrives at their doorstep.



Release Details




Series: Trying Season 5



Genre: Comedy, family drama



Episodes: 8 episodes



Start airing date: July 8, 2026



Finale date: August 26, 2026



Release pattern: One episode weekly every Wednesday



Main cast: Esther Smith, Rafe Spall, Scarlett Rayner, Cooper Turner, Charlotte Riley, Celia Imrie, Phil Davis, Oliver Chris, Roderick Smith and Branka Katić




Plot



Trying Season 5 continues Nikki and Jason’s journey as parents, but this time their settled family life faces a new test. Kat, the biological mother of Princess and Tyler, enters their lives, and her arrival brings confusion, emotions and questions about what family now means for everyone involved.



The new season looks focused on Nikki and Jason trying to protect the home they have built while also understanding Kat’s place in the children’s lives. The story still keeps the warm comedy tone of the series, but the emotional stakes are higher because the kids are older and the family is no longer in the same place it was before.



Spoiler note: The official plot only confirms Kat’s arrival and the chaos that follows. The episode-by-episode twists are not included here.



FAQs



When does Trying Season 5 release? Trying Season 5 premieres on Wednesday, July 8, 2026, on Apple TV.  How many episodes are in Trying Season 5? Trying Season 5 has 8 episodes, with one new episode releasing weekly through August 26, 2026.  Who returns in Trying Season 5? Esther Smith returns as Nikki, and Rafe Spall returns as Jason. Scarlett Rayner and Cooper Turner also return as Princess and Tyler.  What is Trying Season 5 about? The season follows Nikki and Jason as they deal with Kat, the biological mother of Princess and Tyler, coming back into the family picture.  Is Trying Season 5 streaming on Apple TV? Yes, Trying Season 5 streams on Apple TV from July 8, 2026.  



Trying Season 5 arrives at a good time for fans who want a warm, funny and emotional family story this week. Apple TV costs $12.99 per month in the US after the free trial. What do you plan to watch this week? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘In some jobs, they want to be replaced’: Chinese robotics company Agibot says humanoids could take over ‘dangerous’ jobs — and one day even teach children]]></title>
<description><![CDATA[At Agibot's UK launch event, an executive for the Chinese company spoke on its bold vision for the future of work.]]></description>
<link>https://tsecurity.de/de/3645556/it-nachrichten/in-some-jobs-they-want-to-be-replaced-chinese-robotics-company-agibot-says-humanoids-could-take-over-dangerous-jobs-and-one-day-even-teach-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645556/it-nachrichten/in-some-jobs-they-want-to-be-replaced-chinese-robotics-company-agibot-says-humanoids-could-take-over-dangerous-jobs-and-one-day-even-teach-children/</guid>
<pubDate>Sat, 04 Jul 2026 18:03:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At Agibot's UK launch event, an executive for the Chinese company spoke on its bold vision for the future of work.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK parents warned over posting images of children amid AI sexual abuse fears]]></title>
<description><![CDATA[Exclusive: National Crime Agency and safety watchdog issue guidance amid rise in explicit material onlineAnalysis | AI prey: why watchdogs are telling parents to protect children from nudification appsThe UK National Crime Agency has recommended parents should not put photos of their children on ...]]></description>
<link>https://tsecurity.de/de/3643475/ai-nachrichten/uk-parents-warned-over-posting-images-of-children-amid-ai-sexual-abuse-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643475/ai-nachrichten/uk-parents-warned-over-posting-images-of-children-amid-ai-sexual-abuse-fears/</guid>
<pubDate>Fri, 03 Jul 2026 14:04:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Exclusive: National Crime Agency and safety watchdog issue guidance amid rise in explicit material online</p><ul><li><p><a href="https://www.theguardian.com/society/2026/jul/03/ai-prey-watchdogs-telling-parents-protect-children-nudification-apps">Analysis | AI prey: why watchdogs are telling parents to protect children from nudification apps</a></p></li></ul><p>The UK National Crime Agency has recommended parents should not put photos of their children on public display online as part of landmark guidance to tackle the rise of AI-generated sexual abuse material.</p><p>Advice issued by the NCA and the child safety watchdog the Internet Watch Foundation suggests parents and guardians make their social media accounts private or share pictures of their children through a “close friends” group.</p> <a href="https://www.theguardian.com/society/2026/jul/03/ai-sexual-abuse-fears-uk-parents-warned-posting-images-children-national-crime-agency">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI prey: why watchdogs are telling parents to protect children from nudification apps]]></title>
<description><![CDATA[As imaging tools become more sophisticated, online predators are using images of children to make extreme pornographyUK parents warned over posting images of children amid AI sexual abuse fearsThe two photos started out as typical teenage selfies: looking into the mirror, fully clothed. But once ...]]></description>
<link>https://tsecurity.de/de/3643474/ai-nachrichten/ai-prey-why-watchdogs-are-telling-parents-to-protect-children-from-nudification-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643474/ai-nachrichten/ai-prey-why-watchdogs-are-telling-parents-to-protect-children-from-nudification-apps/</guid>
<pubDate>Fri, 03 Jul 2026 14:04:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As imaging tools become more sophisticated, online predators are using images of children to make extreme pornography</p><ul><li><p><a href="https://www.theguardian.com/society/2026/jul/03/ai-sexual-abuse-fears-uk-parents-warned-posting-images-children-national-crime-agency">UK parents warned over posting images of children amid AI sexual abuse fears</a></p></li></ul><p>The two photos started out as typical teenage selfies: looking into the mirror, fully clothed. But once online predators had got hold of those pictures and ran them through an AI imaging tool, they had become the basis for extreme pornography videos.</p><p>These examples come from the <a href="https://www.childline.org.uk/info-advice/bullying-abuse-safety/online-mobile-safety/report-remove/">Report Remove</a> service, which allows children who have had explicit pictures of themselves distributed without their consent to flag the image confidentially and have it blocked or taken down from social media. Due to breakthroughs in AI, and the wide availability of AI models and <a href="https://www.theguardian.com/technology/2025/apr/28/what-are-nudification-apps-how-would-uk-ban-work">nudification apps</a>, some under-18s are becoming victims without even being in contact with criminals.</p> <a href="https://www.theguardian.com/society/2026/jul/03/ai-prey-watchdogs-telling-parents-protect-children-nudification-apps">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Every New Apple TV Movie Coming After Silo Season 3]]></title>
<description><![CDATA[Apple TV has several new movies lined up after the Silo season 3 premiere, and the upcoming schedule covers sports comedy, spy action, adventure, real-life drama, and a coming-of-age story. 



These five Apple TV movies arrive between July and November, giving subscribers a steady run of new rel...]]></description>
<link>https://tsecurity.de/de/3641734/ios-mac-os/every-new-apple-tv-movie-coming-after-silo-season-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641734/ios-mac-os/every-new-apple-tv-movie-coming-after-silo-season-3/</guid>
<pubDate>Thu, 02 Jul 2026 18:27:27 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has several new movies lined up after the Silo season 3 premiere, and the upcoming schedule covers sports comedy, spy action, adventure, real-life drama, and a coming-of-age story. 



These five Apple TV movies arrive between July and November, giving subscribers a steady run of new releases through the second half of the year.



Upcoming Apple TV Movies



MovieRelease DateGenreThe DinkJuly 24Sports ComedyMaydaySeptember 4Espionage Action-ComedyMatchbox The MovieOctober 9Action-AdventureTenzingOctober 16DramaWay of the Warrior KidNovember 25Drama



What’s Coming to Apple TV




The Dink arrives on July 24 with Jake Johnson as Dusty Boyd, a former tennis prodigy who now coaches children at his father’s country club. After an injury stops him from playing tennis, Dusty turns to pickleball and slowly gets pulled into a personal fight involving family approval, old failures, and the future of the club.



Mayday premieres on September 4 and brings Ryan Reynolds and Kenneth Branagh together in an espionage action-comedy set during the Cold War. Reynolds plays a U.S. Navy pilot trapped behind enemy lines, while Branagh plays an ex-KGB agent who becomes part of an unexpected rescue story.



Matchbox The Movie arrives on October 9 as an action-adventure inspired by the classic Mattel toys. John Cena leads the film as Sean, an undercover CIA agent whose return pulls his childhood friends into a global mission.



Tenzing premieres on October 16 and tells the story of Tenzing Norgay, who climbed Mount Everest with Edmund Hillary. The film focuses on ambition, class, respect, and Tenzing’s deep spiritual connection with Chomolungma.



Way of the Warrior Kid arrives on November 25 with Jude Hill and Chris Pratt in a drama about a bullied middle school student whose Navy SEAL uncle helps him build discipline, confidence, and courage.




Apple TV is available for $12.99 per month, and viewers can also get it through the Apple One bundle. Which upcoming Apple TV movie are you most interested in watching? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Announces iPhone Photography Awards 2026 Winners]]></title>
<description><![CDATA[The iPhone Photography Awards 2026 winners have been announced, once again bringing attention to some of the best photos captured on iPhone and iPad devices by users around the world.



The Grand Prize went to Robyn Jensen for a dramatic photo of a volcano erupting in the Cayman Islands, capture...]]></description>
<link>https://tsecurity.de/de/3641602/ios-mac-os/apple-announces-iphone-photography-awards-2026-winners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641602/ios-mac-os/apple-announces-iphone-photography-awards-2026-winners/</guid>
<pubDate>Thu, 02 Jul 2026 17:25:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The iPhone Photography Awards 2026 winners have been announced, once again bringing attention to some of the best photos captured on iPhone and iPad devices by users around the world.



The Grand Prize went to Robyn Jensen for a dramatic photo of a volcano erupting in the Cayman Islands, captured on an iPhone 15 Pro. The image shows how far mobile photography has come, especially when photographers use timing, composition, and natural light well.

















The Gold Prize went to Gellért Gombai for a black-and-white photo of two children sleeping on grass under the shadow of a badminton racket, shot using an iPhone X.



Other winning photos were captured on newer models, including the iPhone 16 Pro and iPhone 16 Pro Max. The contest also named winners across categories such as animals, architecture, landscape, nature, portrait, travel, and still life.



The next entry deadline is March 31, 2027.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Loses Bid To Dismiss US States' Claims That Facebook, Instagram Addict Children]]></title>
<description><![CDATA[A federal judge rejected Meta's bid to dismiss claims from 29 state attorneys general alleging that Facebook and Instagram were designed to addict children while concealing the harms. The judge found significant factual disputes that must be decided at trial. They also ruled that Meta failed to c...]]></description>
<link>https://tsecurity.de/de/3639303/it-security-nachrichten/meta-loses-bid-to-dismiss-us-states-claims-that-facebook-instagram-addict-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639303/it-security-nachrichten/meta-loses-bid-to-dismiss-us-states-claims-that-facebook-instagram-addict-children/</guid>
<pubDate>Wed, 01 Jul 2026 19:38:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A federal judge rejected Meta's bid to dismiss claims from 29 state attorneys general alleging that Facebook and Instagram were designed to addict children while concealing the harms. The judge found significant factual disputes that must be decided at trial. They also ruled that Meta failed to comply with federal parental notice and consent requirements for children under 13, "and granted summary judgement to the states on that issue," reports Reuters. From the report: In a separate statement, California Attorney General Rob Bonta called the decision a "critical win" in holding Meta accountable for fueling a mental health crisis among American children. Gonzalez Rogers also oversees related multidistrict litigation by more than 2,600 individuals, school districts and local governments over whether social media platforms such as Facebook, Instagram, Google and YouTube, Snapchat and TikTok addict children.
 
The states said research has shown that children's use of Facebook and Instagram could lead to depression, anxiety, insomnia, interference with education and daily life, and self-harm including suicide. Meta countered that the attorneys general had no evidence it misled consumers about its platforms' alleged addictiveness, including in congressional testimony by Chief Executive Mark Zuckerberg. The Menlo Park, California-based company said this was because "social media addiction" is not an established psychiatric condition, and therefore statements that its platforms are not addictive could not be false. Meta also said it didn't violate the children's online privacy law because it directed Facebook and Instagram to a general audience, not just children under age 13.
 
In a 38-page decision, Gonzalez Rogers found material factual disputes over whether Meta's social media platforms are addictive, whether Meta falsely denied it designed them that way, and whether it "partially" directed the platforms at children. "The AGs present a reasonable interpretation of [Meta's] statements that Facebook and Instagram are not designed in ways that cause teens to compulsively use the platforms to their detriment," the judge wrote. "To the extent plaintiffs' evidence shows that the platforms are in fact designed to do just that, a jury could reasonably find the statements were untrue to a reasonable person," she added. A trial over California, Colorado, Kentucky and New Jersey's claims against Meta is scheduled for August 18, court records show. Further reading: Will Social Media Change After YouTube and Meta's Court Defeat?<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Loses+Bid+To+Dismiss+US+States'+Claims+That+Facebook%2C+Instagram+Addict+Children%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F01%2F1721251%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F01%2F1721251%2Fmeta-loses-bid-to-dismiss-us-states-claims-that-facebook-instagram-addict-children%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/01/1721251/meta-loses-bid-to-dismiss-us-states-claims-that-facebook-instagram-addict-children?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UAE Becomes First Arab Nation to Ban Social Media for Children Under 15]]></title>
<description><![CDATA[  The United Arab Emirates has become the first Arab nation to impose a comprehensive ban on social media use for children under the age of 15, marking a significant milestone in digital child protection. Announced in mid-June 2026 through…
Read more →
The post UAE Becomes First Arab Nation to Ba...]]></description>
<link>https://tsecurity.de/de/3639177/it-security-nachrichten/uae-becomes-first-arab-nation-to-ban-social-media-for-children-under-15/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639177/it-security-nachrichten/uae-becomes-first-arab-nation-to-ban-social-media-for-children-under-15/</guid>
<pubDate>Wed, 01 Jul 2026 18:37:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  The United Arab Emirates has become the first Arab nation to impose a comprehensive ban on social media use for children under the age of 15, marking a significant milestone in digital child protection. Announced in mid-June 2026 through…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/uae-becomes-first-arab-nation-to-ban-social-media-for-children-under-15/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/uae-becomes-first-arab-nation-to-ban-social-media-for-children-under-15/">UAE Becomes First Arab Nation to Ban Social Media for Children Under 15</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We can live without AI, but can we live without clean water? | Letters]]></title>
<description><![CDATA[Readers respond to an article about Erin Brockovich’s battle against datacentres and voice their fears for the environment What are the benefits obtained from AI’s massive use of electricity and water (‘We’re up against forces that have all the money in the world’: Erin Brockovich on her battle a...]]></description>
<link>https://tsecurity.de/de/3639151/ai-nachrichten/we-can-live-without-ai-but-can-we-live-without-clean-water-letters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639151/ai-nachrichten/we-can-live-without-ai-but-can-we-live-without-clean-water-letters/</guid>
<pubDate>Wed, 01 Jul 2026 18:19:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Readers respond to an article about Erin Brockovich’s battle against datacentres and voice their fears for the environment </p><p>What are the benefits obtained from AI’s massive use of electricity and water (<a href="https://www.theguardian.com/environment/2026/jun/29/were-up-against-forces-that-have-all-the-money-in-the-world-erin-brockovich-on-her-battle-against-ai-datacentres">‘We’re up against forces that have all the money in the world’: Erin Brockovich on her battle against AI datacentres, 29 June</a>)? Analysis shows that <a href="https://hbr.org/2026/06/how-people-are-really-using-ai-in-2026">the top four uses of AI</a> are “therapy/companionship”, “technical assistance and troubleshooting”, “fun and nonsense”, and “fan fiction and storytelling”.</p><p>AI use for therapy, and due to loneliness, appears not to reduce loneliness. AI provides affirmation, but at the expense of reducing the social skills needed to interact in the real world. Teachers report that students’ use of AI <a href="https://www.theguardian.com/technology/2026/apr/02/pupils-england-losing-thinking-skills-because-of-ai-survey">reduces their capacity for critical thinking</a>.</p> <a href="https://www.theguardian.com/technology/2026/jul/01/we-can-live-without-ai-but-can-we-live-without-clean-water">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hegseth “Max Lethality” in Iran Kills Children Faster Than My Lai]]></title>
<description><![CDATA[The war crimes were predicted, such that prevention was deliberately removed. This combination, say experts, means Hegseth created war crimes by policy. It was Hegseth’s 2026 attempt to make America look even more brutal and worse than the My Lai massacre. One former Pentagon official, similarly ...]]></description>
<link>https://tsecurity.de/de/3638891/it-security-nachrichten/hegseth-max-lethality-in-iran-kills-children-faster-than-my-lai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638891/it-security-nachrichten/hegseth-max-lethality-in-iran-kills-children-faster-than-my-lai/</guid>
<pubDate>Wed, 01 Jul 2026 16:50:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The war crimes were predicted, such that prevention was deliberately removed. This combination, say experts, means Hegseth created war crimes by policy. It was Hegseth’s 2026 attempt to make America look even more brutal and worse than the My Lai massacre. One former Pentagon official, similarly speaking on condition of anonymity, said the bombing came … <a href="https://www.flyingpenguin.com/hegseth-max-lethality-my-lai/" class="more-link">Continue reading <span class="screen-reader-text">Hegseth “Max Lethality” in Iran Kills Children Faster Than My Lai</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hegseth “Max Lethality” in Iran Kills Children Faster Than My Lai]]></title>
<description><![CDATA[The war crimes were predicted, such that prevention was deliberately removed. This combination, say experts, means Hegseth created war crimes by policy. It was Hegseth’s 2026 attempt to make America look even more brutal and worse than the My Lai massacre. One former Pentagon official, similarly ...]]></description>
<link>https://tsecurity.de/de/3638799/it-security-nachrichten/hegseth-max-lethality-in-iran-kills-children-faster-than-my-lai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638799/it-security-nachrichten/hegseth-max-lethality-in-iran-kills-children-faster-than-my-lai/</guid>
<pubDate>Wed, 01 Jul 2026 16:24:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The war crimes were predicted, such that prevention was deliberately removed. This combination, say experts, means Hegseth created war crimes by policy. It was Hegseth’s 2026 attempt to make America look even more brutal and worse than the My Lai massacre. One former Pentagon official, similarly speaking on condition of anonymity, said the bombing came … <a href="https://www.flyingpenguin.com/82031-2/" class="more-link">Continue reading <span class="screen-reader-text">Hegseth “Max Lethality” in Iran Kills Children Faster Than My Lai</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Yoto Music Box Is a Ray of Hope Amid the ‘Techlash’]]></title>
<description><![CDATA[Amid widespread “techlash” over addictive screens and apps, the Yoto, an audio player for children, shows there’s still a way to make money while doing something nice.]]></description>
<link>https://tsecurity.de/de/3637947/it-nachrichten/the-yoto-music-box-is-a-ray-of-hope-amid-the-techlash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637947/it-nachrichten/the-yoto-music-box-is-a-ray-of-hope-amid-the-techlash/</guid>
<pubDate>Wed, 01 Jul 2026 11:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amid widespread “techlash” over addictive screens and apps, the Yoto, an audio player for children, shows there’s still a way to make money while doing something nice.]]></content:encoded>
</item>
<item>
<title><![CDATA[This month in security with Tony Anscombe – June 2026 edition]]></title>
<description><![CDATA[Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026 This article has been indexed from WeLiveSecurity Read the original article: This month in…
Read more →
The post This month in...]]></description>
<link>https://tsecurity.de/de/3637750/it-security-nachrichten/this-month-in-security-with-tony-anscombe-june-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637750/it-security-nachrichten/this-month-in-security-with-tony-anscombe-june-2026-edition/</guid>
<pubDate>Wed, 01 Jul 2026 09:36:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026 This article has been indexed from WeLiveSecurity Read the original article: This month in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/this-month-in-security-with-tony-anscombe-june-2026-edition/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/this-month-in-security-with-tony-anscombe-june-2026-edition/">This month in security with Tony Anscombe – June 2026 edition</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This month in security with Tony Anscombe – June 2026 edition]]></title>
<description><![CDATA[Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026]]></description>
<link>https://tsecurity.de/de/3637663/malware-trojaner-viren/this-month-in-security-with-tony-anscombe-june-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637663/malware-trojaner-viren/this-month-in-security-with-tony-anscombe-june-2026-edition/</guid>
<pubDate>Wed, 01 Jul 2026 09:03:30 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026]]></content:encoded>
</item>
<item>
<title><![CDATA[US House Passes KIDS Act, Advancing Child Safety While Privacy Advocates Warn of Universal Age Verification]]></title>
<description><![CDATA[The United States House of Representatives has approved an extensive online safety bill. Those supporting this legislation argue that it’ll help to protect children better. But privacy advocates worry that it will change how millions of US residents use the internet. The KIDS (Kids Internet and D...]]></description>
<link>https://tsecurity.de/de/3636427/it-security-nachrichten/us-house-passes-kids-act-advancing-child-safety-while-privacy-advocates-warn-of-universal-age-verification/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636427/it-security-nachrichten/us-house-passes-kids-act-advancing-child-safety-while-privacy-advocates-warn-of-universal-age-verification/</guid>
<pubDate>Tue, 30 Jun 2026 19:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The United States House of Representatives has approved an extensive online safety bill. Those supporting this legislation argue that it’ll help to protect children better. But privacy advocates worry that it will change how millions of US residents use the internet. The KIDS (Kids Internet and Digital Safety) Act received a bipartisan vote of 267-117 […]</p>
<p>The post <a href="https://privacysavvy.com/news/cybersecurity/us-house-passes-kids-act-online-child-safety/">US House Passes KIDS Act, Advancing Child Safety While Privacy Advocates Warn of Universal Age Verification</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Supreme Court stops Trump’s attempt to end birthright citizenship]]></title>
<description><![CDATA[The Supreme Court upheld birthright citizenship, ruling 6-3 against President Donald Trump's effort to end the longstanding constitutional right via executive order. Birthright citizenship dates back to Reconstruction. Under the 14th Amendment, which was ratified in 1868 to guarantee citizenship ...]]></description>
<link>https://tsecurity.de/de/3636033/it-nachrichten/the-supreme-court-stops-trumps-attempt-to-end-birthright-citizenship/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636033/it-nachrichten/the-supreme-court-stops-trumps-attempt-to-end-birthright-citizenship/</guid>
<pubDate>Tue, 30 Jun 2026 17:03:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Supreme Court upheld birthright citizenship, ruling 6-3 against President Donald Trump's effort to end the longstanding constitutional right via executive order. Birthright citizenship dates back to Reconstruction. Under the 14th Amendment, which was ratified in 1868 to guarantee citizenship and equal protection to the children of formerly enslaved people, anyone born in the United […]]]></content:encoded>
</item>
<item>
<title><![CDATA[This month in security with Tony Anscombe – June 2026 edition]]></title>
<description><![CDATA[Author: ESET - Bewertung: 0x - Views:2 It's that time of month when ESET Chief Security Evangelist Tony Anscombe (https://www.welivesecurity.com/en/our-experts/tony-anscombe/)  looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what th...]]></description>
<link>https://tsecurity.de/de/3635962/it-security-video/this-month-in-security-with-tony-anscombe-june-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635962/it-security-video/this-month-in-security-with-tony-anscombe-june-2026-edition/</guid>
<pubDate>Tue, 30 Jun 2026 16:47:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: ESET - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/HBx8LyXsWoY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>It's that time of month when ESET Chief Security Evangelist Tony Anscombe (https://www.welivesecurity.com/en/our-experts/tony-anscombe/)  looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses. Here's some of what caught Tony's attention in June 2026:<br />
 <br />
• The US Cybersecurity and Infrastructure Security Agency (CISA) has issued new vulnerability patching rules (https://www.darkreading.com/cyber-risk/cisa-rewrites-federal-patching-requirements-ai-threat-era) that require federal agencies to remediate the most dangerous vulnerabilities within three days,<br />
• Cyberattackers are taking aim (https://www.bleepingcomputer.com/news/security/over-900-us-gas-station-tank-gauge-systems-exposed-to-attacks/) at Internet-exposed automatic tank gauge (ATG) systems in the United States, according to a warning (https://www.ic3.gov/CSA/2026/260602.pdf) by several US government agencies,<br />
• Americans lost $3.5 billion (https://www.bleepingcomputer.com/news/security/ftc-warns-of-record-35-billion-losses-to-imposter-scams-in-2025/) to imposter scams in 2025, with reported losses nearly tripling since 2020, according to the U.S. Federal Trade Commission (FTC),<br />
• The UK and Canada are planning to introduce a ban on social media (https://www.darkreading.com/cyber-risk/uk-social-media-ban-privacy-experts-worried) use by children under the age of 16.<br />
 <br />
What lessons does the new CISA policy hold for organizations outside the agency's direct remit? What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems? How can you stay safe from imposter fraud (https://www.welivesecurity.com/en/scams/many-faces-impersonation-fraud-spot-imposter-too-late/), and could the social media bans for children work? Learn more from Tony's video and be sure to check out the May 2026 edition (https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-may-2026/) of Tony's monthly security news roundup for more insights.<br />
 <br />
All this – and more – on https://www.welivesecurity.com/en/ <br />
Connect with us on: https://www.facebook.com/eset, https://x.com/ESET, https://www.linkedin.com/company/eset/ and https://www.instagram.com/eset/.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[More NI Schools Warned After C2K Network Hack]]></title>
<description><![CDATA[Education Authority tells parents at 16 additional schools that personal data of children may have been stolen in C2K breach This article has been indexed from Silicon UK Read the original article: More NI Schools Warned After C2K Network Hack
Read more →
The post More NI Schools Warned After C2K...]]></description>
<link>https://tsecurity.de/de/3634924/it-security-nachrichten/more-ni-schools-warned-after-c2k-network-hack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634924/it-security-nachrichten/more-ni-schools-warned-after-c2k-network-hack/</guid>
<pubDate>Tue, 30 Jun 2026 10:20:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Education Authority tells parents at 16 additional schools that personal data of children may have been stolen in C2K breach This article has been indexed from Silicon UK Read the original article: More NI Schools Warned After C2K Network Hack</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/more-ni-schools-warned-after-c2k-network-hack/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/more-ni-schools-warned-after-c2k-network-hack/">More NI Schools Warned After C2K Network Hack</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hundreds of Trump Forced Deportees Feared Dead]]></title>
<description><![CDATA[Trump used forced deportations to put hundreds of Venezuelans into a detention facility that collapsed into rubble. They are now missing and feared dead. A deportation flight from Miami arrived in Venezuela hours before Wednesday’s earthquakes. On board were 146 Venezuelans, including 19 women an...]]></description>
<link>https://tsecurity.de/de/3634817/it-security-nachrichten/hundreds-of-trump-forced-deportees-feared-dead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634817/it-security-nachrichten/hundreds-of-trump-forced-deportees-feared-dead/</guid>
<pubDate>Tue, 30 Jun 2026 09:22:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trump used forced deportations to put hundreds of Venezuelans into a detention facility that collapsed into rubble. They are now missing and feared dead. A deportation flight from Miami arrived in Venezuela hours before Wednesday’s earthquakes. On board were 146 Venezuelans, including 19 women and seven children, according to ICE Flight Monitor, an initiative of … <a href="https://www.flyingpenguin.com/hundreds-of-trump-forced-deportees-feared-dead/" class="more-link">Continue reading <span class="screen-reader-text">Hundreds of Trump Forced Deportees Feared Dead</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Half of social media child safety features don't work, report claims]]></title>
<description><![CDATA[A new report found half of social media safety features intended to keep children safe online do not work as claimed.]]></description>
<link>https://tsecurity.de/de/3633489/it-nachrichten/half-of-social-media-child-safety-features-dont-work-report-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633489/it-nachrichten/half-of-social-media-child-safety-features-dont-work-report-claims/</guid>
<pubDate>Mon, 29 Jun 2026 18:18:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new report found half of social media safety features intended to keep children safe online do not work as claimed.]]></content:encoded>
</item>
<item>
<title><![CDATA[This Day in History: 1876 Custer Assault on Women and Children Destroyed at Little Big Horn]]></title>
<description><![CDATA[Today in America we remember how Custer’s men didn’t make a stand, and instead collapsed and scattered into chaos when they were confronted by American Native warriors along the Little Bighorn River in southeastern Montana Territory. If Custer stood for anything, it was the Epstein-like kidnappin...]]></description>
<link>https://tsecurity.de/de/3632678/it-security-nachrichten/this-day-in-history-1876-custer-assault-on-women-and-children-destroyed-at-little-big-horn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632678/it-security-nachrichten/this-day-in-history-1876-custer-assault-on-women-and-children-destroyed-at-little-big-horn/</guid>
<pubDate>Mon, 29 Jun 2026 12:52:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today in America we remember how Custer’s men didn’t make a stand, and instead collapsed and scattered into chaos when they were confronted by American Native warriors along the Little Bighorn River in southeastern Montana Territory. If Custer stood for anything, it was the Epstein-like kidnapping of young girls to “force surrender” as blackmail. On … <a href="https://www.flyingpenguin.com/this-day-in-history-1876-custer-assault-on-women-and-children-destroyed-at-little-big-horn/" class="more-link">Continue reading <span class="screen-reader-text">This Day in History: 1876 Custer Assault on Women and Children Destroyed at Little Big Horn</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears]]></title>
<description><![CDATA[The National Design Studio, staffed by Doge veterans, installed visitor-tracking software on vital federal websitesAn opaque White House office staffed largely by veterans of Elon Musk’s “department of government efficiency” (Doge) has quietly rebuilt some of the federal government’s most sensiti...]]></description>
<link>https://tsecurity.de/de/3631850/it-nachrichten/its-dangerous-and-its-going-to-erode-trust-redesign-of-us-government-websites-stokes-surveillance-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631850/it-nachrichten/its-dangerous-and-its-going-to-erode-trust-redesign-of-us-government-websites-stokes-surveillance-fears/</guid>
<pubDate>Mon, 29 Jun 2026 05:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The National Design Studio, staffed by Doge veterans, installed visitor-tracking software on vital federal websites</p><p>An opaque White House office staffed largely by veterans of Elon Musk’s “department of government efficiency” (Doge) has quietly rebuilt some of the federal government’s most sensitive websites – for passport applications, voter registration, prescription-drug pricing and children’s savings – in ways critics say appear to violate federal law.</p><p>The <a href="https://ndstudio.gov/">National Design Studio</a> (NDS) was established by a <a href="https://www.theguardian.com/us-news/donaldtrump">Donald Trump</a> executive order last August, and is led by <a href="https://www.theguardian.com/us-news/2025/nov/23/trump-musk-doge-reportedly-disbanded">Trump-aligned Airbnb co-founder Joe Gebbia</a> and staffed by Doge veterans.</p> <a href="https://www.theguardian.com/us-news/2026/jun/28/government-website-visitor-tracking-surveillance-fears">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Create App Schedules for School Hours in iOS 27]]></title>
<description><![CDATA[Apple has expanded Screen Time in iOS 27 with a new App Schedules feature that gives parents much better control over when children can use specific apps. Instead of relying only on daily time limits, you can now create schedules for different parts of the day, including before school, school hou...]]></description>
<link>https://tsecurity.de/de/3630978/ios-mac-os/how-to-create-app-schedules-for-school-hours-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630978/ios-mac-os/how-to-create-app-schedules-for-school-hours-in-ios-27/</guid>
<pubDate>Sun, 28 Jun 2026 13:38:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has expanded Screen Time in iOS 27 with a new App Schedules feature that gives parents much better control over when children can use specific apps. Instead of relying only on daily time limits, you can now create schedules for different parts of the day, including before school, school hours, after school, homework time, evenings, weekends, and holidays. This helps reduce distractions while still allowing access to essential apps when needed.



If your family uses Family Sharing and your child's devices are running iOS 27 or the latest compatible Apple software, setting up school hour schedules only takes a few minutes.



Table of contentsCreate App Schedules for School HoursCreate Different Schedules for the Entire DayAllow Essential Apps During School HoursAdd Time Limits Alongside App SchedulesCreate Separate Weekend SchedulesPause or Change App Access InstantlyFAQsSummaryConclusion



Create App Schedules for School Hours







The new App Schedules feature is part of the redesigned Screen Time experience in iOS 27. It lets parents decide exactly which apps remain available during different times of the day.




Open Settings on the parent's iPhone.



Tap Screen Time.



Select your child's profile.



Open Schedules.



Tap Create Schedule.



Choose a schedule name such as School Hours.



Select the days the schedule should apply, such as Monday through Friday.



Set the start and end time for school.



Choose which apps or app categories remain available.



Save the schedule.




During school hours, only the apps you allow remain accessible while the rest stay restricted until the schedule ends.



Create Different Schedules for the Entire Day



You are not limited to a single schedule. iOS 27 lets you build multiple schedules that automatically switch throughout the day.




Go to Settings &gt; Screen Time &gt; Schedules.



Tap Add Schedule.



Create separate schedules such as:

Before School



School Hours



After School



Homework



Bedtime





Set different times for each schedule.



Save your changes.




Parents can also create separate schedules for weekends, holidays, and early school dismissal days.



Allow Essential Apps During School Hours



Even while restrictions are active, important apps can stay available.



For example, you may want your child to continue using Phone, Messages, Calculator, Maps, School learning apps, and Emergency contacts.




Open Settings.



Tap Screen Time.



Select your child's account.



Open Always Allowed.



Add the apps and contacts you want available at all times.



Save the settings.




These apps remain accessible even when a schedule is active.



Add Time Limits Alongside App Schedules



App Schedules work well with Screen Time's daily limits. For example, you can block games during school and still limit gaming to one hour after school.




Go to Settings &gt; Screen Time.



Tap Time Allowances or App Limits.



Select an app category such as Games or Social Media.



Set the daily limit.



Save your changes.




Using schedules together with time limits gives parents much more flexibility than older versions of Screen Time.



Create Separate Weekend Schedules



Weekend routines are often different from school days.




Open Screen Time.



Tap Schedules.



Create a new schedule.



Select Saturday and Sunday.



Choose different app availability and times.



Save the schedule.




You can also create custom schedules for vacations, exam periods, or public holidays.



Pause or Change App Access Instantly



Sometimes you may need to change restrictions without editing every schedule.




Open Settings.



Go to Screen Time.



Select your child's device.



Pause access or temporarily allow additional apps.



Changes take effect immediately.




This is useful if your child needs extra time for homework, travel, or a special event.



FAQs



Does App Schedules require iOS 27? Yes. The new App Schedules feature is part of the redesigned Screen Time experience introduced in iOS 27. For Family Sharing, all participating devices should run the latest compatible Apple software for full functionality.  Can I create different schedules for weekdays and weekends? Yes. You can build separate schedules for weekdays, weekends, holidays, and other custom situations such as early school release days.  Can school apps stay available during restrictions? Yes. You can choose which apps remain available during a schedule by using the allowed apps settings, ensuring educational and emergency apps continue to work.  Does App Schedules replace App Limits? No. App Schedules controls when apps are available, while App Limits or Time Allowances control how long apps can be used. Both features work together.  Can I manage my child's iPhone remotely? Yes. Parents using Family Sharing can manage Screen Time settings from their own Apple device.  



Summary




iOS 27 introduces App Schedules as part of the redesigned Screen Time experience.



Parents can create schedules for school hours, homework, bedtime, weekends, and holidays.



Essential apps and contacts can remain available during restricted periods.



App Schedules works alongside Time Allowances and App Limits for better control.



Family Sharing makes it easy to manage children's devices from a parent's iPhone.



Multiple custom schedules help children stay focused while maintaining access to important apps.




Conclusion



The new App Schedules feature in iOS 27 gives parents far more control over how children use their devices throughout the day. Whether you want to block games during class, allow only educational apps during homework, or create different routines for weekends and holidays, the updated Screen Time tools make the process simple. Combined with App Limits, Time Allowances, and Always Allowed apps, App Schedules helps families build healthier digital habits while keeping essential communication available when it matters.]]></content:encoded>
</item>
<item>
<title><![CDATA[Social media bans go global: big tech faces a reckoning after Australia’s crackdown]]></title>
<description><![CDATA[As a host of countries move to rein in social media use by children, could this be technology’s big tobacco moment? Continue reading...]]></description>
<link>https://tsecurity.de/de/3628997/ai-nachrichten/social-media-bans-go-global-big-tech-faces-a-reckoning-after-australias-crackdown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628997/ai-nachrichten/social-media-bans-go-global-big-tech-faces-a-reckoning-after-australias-crackdown/</guid>
<pubDate>Sat, 27 Jun 2026 07:04:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As a host of countries move to rein in social media use by children, could this be technology’s big tobacco moment?</p> <a href="https://www.theguardian.com/news/ng-interactive/2026/jun/27/social-media-bans-go-global-big-tech-reckoning-australia-crackdown">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Es reicht (fusion26)]]></title>
<description><![CDATA[Zwischen Durchdrehen und Klarkommen- eine musikalische Performance über Mutterschaft und darüber, was die Erwartungen und das Scheitern daran mit uns allen zu tun haben. Zum Lachen und Weinen und wütend Werden und Mtsingen. Von Elikya.

Theater + Q&A

Language: DE Translation: NO Video Recording...]]></description>
<link>https://tsecurity.de/de/3628314/it-security-video/es-reicht-fusion26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628314/it-security-video/es-reicht-fusion26/</guid>
<pubDate>Fri, 26 Jun 2026 20:19:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zwischen Durchdrehen und Klarkommen- eine musikalische Performance über Mutterschaft und darüber, was die Erwartungen und das Scheitern daran mit uns allen zu tun haben. Zum Lachen und Weinen und wütend Werden und Mtsingen. Von Elikya.

Theater + Q&amp;A

Language: DE Translation: NO Video Recording: YES

For all parents who lost a child and all children who lost a parent. For all who never became mothers. For all who never wanted to become mothers. For all who had to go through miscarriages. For all who can not get pregnant. For all adoptive parents. For all parents who have put a child up for adoption. For all who have terminated a pregnancy. For all who provide abortion services. For all the caregivers who moved from other countries to care for our parents and are missed by their own families. For all chosen families.

Theater + Q&amp;A

Language: DE Translation: NO Video Recording: YES

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Killing the Internet: inside the global movement that wants to save the open web]]></title>
<description><![CDATA[As the UK joins the list of countries that want to ban teens from social media, a group of gamers and digital rights activists have come together to prevent the loss of internet freedom, under the guise of protecting children's online safety, and promote evidence-based alternative measures.]]></description>
<link>https://tsecurity.de/de/3627054/it-nachrichten/stop-killing-the-internet-inside-the-global-movement-that-wants-to-save-the-open-web/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627054/it-nachrichten/stop-killing-the-internet-inside-the-global-movement-that-wants-to-save-the-open-web/</guid>
<pubDate>Fri, 26 Jun 2026 12:31:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As the UK joins the list of countries that want to ban teens from social media, a group of gamers and digital rights activists have come together to prevent the loss of internet freedom, under the guise of protecting children's online safety, and promote evidence-based alternative measures.]]></content:encoded>
</item>
<item>
<title><![CDATA[From blocking out plane noise to keeping up with your LED light-therapy routine, I've handpicked 15 beauty tech deals for your next holiday]]></title>
<description><![CDATA[From Nanoleaf's light-therapy wand to the Oura Ring 4, here are the beauty tech deals worth making room for in your suitcase.]]></description>
<link>https://tsecurity.de/de/3624418/it-nachrichten/from-blocking-out-plane-noise-to-keeping-up-with-your-led-light-therapy-routine-ive-handpicked-15-beauty-tech-deals-for-your-next-holiday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624418/it-nachrichten/from-blocking-out-plane-noise-to-keeping-up-with-your-led-light-therapy-routine-ive-handpicked-15-beauty-tech-deals-for-your-next-holiday/</guid>
<pubDate>Thu, 25 Jun 2026 14:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From Nanoleaf's light-therapy wand to the Oura Ring 4, here are the beauty tech deals worth making room for in your suitcase.]]></content:encoded>
</item>
<item>
<title><![CDATA[What CIOs must do after the board meeting]]></title>
<description><![CDATA[Ahead of board meetings, CIOs refine slides, rehearse talking points, anticipate questions, and align with the executive team. Then they walk in, deliver their presentation, answer a few questions, and breathe a sigh of relief when it’s over.



The problem, according to several experienced CIOs-...]]></description>
<link>https://tsecurity.de/de/3624013/it-nachrichten/what-cios-must-do-after-the-board-meeting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624013/it-nachrichten/what-cios-must-do-after-the-board-meeting/</guid>
<pubDate>Thu, 25 Jun 2026 12:02:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ahead of board meetings, CIOs refine slides, rehearse talking points, anticipate questions, and align with the executive team. Then they walk in, deliver their presentation, answer a few questions, and breathe a sigh of relief when it’s over.</p>



<p>The problem, according to several experienced CIOs-turned-board-directors, is that many tech leaders treat the board meeting as a discrete event rather than part of a relationship.</p>



<p>“The board meeting is an ongoing dialogue, not an event,” says Ron Guerrier, CTO of Save the Children who’s sat on or advised several boards.</p>



<p>That mindset shift becomes increasingly important as boards dig deeper on issues like cyber risk, AI governance, and major enterprise initiatives. So while CIOs often focus on the presentation itself, experienced boardroom veterans say what happens after can be just as critical.</p>



<h2 class="wp-block-heading">Keep the conversation going</h2>



<p>One of the biggest mistakes CIOs make is viewing board engagement as a quarterly obligation. Once the meeting ends, they return to their day jobs and wait for the next board cycle to begin. For Guerrier, that misses the point.</p>



<p>The strongest <a href="https://www.cio.com/article/4149185/the-inside-track-on-how-boards-evaluate-their-cios.html?utm=hybrid_search">CIO-board relationships</a> are built over time through a series of conversations, not quarterly presentations. Questions raised during a board meeting shouldn’t disappear into the next reporting cycle. Instead, CIOs should view them as signals about what directors prioritize and where future conversations should focus.</p>



<p>That doesn’t mean bombarding directors with updates, though. It means remaining engaged, responsive, and thoughtful between meetings. The most effective CIOs understand that every board interaction contributes to a broader relationship built on trust and credibility.</p>



<h2 class="wp-block-heading">Reflect before you react</h2>



<p>The instinct after a board meeting is often to move immediately to follow-up actions, answer outstanding questions, and get back to the daily demands of running IT.</p>



<p>CIOs should resist that urge, says Sigal Zarmi, former CIO and current public-company board director. “The most important thing is to step back and think what resonated with the board,” she says. “What were the questions, what really piqued their interests, and what’s the board focusing on.”</p>



<p>Board questions often provide insight into the main things directors care about, whether it’s innovation, cyber risk, AI, operational resilience, or broader business transformation efforts. Understanding those priorities can help CIOs shape future conversations and align their messaging.</p>



<p>According to Zarmi, many technology leaders leave valuable insights on the table because they become overly focused on their content rather than on engaging the board.</p>



<p>“A lot of people presenting think the board needs to know all the details in the world,” she says. “They come with heavy decks and a lot of data the board can’t comprehend.”</p>



<p>Instead, she encourages CIOs to focus on narrative and business impact. “What’s most important is really to tell the story of what you’re doing, why you’re doing it, and the impact on the business.”</p>



<h2 class="wp-block-heading">Follow-up isn’t housekeeping, it’s leadership</h2>



<p>Wayne Shurts, former CTO of Sysco and current board member and advisor, believes many CIOs overlook one of the most valuable aspects of board engagement: access to experienced executives who can help them think differently.</p>



<p>“It really begins before the board meeting,” he says.</p>



<p>Long before a CIO walks into the boardroom, Shurts recommends building relationships with directors whose backgrounds align with the issues tech leaders are likely to discuss. Those conversations can provide valuable insight into board priorities, concerns, and expectations. “Try to get a feel for the audience before you walk in there and present, which is just basic, but not enough people do it,” he says.</p>



<p>The same philosophy applies after the meeting ends. If directors raise questions that can’t be fully addressed during the meeting, Shurts recommends following up rather than waiting for the next quarterly cycle. More importantly, he believes CIOs often underestimate how much value they can gain from the board itself.</p>



<p>“Sometimes boards are really helpful,” he says. “They might have given you some valuable information that can make things go better.”</p>



<p>Too many CIOs interpret tough questions as criticism, though. But experienced board members often see them as opportunities to challenge assumptions, improve decision-making, and strengthen outcomes. The same principle applies when discussing major initiatives since directors evaluate the leadership team’s alignment around business priorities, rather than the CIO in particular.</p>



<p>“There are very few, if any, IT projects that aren’t business projects,” says Shurts.</p>



<p>No matter what the topic, boards want to see evidence that technology investments are supported across the business and understood by the leaders accountable for delivering results.</p>



<h2 class="wp-block-heading">Ask what happened after you left the room</h2>



<p>One of the most overlooked opportunities comes after the presentation ends and the CIO leaves the discussion. Many IT leaders debrief with their CEO, general counsel, or executive team. Far fewer seek feedback from trusted directors. Shurts believes they should.</p>



<p>After significant board interactions, he recommends reaching out to directors with whom a relationship already exists and simply ask, “How’d that go? How did I do?”</p>



<p>Good directors can provide valuable perspective on how the discussion landed, what concerns surfaced during subsequent conversations, and whether there were issues that deserve additional attention. Those conversations can reveal concerns that never surfaced publicly during the meeting. They can also identify opportunities to improve future interactions, strengthen relationships, and better understand how directors think about technology issues.</p>



<p>For Zarmi, the final lesson is transparency. Any communication with directors after a meeting should remain aligned with the CEO and broader leadership team. CIOs may own the technology strategy, but they’re still operating within a larger enterprise context.</p>



<p>“Always follow up with the CEO,” she says. “’Here’s what I presented. What do you think and how can I be more effective?’”</p>



<p>That discipline becomes especially important when directors ask follow-up questions. While a CIO may be tempted to respond tactically, Zarmi argues that leaders must first consider how their answer fits into the broader business narrative since CIOs need to think about the role they play in the big picture, she adds.</p>



<p>As Shurts puts it, “Boards are over-presented to, and under-dialogued with.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Irish Internet Hotline named Trusted Flagger under EU Digital Services Act]]></title>
<description><![CDATA[The designation represents a significant step forward in improving the handling and escalation of reports relating to illegal online content, particularly in relation to children.
Read more: Irish Internet Hotline named Trusted Flagger under EU Digital Services Act]]></description>
<link>https://tsecurity.de/de/3623806/it-nachrichten/irish-internet-hotline-named-trusted-flagger-under-eu-digital-services-act/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623806/it-nachrichten/irish-internet-hotline-named-trusted-flagger-under-eu-digital-services-act/</guid>
<pubDate>Thu, 25 Jun 2026 10:33:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The designation represents a significant step forward in improving the handling and escalation of reports relating to illegal online content, particularly in relation to children.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/enterprise/irish-internet-hotline-named-trusted-flagger-eu-digital-services-act">Irish Internet Hotline named Trusted Flagger under EU Digital Services Act</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39012 | Huawei Aslan Children Watch input validation (EUVD-2022-41558)]]></title>
<description><![CDATA[A vulnerability was found in Huawei Aslan Children Watch. It has been classified as problematic. Impacted is an unknown function. This manipulation causes improper input validation.

This vulnerability is handled as CVE-2022-39012. The attack can only be done within the local network. There is no...]]></description>
<link>https://tsecurity.de/de/3623505/sicherheitsluecken/cve-2022-39012-huawei-aslan-children-watch-input-validation-euvd-2022-41558/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623505/sicherheitsluecken/cve-2022-39012-huawei-aslan-children-watch-input-validation-euvd-2022-41558/</guid>
<pubDate>Thu, 25 Jun 2026 08:09:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/huawei:aslan_children_watch">Huawei Aslan Children Watch</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function. This manipulation causes improper input validation.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-39012">CVE-2022-39012</a>. The attack can only be done within the local network. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-06-24, Version 26.4.0 (Current), @aduh95]]></title>
<description><![CDATA[Notable Changes

[cde0daabcc] - (SEMVER-MINOR) doc: update blockList stability status to release candidate (alphaleadership) #63050
[b78f5a7537] - (SEMVER-MINOR) fs: support caller-supplied readFile() buffers (Matteo Collina) #63634
[417aacbc36] - (SEMVER-MINOR) http: close pre-request sockets in...]]></description>
<link>https://tsecurity.de/de/3623069/downloads/2026-06-24-version-2640-current-aduh95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623069/downloads/2026-06-24-version-2640-current-aduh95/</guid>
<pubDate>Thu, 25 Jun 2026 01:46:32 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/cde0daabcc"><code>cde0daabcc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>doc</strong>: update <code>blockList</code> stability status to release candidate (alphaleadership) <a href="https://github.com/nodejs/node/pull/63050" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63050/hovercard">#63050</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b78f5a7537"><code>b78f5a7537</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>fs</strong>: support caller-supplied <code>readFile()</code> buffers (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63634" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63634/hovercard">#63634</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/417aacbc36"><code>417aacbc36</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: close pre-request sockets in <code>closeIdleConnections</code> (semimikoh) <a href="https://github.com/nodejs/node/pull/63470" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63470/hovercard">#63470</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fbb108be7d"><code>fbb108be7d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>loader</strong>: implement package maps (Maël Nison) <a href="https://github.com/nodejs/node/pull/62239" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62239/hovercard">#62239</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/45494d5a8a"><code>45494d5a8a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>net</strong>: support <code>TCP_KEEPINTVL</code> and <code>TCP_KEEPCNT</code> in <code>setKeepAlive</code> (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63825" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63825/hovercard">#63825</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee29465e77"><code>ee29465e77</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>tls</strong>: add certificateCompression option (Tim Perry) <a href="https://github.com/nodejs/node/pull/62217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62217/hovercard">#62217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b17817eb2b"><code>b17817eb2b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: dispatch <code>node:fs/promises</code> to mounted VFS instances (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63537" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63537/hovercard">#63537</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7bc93a6ac5"><code>7bc93a6ac5</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: add minimal <code>node:vfs</code> subsystem (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63115" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63115/hovercard">#63115</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/c7eb83b46a"><code>c7eb83b46a</code></a>] - <strong>benchmark</strong>: add child_process async path baselines (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63929" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63929/hovercard">#63929</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/066fff17a5"><code>066fff17a5</code></a>] - <strong>benchmark</strong>: remove old alias usage in ffi benchmarks (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63666" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63666/hovercard">#63666</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/509cd1b94f"><code>509cd1b94f</code></a>] - <strong>buffer</strong>: optimize Buffer.prototype.copy (Robert Nagy) <a href="https://github.com/nodejs/node/pull/63828" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63828/hovercard">#63828</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/86e651bbd0"><code>86e651bbd0</code></a>] - <strong>buffer</strong>: use simdutf for two-byte utf8 byteLength (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63639" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63639/hovercard">#63639</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3f4ed9015"><code>d3f4ed9015</code></a>] - <strong>build</strong>: suppress compiler warnings for histogram (Richard Lau) <a href="https://github.com/nodejs/node/pull/63980" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63980/hovercard">#63980</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/82dd7ddbe6"><code>82dd7ddbe6</code></a>] - <strong>build</strong>: add QUIC CI job for PRs matching QUIC related paths (Tim Perry) <a href="https://github.com/nodejs/node/pull/63875" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63875/hovercard">#63875</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1124c0652d"><code>1124c0652d</code></a>] - <strong>build</strong>: remove redundant intermediate node_aix_shared (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63747" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63747/hovercard">#63747</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e510ee8087"><code>e510ee8087</code></a>] - <strong>build</strong>: build codecache and snapshot with libnode (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63626" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63626/hovercard">#63626</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5b583dace5"><code>5b583dace5</code></a>] - <strong>build</strong>: enable maglev by default on Linux ppc64le (Richard Lau) <a href="https://github.com/nodejs/node/pull/63474" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63474/hovercard">#63474</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a2324246b4"><code>a2324246b4</code></a>] - <strong>build</strong>: remove duplicated node_use_sqlite and node_use_ffi conditions (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63629" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63629/hovercard">#63629</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2a467a5f69"><code>2a467a5f69</code></a>] - <em><strong>Revert</strong></em> "<strong>build, doc</strong>: generate node.1 with doc-kit" (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64091" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64091/hovercard">#64091</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e01dec45b8"><code>e01dec45b8</code></a>] - <strong>build, doc</strong>: generate node.1 with doc-kit (Aviv Keller) <a href="https://github.com/nodejs/node/pull/62044" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62044/hovercard">#62044</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2ab9848fe4"><code>2ab9848fe4</code></a>] - <strong>child_process</strong>: pass spawn options to the binding positionally (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63930" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63930/hovercard">#63930</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/04c04c8b5c"><code>04c04c8b5c</code></a>] - <strong>child_process</strong>: serialize advanced IPC messages natively (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63933" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63933/hovercard">#63933</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1eef57293d"><code>1eef57293d</code></a>] - <strong>crypto</strong>: support non-byte WebCrypto lengths and cSHAKE (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63988" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63988/hovercard">#63988</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/788a66e147"><code>788a66e147</code></a>] - <strong>crypto</strong>: share WebCrypto method and usage helpers (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63975" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63975/hovercard">#63975</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f9fdce3f46"><code>f9fdce3f46</code></a>] - <strong>crypto</strong>: use EVP_MAC for HMAC on OpenSSL &gt;=3 (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63942" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63942/hovercard">#63942</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7e9ca87e58"><code>7e9ca87e58</code></a>] - <strong>crypto</strong>: make webcrypto aliasKeyFormat directional (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63910" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63910/hovercard">#63910</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/656e57ebbf"><code>656e57ebbf</code></a>] - <strong>crypto</strong>: fix unhandled error in Hash._transform (Haram Jeong) <a href="https://github.com/nodejs/node/pull/63261" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63261/hovercard">#63261</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/65536f0d98"><code>65536f0d98</code></a>] - <strong>crypto</strong>: refactor keyObject.toCryptoKey() and SubtleCrypto.getPublicKey() (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63622" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63622/hovercard">#63622</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/978f1d2bcc"><code>978f1d2bcc</code></a>] - <strong>crypto</strong>: handle cipher context allocation failures (Tian Teng) <a href="https://github.com/nodejs/node/pull/63542" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63542/hovercard">#63542</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5551e8f773"><code>5551e8f773</code></a>] - <strong>crypto</strong>: deduplicate X509 subject matching logic (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/63644" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63644/hovercard">#63644</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/57ae87640a"><code>57ae87640a</code></a>] - <strong>crypto</strong>: fix warnings in test_node_crypto.cc (Maya Lekova) <a href="https://github.com/nodejs/node/pull/63490" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63490/hovercard">#63490</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9984b05dff"><code>9984b05dff</code></a>] - <strong>crypto</strong>: coerce -0 to +0 before native calls (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/88011a3689"><code>88011a3689</code></a>] - <strong>crypto,tls</strong>: do not ignore BN_get_word error (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/63895" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63895/hovercard">#63895</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9a3393d14f"><code>9a3393d14f</code></a>] - <strong>debugger</strong>: lazily wait for initial break output (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63969/hovercard">#63969</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b0bfcb9c59"><code>b0bfcb9c59</code></a>] - <strong>debugger</strong>: defer probe pause handling until startup (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63608" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63608/hovercard">#63608</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8516003953"><code>8516003953</code></a>] - <strong>debugger</strong>: await initialization after run and restart (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63607" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63607/hovercard">#63607</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4438cb5284"><code>4438cb5284</code></a>] - <strong>debugger</strong>: add --max-hit option to probe mode (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63704" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63704/hovercard">#63704</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/238b54ed2a"><code>238b54ed2a</code></a>] - <strong>debugger</strong>: add more logs to probe mode (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63663" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63663/hovercard">#63663</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bbef54b413"><code>bbef54b413</code></a>] - <strong>deps</strong>: libffi: cherry-pick 9ca53a19833d (Anthony Green) <a href="https://github.com/nodejs/node/pull/64040" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64040/hovercard">#64040</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9761385dbd"><code>9761385dbd</code></a>] - <strong>deps</strong>: update libffi to 3.6.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64040" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64040/hovercard">#64040</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/373ec2d092"><code>373ec2d092</code></a>] - <strong>deps</strong>: update acorn to 8.17.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63901" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63901/hovercard">#63901</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e44b5d487e"><code>e44b5d487e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>deps</strong>: update OpenSSL build config to support compression (Tim Perry) <a href="https://github.com/nodejs/node/pull/62217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62217/hovercard">#62217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ed287a2e2"><code>3ed287a2e2</code></a>] - <strong>deps</strong>: upgrade npm to 11.17.0 (npm team) <a href="https://github.com/nodejs/node/pull/63857" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63857/hovercard">#63857</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b1b597c797"><code>b1b597c797</code></a>] - <strong>deps</strong>: add ngtcp2_fmt.c to build configuration (ngtcp2.gyp) (沈鸿飞) <a href="https://github.com/nodejs/node/pull/63821" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63821/hovercard">#63821</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0bf8e12305"><code>0bf8e12305</code></a>] - <strong>deps</strong>: V8: add CopyArrayBufferBytes API (Robert Nagy) <a href="https://github.com/nodejs/node/pull/63828" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63828/hovercard">#63828</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e49d7301a5"><code>e49d7301a5</code></a>] - <strong>deps</strong>: update ngtcp2 to 1.23.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63777" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63777/hovercard">#63777</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e5c079004b"><code>e5c079004b</code></a>] - <strong>deps</strong>: update nghttp3 to 1.16.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63776" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63776/hovercard">#63776</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d599fa2346"><code>d599fa2346</code></a>] - <strong>deps</strong>: update googletest to 7140cd416cecd7462a8aae488024abeee55598e4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63775" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63775/hovercard">#63775</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bc09f1508c"><code>bc09f1508c</code></a>] - <strong>deps</strong>: update sqlite to 3.53.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63774" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63774/hovercard">#63774</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/60787746c4"><code>60787746c4</code></a>] - <strong>deps</strong>: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63773" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63773/hovercard">#63773</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/971af104f1"><code>971af104f1</code></a>] - <strong>deps</strong>: update amaro to 1.1.10 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63670" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63670/hovercard">#63670</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e17f665444"><code>e17f665444</code></a>] - <strong>deps</strong>: update googletest to 8736d2cd5c1dcba41170ed2fddca14021d4916c3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63669" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63669/hovercard">#63669</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7591949457"><code>7591949457</code></a>] - <strong>dgram</strong>: add synchronous Socket connectSync() (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63932" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63932/hovercard">#63932</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d75222d7cb"><code>d75222d7cb</code></a>] - <strong>dgram</strong>: add synchronous Socket.prototype.bindSync() (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63838" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63838/hovercard">#63838</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0cf8342ae2"><code>0cf8342ae2</code></a>] - <strong>dns</strong>: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e068299320"><code>e068299320</code></a>] - <strong>doc</strong>: update gcc toolchains to <code>gcc-13</code> and <code>g++-13</code> (Louie Llaneta) <a href="https://github.com/nodejs/node/pull/64018" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64018/hovercard">#64018</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/65178bdcf3"><code>65178bdcf3</code></a>] - <strong>doc</strong>: add aduh95 to last security release steward (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63981" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63981/hovercard">#63981</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83eedfe85b"><code>83eedfe85b</code></a>] - <strong>doc</strong>: fix typo in util.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63961" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63961/hovercard">#63961</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54948c78e7"><code>54948c78e7</code></a>] - <strong>doc</strong>: clarify callback exceptions (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63939" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63939/hovercard">#63939</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/205d0a57f2"><code>205d0a57f2</code></a>] - <strong>doc</strong>: fix incorrect test runner mock examples (Kimaswa Emmanuel Yusufu) <a href="https://github.com/nodejs/node/pull/63656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63656/hovercard">#63656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44809b176c"><code>44809b176c</code></a>] - <strong>doc</strong>: clarify fromReadable() duck-typed contract (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63682" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63682/hovercard">#63682</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9cb15fcc85"><code>9cb15fcc85</code></a>] - <strong>doc</strong>: fix typo in cli.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63883" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63883/hovercard">#63883</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/394d0bb928"><code>394d0bb928</code></a>] - <strong>doc</strong>: fix typo in vm.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63881" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63881/hovercard">#63881</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/59b7be8193"><code>59b7be8193</code></a>] - <strong>doc</strong>: fix typo in packages.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63882" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63882/hovercard">#63882</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/33c236cea9"><code>33c236cea9</code></a>] - <strong>doc</strong>: fix a/an article typos in module, util, and dns (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63766" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63766/hovercard">#63766</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/30595da67b"><code>30595da67b</code></a>] - <strong>doc</strong>: update npm supported versions link (hojeong park) <a href="https://github.com/nodejs/node/pull/63672" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63672/hovercard">#63672</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5919ba7e97"><code>5919ba7e97</code></a>] - <strong>doc</strong>: fix AES-OCB IV length in SubtleCrypto.supports example (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63717" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63717/hovercard">#63717</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/51cab5cb72"><code>51cab5cb72</code></a>] - <strong>doc</strong>: add webstreams to args for <code>pipeline</code> from <code>stream/promises</code> (David Sanders) <a href="https://github.com/nodejs/node/pull/63628" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63628/hovercard">#63628</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce85b2af88"><code>ce85b2af88</code></a>] - <strong>doc</strong>: fix "used to sent" → "used to send" in http2 (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63700" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63700/hovercard">#63700</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/298735e8df"><code>298735e8df</code></a>] - <strong>doc</strong>: mark Node.js 25 as End-of-Life (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63692" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63692/hovercard">#63692</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56948518b9"><code>56948518b9</code></a>] - <strong>doc</strong>: clarify tty raw mode applies to input processing only (Muhammad Zeeshan) <a href="https://github.com/nodejs/node/pull/63438" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63438/hovercard">#63438</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32ff731248"><code>32ff731248</code></a>] - <strong>doc</strong>: add worker_threads history entries (Bob Put) <a href="https://github.com/nodejs/node/pull/63545" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63545/hovercard">#63545</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cde0daabcc"><code>cde0daabcc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>doc</strong>: update <code>blockList</code> stability status to release candidate (alphaleadership) <a href="https://github.com/nodejs/node/pull/63050" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63050/hovercard">#63050</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d29483fc4f"><code>d29483fc4f</code></a>] - <strong>doc,crypto</strong>: mark argon2 and encap/decap as stable (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63924" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63924/hovercard">#63924</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e668331d9"><code>6e668331d9</code></a>] - <strong>events</strong>: improve <code>addAbortListener</code> perf by caching options object (Raz Luvaton) <a href="https://github.com/nodejs/node/pull/52367" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/52367/hovercard">#52367</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/97aafe2519"><code>97aafe2519</code></a>] - <strong>ffi</strong>: add fast support for almost all other platforms (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/63941" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63941/hovercard">#63941</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f52cf5eeaa"><code>f52cf5eeaa</code></a>] - <strong>ffi</strong>: add experimental fast FFI call API for AArch64 and x86_64 (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/63068" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63068/hovercard">#63068</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9461fee05"><code>d9461fee05</code></a>] - <strong>ffi</strong>: port semi-colon fix for riscv64 (and others) (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63794" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63794/hovercard">#63794</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c8402e0a8"><code>4c8402e0a8</code></a>] - <strong>fs</strong>: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied) <a href="https://github.com/nodejs/node/pull/63709" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63709/hovercard">#63709</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b78f5a7537"><code>b78f5a7537</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>fs</strong>: support caller-supplied readFile() buffers (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63634" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63634/hovercard">#63634</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d0097d489"><code>3d0097d489</code></a>] - <strong>fs</strong>: prevent spurious recursive watch events on prefix siblings (Marco) <a href="https://github.com/nodejs/node/pull/63095" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63095/hovercard">#63095</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/14d829cb3c"><code>14d829cb3c</code></a>] - <strong>fs</strong>: ignore deleted dirs in recursive watch scan (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63686" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63686/hovercard">#63686</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ceba08a1ea"><code>ceba08a1ea</code></a>] - <strong>fs</strong>: coerce -0 to +0 in mode flags and watch intervals (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6577d3b282"><code>6577d3b282</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/417aacbc36"><code>417aacbc36</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: close pre-request sockets in closeIdleConnections (semimikoh) <a href="https://github.com/nodejs/node/pull/63470" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63470/hovercard">#63470</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b7fd13a59a"><code>b7fd13a59a</code></a>] - <strong>http2</strong>: retain header memory in session accounting (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63752" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63752/hovercard">#63752</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e611ccd167"><code>e611ccd167</code></a>] - <strong>inspector</strong>: fix inspector.close() documented behavior (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63837" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63837/hovercard">#63837</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a44f51eef3"><code>a44f51eef3</code></a>] - <strong>lib</strong>: fix missing lazyDOMException import (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64033" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64033/hovercard">#64033</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/27cc4ec598"><code>27cc4ec598</code></a>] - <strong>lib</strong>: add lint rule to enforce use of <code>kEmptyObject</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63790" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63790/hovercard">#63790</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7ee31b0bf4"><code>7ee31b0bf4</code></a>] - <strong>lib</strong>: improve control abstraction coverage in frozen intrinsics (Renegade334) <a href="https://github.com/nodejs/node/pull/63698" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63698/hovercard">#63698</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/078457839a"><code>078457839a</code></a>] - <strong>lib</strong>: add Iterator global to primordials (Renegade334) <a href="https://github.com/nodejs/node/pull/63698" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63698/hovercard">#63698</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58837dc4dd"><code>58837dc4dd</code></a>] - <strong>lib</strong>: remove source map deadcode in type stripping (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63738" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63738/hovercard">#63738</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e7513a8b9e"><code>e7513a8b9e</code></a>] - <strong>lib</strong>: make <code>Navigator#language</code> getter throw on invalid <code>this</code> (Mohamed Sayed) <a href="https://github.com/nodejs/node/pull/63601" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63601/hovercard">#63601</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fbb108be7d"><code>fbb108be7d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>loader</strong>: implement package maps (Maël Nison) <a href="https://github.com/nodejs/node/pull/62239" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62239/hovercard">#62239</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ea0b8e1dc2"><code>ea0b8e1dc2</code></a>] - <strong>meta</strong>: bump github/codeql-action from 4.35.3 to 4.36.1 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63724" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63724/hovercard">#63724</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ac90719532"><code>ac90719532</code></a>] - <strong>meta</strong>: bump actions/cache from 5.0.4 to 5.0.5 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62847" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62847/hovercard">#62847</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ed3de3062"><code>3ed3de3062</code></a>] - <strong>meta</strong>: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63726" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63726/hovercard">#63726</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d08d57bf70"><code>d08d57bf70</code></a>] - <strong>meta</strong>: bump codecov/codecov-action from 6.0.0 to 6.0.1 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63725" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63725/hovercard">#63725</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e748d192cf"><code>e748d192cf</code></a>] - <strong>meta</strong>: bump cachix/cachix-action (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63729" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63729/hovercard">#63729</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10554eb131"><code>10554eb131</code></a>] - <strong>meta</strong>: bump actions/stale from 10.2.0 to 10.3.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63728" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63728/hovercard">#63728</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/791885f2af"><code>791885f2af</code></a>] - <strong>meta</strong>: bump step-security/harden-runner from 2.19.0 to 2.19.4 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63727" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63727/hovercard">#63727</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32d9a407d9"><code>32d9a407d9</code></a>] - <strong>meta</strong>: bump cachix/install-nix-action from 31.10.5 to 31.10.6 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63723" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63723/hovercard">#63723</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b97c7bed07"><code>b97c7bed07</code></a>] - <strong>module</strong>: enable existing machinery for deferred import of static modules (Maya Lekova) <a href="https://github.com/nodejs/node/pull/63712" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63712/hovercard">#63712</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4becad2117"><code>4becad2117</code></a>] - <strong>module</strong>: use file: URL as sourceURL for type-stripped CommonJS (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63705" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63705/hovercard">#63705</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c71c85b95f"><code>c71c85b95f</code></a>] - <strong>net</strong>: early TCP binding via synchronous net.BoundSocket (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63951" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63951/hovercard">#63951</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/45494d5a8a"><code>45494d5a8a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>net</strong>: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63825" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63825/hovercard">#63825</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3988efa1f3"><code>3988efa1f3</code></a>] - <strong>net</strong>: coerce -0 to +0 in BlockList prefixes (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/484efd1c44"><code>484efd1c44</code></a>] - <strong>quic</strong>: fix get_reader bug that dropped data on FIN (Tim Perry) <a href="https://github.com/nodejs/node/pull/63946" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63946/hovercard">#63946</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/04a17fe6f0"><code>04a17fe6f0</code></a>] - <strong>quic</strong>: expose QUIC certificates as JS X509Certificate, not raw handles (Tim Perry) <a href="https://github.com/nodejs/node/pull/63191" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63191/hovercard">#63191</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b62d5696dc"><code>b62d5696dc</code></a>] - <strong>quic</strong>: fix reader backpressure deadlock on idle connections (Tim Perry) <a href="https://github.com/nodejs/node/pull/63950" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63950/hovercard">#63950</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f1c8d7453"><code>3f1c8d7453</code></a>] - <strong>quic</strong>: fix broken listEndpoints export, test callbacks &amp; nghttp3 include (Tim Perry) <a href="https://github.com/nodejs/node/pull/63874" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63874/hovercard">#63874</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8538b9deb"><code>d8538b9deb</code></a>] - <strong>quic</strong>: impl. cb for http/3 settings/app. options (Marten Richter) <a href="https://github.com/nodejs/node/pull/63558" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63558/hovercard">#63558</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/643b19716e"><code>643b19716e</code></a>] - <strong>quic</strong>: add listEndpoints API (James M Snell) <a href="https://github.com/nodejs/node/pull/63536" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63536/hovercard">#63536</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2bce35bea4"><code>2bce35bea4</code></a>] - <strong>sqlite</strong>: do not leave database open after failed open (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63854" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63854/hovercard">#63854</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/394af52abb"><code>394af52abb</code></a>] - <strong>sqlite</strong>: fix stack-use-after-scope with function callback (ndossche) <a href="https://github.com/nodejs/node/pull/63640" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63640/hovercard">#63640</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10f03e5958"><code>10f03e5958</code></a>] - <strong>src</strong>: omit unconvertible names in cjs_lexer::Parse (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63943" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63943/hovercard">#63943</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1723773d41"><code>1723773d41</code></a>] - <strong>src</strong>: keep global list of addon-provided cleanup hooks (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63985" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63985/hovercard">#63985</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ef12e9ea44"><code>ef12e9ea44</code></a>] - <strong>src</strong>: guard OpenSSL compression header include (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64009" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64009/hovercard">#64009</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/48af8a6d8d"><code>48af8a6d8d</code></a>] - <strong>src</strong>: handle empty MaybeLocal in cjs_lexer::Parse (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63885" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63885/hovercard">#63885</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2a672ee9e8"><code>2a672ee9e8</code></a>] - <strong>src</strong>: fast path empty native immediate drain (Gürgün Dayıoğlu) <a href="https://github.com/nodejs/node/pull/62969" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62969/hovercard">#62969</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/db6a31d1a1"><code>db6a31d1a1</code></a>] - <strong>src</strong>: do not track weak <code>BaseObject</code>s as childrens of <code>Realm</code>s (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63842" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63842/hovercard">#63842</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5fb837ff46"><code>5fb837ff46</code></a>] - <strong>src</strong>: allow tracking children in <code>MemoryTracker</code> with weak edges (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63842" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63842/hovercard">#63842</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d22d373a9"><code>6d22d373a9</code></a>] - <strong>src</strong>: use C++14 deprecated attribute for <code>NODE_DEPRECATED</code> (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63755" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63755/hovercard">#63755</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7ac3fe1992"><code>7ac3fe1992</code></a>] - <strong>src</strong>: add cleanup hooks to <code>node::ObjectWrap</code> (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63642" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63642/hovercard">#63642</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d82d369155"><code>d82d369155</code></a>] - <strong>src</strong>: fix edge case when deflateInit2() fails with Z_VERSION_ERROR (Nora Dossche) <a href="https://github.com/nodejs/node/pull/63476" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63476/hovercard">#63476</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/03858d152b"><code>03858d152b</code></a>] - <strong>src</strong>: remove redundant <code>handle_</code> field in ffi (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63665" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63665/hovercard">#63665</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1682264f6b"><code>1682264f6b</code></a>] - <strong>src</strong>: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63385" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63385/hovercard">#63385</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cc29696acf"><code>cc29696acf</code></a>] - <strong>stream</strong>: fix Writable.toWeb() desiredSize for non-object-mode (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62986" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62986/hovercard">#62986</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9967a25b2"><code>d9967a25b2</code></a>] - <strong>stream</strong>: handle falsy push writer fail reasons (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63569" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63569/hovercard">#63569</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b53f8f75c9"><code>b53f8f75c9</code></a>] - <strong>stream</strong>: reduce allocations on WHATWG streams hot paths (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63876" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63876/hovercard">#63876</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/315ca426d8"><code>315ca426d8</code></a>] - <strong>stream</strong>: handle setEncoding after buffered data (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63973" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63973/hovercard">#63973</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/06413cd6bd"><code>06413cd6bd</code></a>] - <strong>stream</strong>: fix Utf8Stream stall after full write of multi-byte data (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63964" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63964/hovercard">#63964</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a9f9a3dafa"><code>a9f9a3dafa</code></a>] - <strong>stream</strong>: keep overlapping broadcast reads pending (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63500" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63500/hovercard">#63500</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/009cca11bd"><code>009cca11bd</code></a>] - <strong>stream</strong>: refine the stream/iter backpressure (James M Snell) <a href="https://github.com/nodejs/node/pull/63697" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63697/hovercard">#63697</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f81dcfc99"><code>3f81dcfc99</code></a>] - <strong>stream</strong>: only pass the expected number of parameters to callbacks (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63909" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63909/hovercard">#63909</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9a83b5d1fe"><code>9a83b5d1fe</code></a>] - <strong>stream</strong>: fix dropped first chunk in Utf8Stream buffer mode (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63833" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63833/hovercard">#63833</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0bdf5adea9"><code>0bdf5adea9</code></a>] - <strong>stream</strong>: remove transform-writer handling in pipeTo (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63684" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63684/hovercard">#63684</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10272a94b6"><code>10272a94b6</code></a>] - <strong>stream</strong>: check done before backpressure in stream reader (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63699" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63699/hovercard">#63699</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/792c410631"><code>792c410631</code></a>] - <strong>stream</strong>: fix pipeToSync byte accounting (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63564" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63564/hovercard">#63564</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3cfafbc54b"><code>3cfafbc54b</code></a>] - <strong>stream</strong>: reject pull() reads on abort (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63498" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63498/hovercard">#63498</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/640a8cede5"><code>640a8cede5</code></a>] - <strong>stream</strong>: fast-path stateless transform flush results (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63605" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63605/hovercard">#63605</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ece4477872"><code>ece4477872</code></a>] - <strong>stream</strong>: optimize pipeTo promise handling (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63572" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63572/hovercard">#63572</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2cb84c2daf"><code>2cb84c2daf</code></a>] - <strong>stream</strong>: handle sync writev completion in pipeTo (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63561" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63561/hovercard">#63561</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d9fdda5fa"><code>7d9fdda5fa</code></a>] - <strong>stream</strong>: settle pending broadcast reads on return (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63603" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63603/hovercard">#63603</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e2aea3aac7"><code>e2aea3aac7</code></a>] - <strong>test</strong>: tolerate duplicate watch change events (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63937" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63937/hovercard">#63937</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ea6300593a"><code>ea6300593a</code></a>] - <strong>test</strong>: mark test-debugger-run-after-quit-restart as flaky on macOS (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64006" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64006/hovercard">#64006</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/be1b204fa4"><code>be1b204fa4</code></a>] - <strong>test</strong>: update WPT for url to d4598eba09 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63899" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63899/hovercard">#63899</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b3d0d05b05"><code>b3d0d05b05</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 03a1476844 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63900" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63900/hovercard">#63900</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/046af2609f"><code>046af2609f</code></a>] - <strong>test</strong>: update WPT for urlpattern to 23aac92784 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63898/hovercard">#63898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/562b831a98"><code>562b831a98</code></a>] - <strong>test</strong>: add tests for 3 methods in utils (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63765" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63765/hovercard">#63765</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/28e3629dd3"><code>28e3629dd3</code></a>] - <strong>test</strong>: mark SEA tests flaky on linux arm debug (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63743" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63743/hovercard">#63743</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/243aa846de"><code>243aa846de</code></a>] - <strong>test</strong>: validate ERR_INVALID_THIS for scheduler methods (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63764" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63764/hovercard">#63764</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6bd07df2bc"><code>6bd07df2bc</code></a>] - <strong>test</strong>: add coverage outside SEA (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63744" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63744/hovercard">#63744</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bd67c9d11b"><code>bd67c9d11b</code></a>] - <strong>test</strong>: update WPT for urlpattern to 2f28df545c (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63771" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63771/hovercard">#63771</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e40bfe7081"><code>e40bfe7081</code></a>] - <strong>test</strong>: make Brotli 16GB test wait for backpressure (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63389/hovercard">#63389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/444c03fd3b"><code>444c03fd3b</code></a>] - <strong>test</strong>: add regression test for using <code>ObjectWrap</code> in worker (Mohamed Akram) <a href="https://github.com/nodejs/node/pull/63642" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63642/hovercard">#63642</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/771230df78"><code>771230df78</code></a>] - <strong>test</strong>: accept SIGILL aborts in async-hooks tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63687" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63687/hovercard">#63687</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b3cd8e5e6"><code>0b3cd8e5e6</code></a>] - <strong>test</strong>: add more test cases for pathToFileURL (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63293" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63293/hovercard">#63293</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0cbc77c60e"><code>0cbc77c60e</code></a>] - <strong>test</strong>: update test426-fixtures to 2965987bf4c96afa400c9356c8e620cb340aaee (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63668" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63668/hovercard">#63668</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f53dee5fe4"><code>f53dee5fe4</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 0c413fb56b (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63647" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63647/hovercard">#63647</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3048f8dc1a"><code>3048f8dc1a</code></a>] - <strong>test,debugger</strong>: add test for type stripping in debugger probe mode (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63748" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63748/hovercard">#63748</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9485caa97e"><code>9485caa97e</code></a>] - <strong>test_runner</strong>: remove unused shuffleArrayWithSeed (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63847" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63847/hovercard">#63847</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/34433a4a87"><code>34433a4a87</code></a>] - <strong>test_runner</strong>: fix watch cwd with isolation none (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63690" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63690/hovercard">#63690</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e7da29b7c"><code>2e7da29b7c</code></a>] - <strong>test_runner</strong>: avoid recompiling coverage globs for every file (sangwook) <a href="https://github.com/nodejs/node/pull/63675" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63675/hovercard">#63675</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/205295a31e"><code>205295a31e</code></a>] - <strong>test_runner</strong>: cache <code>shouldSkipFileCoverage</code> result per URL (sangwook) <a href="https://github.com/nodejs/node/pull/63675" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63675/hovercard">#63675</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee29465e77"><code>ee29465e77</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>tls</strong>: add certificateCompression option (Tim Perry) <a href="https://github.com/nodejs/node/pull/62217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62217/hovercard">#62217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/57d060ed2b"><code>57d060ed2b</code></a>] - <strong>tls</strong>: route event listener exceptions through error handlers (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63822" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63822/hovercard">#63822</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d2dc6f8506"><code>d2dc6f8506</code></a>] - <strong>tools</strong>: bump piscina from 5.1.4 to 5.2.0 in /tools/doc (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64002" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64002/hovercard">#64002</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b0c418f605"><code>b0c418f605</code></a>] - <strong>tools</strong>: update sccache to v0.16.0 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/63078" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63078/hovercard">#63078</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2af8433bef"><code>2af8433bef</code></a>] - <strong>tools</strong>: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63948" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63948/hovercard">#63948</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8ba5b8574b"><code>8ba5b8574b</code></a>] - <strong>tools</strong>: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63947" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63947/hovercard">#63947</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/325087be5b"><code>325087be5b</code></a>] - <strong>tools</strong>: enforce iterator result property order (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63526" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63526/hovercard">#63526</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/314f417db7"><code>314f417db7</code></a>] - <strong>tools</strong>: update the llhttp updater script (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63819" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63819/hovercard">#63819</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c6e4f5a4fe"><code>c6e4f5a4fe</code></a>] - <strong>tools</strong>: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63938" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63938/hovercard">#63938</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/363912acc3"><code>363912acc3</code></a>] - <strong>tools</strong>: align Bash snippets in GHA with <code>lint-sh</code> conventions (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63829/hovercard">#63829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cfd16e973c"><code>cfd16e973c</code></a>] - <strong>tools</strong>: bump @node-core/doc-kit in /tools/doc in the doc group (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63760" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63760/hovercard">#63760</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1566872706"><code>1566872706</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 7 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63730" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63730/hovercard">#63730</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/08437a3a5b"><code>08437a3a5b</code></a>] - <strong>tools</strong>: fix zlib updater script (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63707" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63707/hovercard">#63707</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e883366172"><code>e883366172</code></a>] - <strong>url</strong>: fix URLSearchParams(null) to prudce null= per spec (Marco) <a href="https://github.com/nodejs/node/pull/63782" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63782/hovercard">#63782</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/60e83d9bfd"><code>60e83d9bfd</code></a>] - <strong>util</strong>: fix scientific notation formatting (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63823" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63823/hovercard">#63823</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5f7f60ac36"><code>5f7f60ac36</code></a>] - <strong>util</strong>: fix -0 formatting when numericSeparator is enabled (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63815" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63815/hovercard">#63815</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/af1a11e0dd"><code>af1a11e0dd</code></a>] - <strong>util</strong>: remove style caches from styleText slow path (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/63706" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63706/hovercard">#63706</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b17817eb2b"><code>b17817eb2b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: dispatch fs/promises to mounted VFS instances (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63537" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63537/hovercard">#63537</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7bc93a6ac5"><code>7bc93a6ac5</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: add minimal node:vfs subsystem (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63115" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63115/hovercard">#63115</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/584e7527c4"><code>584e7527c4</code></a>] - <strong>vm</strong>: fix property queries for proxy sandboxes (Brian Meek) <a href="https://github.com/nodejs/node/pull/63742" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63742/hovercard">#63742</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a926e72eaf"><code>a926e72eaf</code></a>] - <strong>watch</strong>: print name of changed file that triggers restart (Marco) <a href="https://github.com/nodejs/node/pull/63781" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63781/hovercard">#63781</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32a2621ca4"><code>32a2621ca4</code></a>] - <strong>watch</strong>: cancel pending restart on shutdown (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63383" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63383/hovercard">#63383</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/692215d1b1"><code>692215d1b1</code></a>] - <strong>zlib</strong>: coerce -0 to +0 for crc32 seeds (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Prime Day Deals on LED Masks and Hair Growth Tools That Actually Work]]></title>
<description><![CDATA[Whether you're looking to upgrade your skin care routine or invest in hair restoration, these are the best Prime Day deals on some of our favorite red light therapy devices.]]></description>
<link>https://tsecurity.de/de/3622991/it-nachrichten/best-prime-day-deals-on-led-masks-and-hair-growth-tools-that-actually-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622991/it-nachrichten/best-prime-day-deals-on-led-masks-and-hair-growth-tools-that-actually-work/</guid>
<pubDate>Thu, 25 Jun 2026 00:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Whether you're looking to upgrade your skin care routine or invest in hair restoration, these are the best Prime Day deals on some of our favorite red light therapy devices.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Turn On Ask to Browse for Your Kids in iOS 27]]></title>
<description><![CDATA[Apple has introduced Ask to Browse in iOS 27 as part of its expanded parental control features. The new tool gives parents more control over the websites their children visit in Safari. When enabled, a child must request permission before opening a new website, and parents can review and approve ...]]></description>
<link>https://tsecurity.de/de/3622136/ios-mac-os/how-to-turn-on-ask-to-browse-for-your-kids-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622136/ios-mac-os/how-to-turn-on-ask-to-browse-for-your-kids-in-ios-27/</guid>
<pubDate>Wed, 24 Jun 2026 18:24:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has introduced Ask to Browse in iOS 27 as part of its expanded parental control features. The new tool gives parents more control over the websites their children visit in Safari. When enabled, a child must request permission before opening a new website, and parents can review and approve or deny the request directly from their devices. 



This feature works across iPhone, iPad, and Mac and is integrated with Screen Time and Family Sharing. If you want to create a safer browsing experience for your child, here is how to turn on Ask to Browse in iOS 27.



Table of contentsTurn On Ask to Browse Using Family SharingEnable Ask to Browse from Screen TimeManage Approved Websites for Your ChildHow Website Approval Requests WorkFAQsSummaryConclusion



Turn On Ask to Browse Using Family Sharing



Before you can use Ask to Browse, your child must be part of your Family Sharing group and have a Child Account set up.



This method enables website approval requests for your child's Safari browsing activity. When your child attempts to visit a website that has not been approved before, Apple sends a request to the parent through Messages for review.




Open Settings on your iPhone.



Tap your Apple ID profile at the top.



Select Family.



Tap your child's account.



Open Screen Time settings.



Locate Ask to Browse under the parental control options.



Turn on the Ask to Browse toggle.



Confirm any prompts that appear on screen.




Once enabled, your child will need approval before accessing new websites in Safari. Approved sites can be visited again without requiring another request.



Enable Ask to Browse from Screen Time



Apple has redesigned Screen Time in iOS 27, making parental controls easier to access and manage. Ask to Browse is part of this updated experience.




Open Settings.



Tap Screen Time.



Under the Family section, select your child's name.



Review your child's Screen Time settings.



Find Ask to Browse.



Enable the feature.



Verify that notifications are allowed on your device so you can receive website approval requests.




After setup, website requests will appear in Messages, allowing you to approve or deny access quickly.



Manage Approved Websites for Your Child



Parents can build a list of approved websites and control what children can access online. Apple also blocks known adult websites by default for child accounts.




Open Settings.



Go to Screen Time.



Select your child's account.



Open website and browsing controls.



Review previously approved websites.



Add trusted websites if needed.



Remove websites that should no longer be accessible.




This allows you to customize your child's browsing experience according to their age and needs.



How Website Approval Requests Work



Understanding how the approval process works helps parents manage requests more efficiently.




Your child enters a website address in Safari.



Safari checks whether the website has already been approved.



If it is a new site, a permission request is generated.



The request appears in the parent's Messages app.



The parent reviews the website.



The parent chooses Approve or Deny.



The child receives the decision immediately.




This process is designed to give parents visibility into new websites before children access them.



FAQs



What is Ask to Browse in iOS 27? Ask to Browse is a new parental control feature that requires children to get permission before visiting new websites in Safari. It extends the idea behind Apple's Ask to Buy feature for apps and purchases.  Does Ask to Browse work on iPad and Mac? Yes. Apple says the feature works across iPhone, iPad, and Mac when using Safari.  Do parents receive website requests in Messages? Yes. Website access requests appear through the Messages app, where parents can approve or deny them.  Is Ask to Browse enabled by default? For younger child accounts, Apple enables stronger protections by default. Parents can also choose to enable Ask to Browse for older children and teens.  Does Ask to Browse block adult websites? Yes. Apple automatically blocks known adult websites for child accounts and provides additional website management tools for parents.  



Summary




Ask to Browse is a new Safari parental control feature in iOS 27.



Children must request permission before visiting new websites.



Parents receive approval requests through Messages.



The feature can be managed through Family Sharing and Screen Time.



Approved websites remain accessible after approval.



Known adult websites are blocked automatically for child accounts.



The feature works across iPhone, iPad, and Mac.




Conclusion



Ask to Browse gives parents a practical way to supervise web access without completely restricting internet use. By enabling the feature in iOS 27, you can review new websites before your child visits them, manage approved sites, and create a safer browsing environment across Apple devices. Combined with the redesigned Screen Time experience, it becomes much easier to stay informed about your child's online activity while still giving them room to explore age-appropriate content.]]></content:encoded>
</item>
<item>
<title><![CDATA[YouTube settles early test case over social media harm to children]]></title>
<description><![CDATA[Google has settled a lawsuit with a minor known who claimed that social media platforms harmed them.]]></description>
<link>https://tsecurity.de/de/3620616/it-nachrichten/youtube-settles-early-test-case-over-social-media-harm-to-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620616/it-nachrichten/youtube-settles-early-test-case-over-social-media-harm-to-children/</guid>
<pubDate>Wed, 24 Jun 2026 10:17:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google has settled a lawsuit with a minor known who claimed that social media platforms harmed them.]]></content:encoded>
</item>
<item>
<title><![CDATA[TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million]]></title>
<description><![CDATA[Two alleged members of the cybercrime collective Scattered Spider have pleaded guilty to their roles in the Transport for London cyberattack, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport a...]]></description>
<link>https://tsecurity.de/de/3620296/it-security-nachrichten/tfl-hackers-plead-guilty-after-breach-exposed-customer-data-and-cost-29-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620296/it-security-nachrichten/tfl-hackers-plead-guilty-after-breach-exposed-customer-data-and-cost-29-million/</guid>
<pubDate>Wed, 24 Jun 2026 07:38:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Transport for London cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million 1"></p>Two alleged members of the cybercrime collective <a href="https://thecyberexpress.com/scattered-spider-teens-plead-not-guilty/" target="_blank" rel="noopener">Scattered Spider </a>have pleaded guilty to their roles in the <a href="https://thecyberexpress.com/transport-for-london-addressing-cyberattack/" target="_blank" rel="noopener">Transport for London cyberattack</a>, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport authority.

The guilty pleas were entered by Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, on the opening day of proceedings at Woolwich Crown Court. The pair had been due to stand trial on June 22 but changed their pleas to guilty.
<h3><strong>Transport for London Cyberattack Led to Major Disruption</strong></h3>
According to the National Crime Agency (NCA) and City of London Police, TfL's network was infiltrated between August 31 and September 3, 2024. The breach forced all 28,000 employees to attend TfL offices for <a href="https://thecyberexpress.com/top-password-managers-for-digital-safety/" target="_blank" rel="noopener">password</a> resets and caused significant operational disruption across the organization.

The TfL cyberattack also resulted in unauthorized access to <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28805">data</a> held within TfL's Oyster refunds system. The incident affected the authority's customer refund process, delaying reimbursements for some customers. In addition, the application system for Oyster photocards used by children and young people was temporarily shut down.

Authorities <a href="https://nca-newsroom.prgloo.com/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="nofollow noopener">said</a> the attack caused substantial financial damage, with TfL reporting losses and recovery costs totaling approximately £29 million.
<h3><strong>Investigation Linked Attackers to Scattered Spider</strong></h3>
Jubair and Flowers were arrested at their homes on September 16, 2024, following a joint investigation conducted by the <a href="https://thecyberexpress.com/nca-arrests-4-for-retail-cyberattacks/" target="_blank" rel="noopener">NCA</a> and City of London Police.

Investigators identified both individuals as members of Scattered Spider, a cybercriminal collective that has been linked to a number of high-profile intrusions.

During searches of Flowers' residence, officers recovered laptops, desktop computers, hard drives, and USB storage devices. Evidence recovered from one Acer laptop included a screenshot showing connectivity to TfL infrastructure.

[caption id="attachment_112868" align="aligncenter" width="600"]<img class="wp-image-112868 size-full" src="https://thecyberexpress.com/wp-content/uploads/TFL-cyberattack-e1782278063737.webp" alt="Transport for London cyberattack" width="600" height="900"> Source: NCA[/caption]

Authorities also found evidence indicating Flowers had accessed an online marketplace that sold breached credentials. Investigators further discovered videos recorded by Flowers that allegedly showed Jubair accessing TfL systems during the attack.

The investigation revealed that the two communicated through <a href="https://thecyberexpress.com/telegram-ban-in-india-ahead-of-neet-re-exam/" target="_blank" rel="noopener">Telegram</a> and collaborated using an online workspace platform that allowed multiple participants to work remotely on shared systems.
<h3><strong>Additional Allegations Involving US Healthcare Networks</strong></h3>
The investigation extended beyond the Transport for London <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28806">cyberattack</a>. When Flowers was first arrested on September 6, 2024, NCA officers identified evidence suggesting unauthorized activity targeting the networks of SSM Health Care Corporation and Sutter Health in the United States.

Court records show Flowers pleaded guilty to charges related to a conspiracy to conduct unauthorized acts against SSM Health Care Corporation's computer systems with intent to impair operations. He also admitted attempting unauthorized acts against Sutter Health's systems with the same intent.

Jubair additionally faced a charge for failing to disclose PINs or passwords associated with devices seized during the investigation.

Authorities noted that Flowers breached bail conditions on two occasions in March and May 2025.
<h3><strong>Law Enforcement Highlights Impact of Cybercrime</strong></h3>
Paul Foster, Deputy Director and head of the NCA's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Cyber Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28803">Cyber Crime</a> Unit, described the case as a lengthy and highly complex investigation. He said the attack demonstrated that <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28804">cybercrime</a> has significant real-world consequences, affecting public services and causing millions of pounds in losses to critical national infrastructure.

Foster also highlighted the growing threat posed by cybercriminal groups operating from the UK and other English-speaking countries, citing Scattered Spider as a notable example.

Deputy Commissioner Nik Adams of the City of London Police said the cyberattack had a significant impact on essential public services and daily operations. He emphasized that individuals responsible for targeting critical organizations and causing financial harm would be pursued through coordinated law enforcement efforts.

The investigation received support from the West Midlands Regional Organised Crime Unit and British Transport Police.

Jubair and Flowers are scheduled to be sentenced at Woolwich Crown Court on July 16.]]></content:encoded>
</item>
<item>
<title><![CDATA[Norway Sets Strict AI Limits for Elementary Schools]]></title>
<description><![CDATA[Norway will restrict generative AI in schools, nearly banning it for elementary pupils as Europe debates children’s digital safety.]]></description>
<link>https://tsecurity.de/de/3619752/it-nachrichten/norway-sets-strict-ai-limits-for-elementary-schools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619752/it-nachrichten/norway-sets-strict-ai-limits-for-elementary-schools/</guid>
<pubDate>Wed, 24 Jun 2026 00:17:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Norway will restrict generative AI in schools, nearly banning it for elementary pupils as Europe debates children’s digital safety.]]></content:encoded>
</item>
<item>
<title><![CDATA[Community Snapshot—May]]></title>
<description><![CDATA[Our global chapters work to keep the Internet a force for good. This brief overview covers just some of their activities in May. 
The post Community Snapshot—May appeared first on Internet Society.]]></description>
<link>https://tsecurity.de/de/3619507/it-nachrichten/community-snapshot-may/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619507/it-nachrichten/community-snapshot-may/</guid>
<pubDate>Tue, 23 Jun 2026 22:17:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="250" height="115" src="https://www.internetsociety.org/wp-content/uploads/2026/06/Paraguay-Chapter-250x115.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="A selfie of four people standing outside together. There are a couple children in blue uniforms in the background." decoding="async" srcset="https://www.internetsociety.org/wp-content/uploads/2026/06/Paraguay-Chapter-250x115.jpg 250w, https://www.internetsociety.org/wp-content/uploads/2026/06/Paraguay-Chapter-450x207.jpg 450w, https://www.internetsociety.org/wp-content/uploads/2026/06/Paraguay-Chapter-1024x470.jpg 1024w, https://www.internetsociety.org/wp-content/uploads/2026/06/Paraguay-Chapter-768x353.jpg 768w, https://www.internetsociety.org/wp-content/uploads/2026/06/Paraguay-Chapter.jpg 1200w" sizes="(max-width: 250px) 100vw, 250px"></p>
<p>Our global chapters work to keep the Internet a force for good. This brief overview covers just some of their activities in May. </p>
<p>The post <a href="https://www.internetsociety.org/blog/2026/06/community-snapshot-may-2/">Community Snapshot—May</a> appeared first on <a href="https://www.internetsociety.org/">Internet Society</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pickleball takes center court: Jake Johnson and Ben Stiller serve up laughs in Apple TV comedy film ‘The Dink’ trailer]]></title>
<description><![CDATA[In Apple's "The Dink," washed up former tennis prodigy Dusty Boyd (Jake Johnson) has been reduced to coaching unruly children at his…
The post Pickleball takes center court: Jake Johnson and Ben Stiller serve up laughs in Apple TV comedy film ‘The Dink’ trailer appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3619481/ios-mac-os/pickleball-takes-center-court-jake-johnson-and-ben-stiller-serve-up-laughs-in-apple-tv-comedy-film-the-dink-trailer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619481/ios-mac-os/pickleball-takes-center-court-jake-johnson-and-ben-stiller-serve-up-laughs-in-apple-tv-comedy-film-the-dink-trailer/</guid>
<pubDate>Tue, 23 Jun 2026 22:10:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In Apple's "The Dink," washed up former tennis prodigy Dusty Boyd (Jake Johnson) has been reduced to coaching unruly children at his…</p>
<p>The post <a href="https://macdailynews.com/2026/06/23/pickleball-takes-center-court-jake-johnson-and-ben-stiller-serve-up-laughs-in-apple-tv-comedy-film-the-dink-trailer/">Pickleball takes center court: Jake Johnson and Ben Stiller serve up laughs in Apple TV comedy film ‘The Dink’ trailer</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV’s Next Comedy Looks Surprisingly Fun, Watch the ‘The Dink’ Trailer]]></title>
<description><![CDATA[Apple TV has released the trailer for The Dink, its upcoming sports comedy starring Jake Johnson as a former tennis prodigy who finds himself pulled into the world of pickleball after an injury changes his plans.



The film premieres exclusively on Apple TV on Friday, July 24, and follows Dusty ...]]></description>
<link>https://tsecurity.de/de/3618937/ios-mac-os/apple-tvs-next-comedy-looks-surprisingly-fun-watch-the-the-dink-trailer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618937/ios-mac-os/apple-tvs-next-comedy-looks-surprisingly-fun-watch-the-the-dink-trailer/</guid>
<pubDate>Tue, 23 Jun 2026 18:27:59 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has released the trailer for The Dink, its upcoming sports comedy starring Jake Johnson as a former tennis prodigy who finds himself pulled into the world of pickleball after an injury changes his plans.



The film premieres exclusively on Apple TV on Friday, July 24, and follows Dusty Boyd, a washed-up tennis player now coaching children at his father’s suburban country club. Dusty wants his father’s approval, so he joins his fight against pickleball, which has started taking over the club.



The movie features a strong cast, including Jake Johnson, Mary Steenburgen, Ed Harris, Patton Oswalt, Chloe Fineman, and Ben Stiller, who also produced the film.



As Dusty recovers from an old injury, he begins playing pickleball and slowly starts enjoying the sport with help from his new partner, Candace. The story then turns into a funny and personal fight over family, identity, and the future of the club.]]></content:encoded>
</item>
<item>
<title><![CDATA[This 3-foot-tall robot wants to be your kid’s classroom buddy and your mom’s new friend]]></title>
<description><![CDATA[Mind Children Robotics, a Seattle-area startup co-founded by AGI researcher Ben Goertzel, is building Codey — a child-sized social robot priced under $10,000 and aimed at classrooms, hospitals and senior care. The company plans its first pilots in South Korea. Read More]]></description>
<link>https://tsecurity.de/de/3618891/it-nachrichten/this-3-foot-tall-robot-wants-to-be-your-kids-classroom-buddy-and-your-moms-new-friend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618891/it-nachrichten/this-3-foot-tall-robot-wants-to-be-your-kids-classroom-buddy-and-your-moms-new-friend/</guid>
<pubDate>Tue, 23 Jun 2026 18:19:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1216" height="684" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/codey-3.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/codey-3.jpg 1216w, https://cdn.geekwire.com/wp-content/uploads/2026/06/codey-3-768x432.jpg 768w" sizes="(max-width: 1216px) 100vw, 1216px"><br>Mind Children Robotics, a Seattle-area startup co-founded by AGI researcher Ben Goertzel, is building Codey — a child-sized social robot priced under $10,000 and aimed at classrooms, hospitals and senior care. The company plans its first pilots in South Korea. <a href="https://www.geekwire.com/2026/this-3-foot-tall-robot-wants-to-be-your-kids-classroom-buddy-and-your-moms-new-friend/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI in the classroom prompts tide of concern from US parents and experts]]></title>
<description><![CDATA[While tech companies and Trump have been pushing teachers to use AI in the classroom, many argue that there is little evidence that it would actually help childrenIn October, Kelly Clancy’s son received an assignment in sixth grade at a middle school in Brooklyn, New York, to create a science exp...]]></description>
<link>https://tsecurity.de/de/3618184/ai-nachrichten/ai-in-the-classroom-prompts-tide-of-concern-from-us-parents-and-experts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618184/ai-nachrichten/ai-in-the-classroom-prompts-tide-of-concern-from-us-parents-and-experts/</guid>
<pubDate>Tue, 23 Jun 2026 14:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>While tech companies and Trump have been pushing teachers to use AI in the classroom, many argue that there is little evidence that it would actually help children</p><p>In October, Kelly Clancy’s son received an assignment in sixth grade at a middle school in Brooklyn, New York, to create a science experiment and then ask Google Gemini, an <a href="https://www.theguardian.com/technology/artificialintelligenceai">artificial intelligence</a> chatbot, for feedback, she said.</p><p>Clancy, who has three children in New York City public schools, told the teacher that the bot “is something that just teaches kids that they can have machines do the thinking for them”, instead of suggesting: “Let’s talk to your partners. What about the science experiment could you improve?”</p> <a href="https://www.theguardian.com/education/2026/jun/23/ai-us-schools-students">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UCD PhD student explores link tying maths and spatial skills in children]]></title>
<description><![CDATA[While the spatial-maths link is well established in the literature we still know relatively little about why the two domains are related.
Read more: UCD PhD student explores link tying maths and spatial skills in children]]></description>
<link>https://tsecurity.de/de/3617316/it-nachrichten/ucd-phd-student-explores-link-tying-maths-and-spatial-skills-in-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617316/it-nachrichten/ucd-phd-student-explores-link-tying-maths-and-spatial-skills-in-children/</guid>
<pubDate>Tue, 23 Jun 2026 08:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>While the spatial-maths link is well established in the literature we still know relatively little about why the two domains are related.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/innovation/ucd-phd-student-explores-link-tying-maths-and-spatial-skills-in-children">UCD PhD student explores link tying maths and spatial skills in children</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Climate Denial Pulls Down US Defense Sea Walls: Sensor Gaps Invite Foreign Attack]]></title>
<description><![CDATA[Three thousand years ago, or so the children’s books say, a city fell because its own defenders pulled down their wall and let the attackers stroll in without a fight. It’s a lesson we all are supposed to know, not least of all anyone tasked with defense of their nation. You probably recognize th...]]></description>
<link>https://tsecurity.de/de/3615658/it-security-nachrichten/climate-denial-pulls-down-us-defense-sea-walls-sensor-gaps-invite-foreign-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615658/it-security-nachrichten/climate-denial-pulls-down-us-defense-sea-walls-sensor-gaps-invite-foreign-attack/</guid>
<pubDate>Mon, 22 Jun 2026 15:54:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Three thousand years ago, or so the children’s books say, a city fell because its own defenders pulled down their wall and let the attackers stroll in without a fight. It’s a lesson we all are supposed to know, not least of all anyone tasked with defense of their nation. You probably recognize the story … <a href="https://www.flyingpenguin.com/climate-denial-pulls-down-sea-walls-sensor-gaps-invite-foreign-attack/" class="more-link">Continue reading <span class="screen-reader-text">Climate Denial Pulls Down US Defense Sea Walls: Sensor Gaps Invite Foreign Attack</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Official Promises Statements 'Around VPNs' and Further Teen Restrictions on Chatbots and Social Media]]></title>
<description><![CDATA[PC Gamer reports:

The UK government is considering an Australia-style ban on social media for under-16s, with Prime Minister Keir Starmer saying that the ban could take effect as soon as spring next year. As for the much nearer future, Science and Technology Secretary Liz Kendall told BBC Breakf...]]></description>
<link>https://tsecurity.de/de/3614123/it-security-nachrichten/uk-official-promises-statements-around-vpns-and-further-teen-restrictions-on-chatbots-and-social-media/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614123/it-security-nachrichten/uk-official-promises-statements-around-vpns-and-further-teen-restrictions-on-chatbots-and-social-media/</guid>
<pubDate>Sun, 21 Jun 2026 23:08:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PC Gamer reports:

The UK government is considering an Australia-style ban on social media for under-16s, with Prime Minister Keir Starmer saying that the ban could take effect as soon as spring next year. As for the much nearer future, Science and Technology Secretary Liz Kendall told BBC Breakfast earlier this week, "We will make further statements in July about VPNs and further restrictions." 

To be clear, no specific restrictions have yet been announced and Kendall sounded somewhat cautious about an outright ban during a parliament debate that took place the same day. "I have commissioned further research about their usage. There are really important issues to balance here," she says. "Many people want to use VPNs for privacy — that is important — but we know that some children use them to get around restrictions. I will come back to that in July in our response to the consultation." So, we'll have to wait until next month for anything definite, but it's hard not to feel like a full ban on VPNs is already on the table. If that does come to pass, more than the contents of my Bluesky inbox will be at stake. 

Utah in the US has already tried to implement a full VPN ban (though this was postponed until September after Aylo, the parent company of Pornhub, challenged the law in court)... [T]he UK could just be the next domino after Utah, potentially setting off a chain reaction that affects users around the world.
 
The article also argues that age checks can also be a privacy nightmare "with the security breach that exposed the personal info of 70,000 Discord users last year being one case in point." 

Here's the complete statement from UK Technology Secretary Kendall. "I'll come back in July with a further statement around VPNs but also additional measures that we want to look at, further restrictions on AI chatbots that parents have found very worrying, more about overnight curfews or breaks in doomscrolling for 16- and 17-year-olds."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=UK+Official+Promises+Statements+'Around+VPNs'+and+Further+Teen+Restrictions+on+Chatbots+and+Social+Media%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F21%2F2052213%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F21%2F2052213%2Fuk-official-promises-statements-around-vpns-and-further-teen-restrictions-on-chatbots-and-social-media%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/21/2052213/uk-official-promises-statements-around-vpns-and-further-teen-restrictions-on-chatbots-and-social-media?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[To the tablet and beyond: does Toy Story 5 go hard enough on technology?]]></title>
<description><![CDATA[The animated sequel sets up a tug-of-war between physical and digital play for children but is still eager not to be an anti-tech screedFor more than 30 years, Pixar’s signature Toy Story series has been entertaining children while giving voice to their parents’ anxieties. This is especially pron...]]></description>
<link>https://tsecurity.de/de/3613141/it-nachrichten/to-the-tablet-and-beyond-does-toy-story-5-go-hard-enough-on-technology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613141/it-nachrichten/to-the-tablet-and-beyond-does-toy-story-5-go-hard-enough-on-technology/</guid>
<pubDate>Sun, 21 Jun 2026 07:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The animated sequel sets up a tug-of-war between physical and digital play for children but is still eager not to be an anti-tech screed</p><p>For more than 30 years, Pixar’s signature Toy Story series has been entertaining children while giving voice to their parents’ anxieties. This is especially pronounced in the film’s sequels, as the living toys who dedicate their lives to the happiness of their owner/child experience all different sorts of potential and parent-paralleled obsolescence, from physical wear-and-tear and a child reaching young adulthood to the toy equivalent of empty-nesting (still hanging around the playroom but no longer anyone’s favourite). It’s only natural – maybe even a little belated – that <a href="https://www.theguardian.com/film/2026/jun/16/toy-story-5-review-pixar-franchise-needs-new-batteries">Toy Story 5</a> would address the encroachment of technology, which continues to make its way to children earlier and earlier. So many years after the tech breakthroughs that allowed Toy Story to become the first computer-animated feature, and Pixar to become a household name in family entertainment, has the formerly Steve Jobs-owned company turned against the kind of innovation that built its success?</p> <a href="https://www.theguardian.com/news/ng-interactive/2026/jun/21/toy-story-5-go-hard-enough-on-technology">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Norway Imposes Near Ban On AI In Elementary School]]></title>
<description><![CDATA[Norway will largely prohibit generative AI use for elementary kids ages 6 to 13 beginning with the new school year, while allowing limited, teacher-supervised use for older students. The government says the restrictions are intended to prevent children from skipping foundational reading, writing,...]]></description>
<link>https://tsecurity.de/de/3611380/it-security-nachrichten/norway-imposes-near-ban-on-ai-in-elementary-school/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611380/it-security-nachrichten/norway-imposes-near-ban-on-ai-in-elementary-school/</guid>
<pubDate>Sat, 20 Jun 2026 00:23:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Norway will largely prohibit generative AI use for elementary kids ages 6 to 13 beginning with the new school year, while allowing limited, teacher-supervised use for older students. The government says the restrictions are intended to prevent children from skipping foundational reading, writing, and mathematics skills amid declining test scores. Reuters reports: Facing a broad decline in education test scores, the government in 2024 banned smartphones from schools and has given teachers back more powers to enforce discipline in the classroom. Using AI increases the risk that young children skip important steps in their education, Prime Minister Jonas Gahr Stoere told a press conference on Friday. "The most important thing in school is that our children learn to read, write and do mathematics," Stoere said, adding that the new standards will be imposed from the new school year beginning in late August.
 
Pupils from first through seventh grade, aged 6 to 13, should as a general rule not be using AI, while those in lower secondary school, aged 14 to 16, can cautiously adopt tools under teachers' supervision, the government said. In upper secondary education, from ages 17 to 19, students should learn to use AI appropriately so that they are prepared for further education and work, it added. In a related statement, the Norwegian government also said it would propose legislation to fund the use of more books in classrooms, reversing the trend towards computer tablets.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Norway+Imposes+Near+Ban+On+AI+In+Elementary+School%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F19%2F2140248%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F19%2F2140248%2Fnorway-imposes-near-ban-on-ai-in-elementary-school%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/19/2140248/norway-imposes-near-ban-on-ai-in-elementary-school?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mind Children Prepares Public Rollout of Autonomous Codey Robot]]></title>
<description><![CDATA[Mind Children is preparing Codey, a three-foot AI robot built for public spaces, as it tests autonomy, conversation, and companion features.]]></description>
<link>https://tsecurity.de/de/3611351/it-nachrichten/mind-children-prepares-public-rollout-of-autonomous-codey-robot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611351/it-nachrichten/mind-children-prepares-public-rollout-of-autonomous-codey-robot/</guid>
<pubDate>Fri, 19 Jun 2026 23:48:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mind Children is preparing Codey, a three-foot AI robot built for public spaces, as it tests autonomy, conversation, and companion features.]]></content:encoded>
</item>
<item>
<title><![CDATA[Norway bans generative AI tools in elementary schools to protect kids' basic learning skills]]></title>
<description><![CDATA[Norway is banning generative AI tools in elementary schools starting in late August. Students in grades 1 through 7 won't be allowed to use AI at all; secondary schools will permit it only under supervision. Prime Minister Stoere says children must first "learn to read, write, and do math."
The a...]]></description>
<link>https://tsecurity.de/de/3611154/ai-nachrichten/norway-bans-generative-ai-tools-in-elementary-schools-to-protect-kids-basic-learning-skills/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611154/ai-nachrichten/norway-bans-generative-ai-tools-in-elementary-schools-to-protect-kids-basic-learning-skills/</guid>
<pubDate>Fri, 19 Jun 2026 20:48:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/06/norway_flag.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Norway is banning generative AI tools in elementary schools starting in late August. Students in grades 1 through 7 won't be allowed to use AI at all; secondary schools will permit it only under supervision. Prime Minister Stoere says children must first "learn to read, write, and do math."</p>
<p>The article <a href="https://the-decoder.com/norway-bans-generative-ai-tools-in-elementary-schools-to-protect-kids-basic-learning-skills/">Norway bans generative AI tools in elementary schools to protect kids' basic learning skills</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Lobbies Congress For Protection From Child-Harm Lawsuits]]></title>
<description><![CDATA[Longtime Slashdot reader schwit1 shares a report from Reuters: Meta has lobbied the U.S. Congress for legal immunity from child-harm claims tied to social media products such as Instagram, as it faces thousands of lawsuits from young users and their families, according to a source familiar with t...]]></description>
<link>https://tsecurity.de/de/3610749/it-security-nachrichten/meta-lobbies-congress-for-protection-from-child-harm-lawsuits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610749/it-security-nachrichten/meta-lobbies-congress-for-protection-from-child-harm-lawsuits/</guid>
<pubDate>Fri, 19 Jun 2026 17:14:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Longtime Slashdot reader schwit1 shares a report from Reuters: Meta has lobbied the U.S. Congress for legal immunity from child-harm claims tied to social media products such as Instagram, as it faces thousands of lawsuits from young users and their families, according to a source familiar with the matter and proposed legislative language reviewed by Reuters. If adopted by lawmakers and passed into law as part of the Kids Online Safety Act (KOSA) under consideration in the U.S. Senate, such a provision could undermine thousands of lawsuits against Meta and other online platforms over harms to children. Meta and Google's YouTube face a combined $6 million in damages after they lost the first case at trial early this year. While legislators have given no indication of adopting the language, the lobbying effort shows the kind of legal protections Meta is seeking amid the biggest attempt to regulate online platforms in the U.S. since the 1990s. Meta has reportedly proposed the language in exchange for dropping its opposition to KOSA. Under the law, platforms would be required to mitigate harms to minors tied to features such as infinite scrolling, notifications, and appearance-altering filters.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Lobbies+Congress+For+Protection+From+Child-Harm+Lawsuits%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F18%2F2342227%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F18%2F2342227%2Fmeta-lobbies-congress-for-protection-from-child-harm-lawsuits%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/06/18/2342227/meta-lobbies-congress-for-protection-from-child-harm-lawsuits?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The UK’s social media ban for under-16s has just empowered big tech | Taylor Lorenz]]></title>
<description><![CDATA[Age verification means that the sector’s biggest players will now have access to information that will only make them richer and more powerfulThis week, the UK announced a wide-ranging ban on social media that will soon block users from communicating or accessing information on apps such as X, In...]]></description>
<link>https://tsecurity.de/de/3610630/it-nachrichten/the-uks-social-media-ban-for-under-16s-has-just-empowered-big-tech-taylor-lorenz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610630/it-nachrichten/the-uks-social-media-ban-for-under-16s-has-just-empowered-big-tech-taylor-lorenz/</guid>
<pubDate>Fri, 19 Jun 2026 16:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Age verification means that the sector’s biggest players will now have access to information that will only make them richer and more powerful</p><p>This week, the UK announced a <a href="https://www.theguardian.com/uk-news/video/2026/jun/15/keir-starmer-announces-social-media-ban-for-under-16s-in-uk-video">wide-ranging ban on social media</a> that will soon block users from communicating or accessing information on apps such as X, Instagram, YouTube, Facebook, TikTok and<strong> </strong>Snapchat unless they prove that they’re over the age of 16.</p><p>The prime minister, Keir Starmer, called the policy “<a href="https://www.theguardian.com/uk-news/2026/jun/15/uk-under-16s-social-media-ban-how-will-it-work">a line in the sand</a>”. “Tech giants had their chance and failed,” <a href="https://www.gov.uk/government/news/social-media-to-be-banned-for-under-16s-in-landmark-government-move-to-givekids-their-childhood-back">he said</a>, “but we’re stepping in to protect children, back parents and set a new normal for future generations.” All internet users, especially children, should be protected from exploitative systems online, but this new law will only foster more harm and help the largest and most powerful tech companies consolidate power and influence over everyone’s lives.</p><p>Taylor Lorenz is a technology journalist who writes the newsletter <a href="https://www.usermag.co/">User Mag</a> and is the author of the bestselling book <a href="https://guardianbookshop.com/extremely-online-9780753560792/">Extremely Online: The Untold Story of Fame, Influence, and Power on the Internet</a></p> <a href="https://www.theguardian.com/commentisfree/2026/jun/19/uk-social-media-ban-under-16s-big-tech-age-verification">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Read a book? Join a club? Stare at a wall? Social media alternatives for under-16s]]></title>
<description><![CDATA[Amid UK government proposals for a ban, experts discuss what other activities might really serve children wellWhen a Lancashire schoolgirl was asked what she would do if the proposed social media ban for under-16s came into effect, her answer hit a national nerve: “Stare at a wall,” she deadpanne...]]></description>
<link>https://tsecurity.de/de/3610566/it-nachrichten/read-a-book-join-a-club-stare-at-a-wall-social-media-alternatives-for-under-16s/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610566/it-nachrichten/read-a-book-join-a-club-stare-at-a-wall-social-media-alternatives-for-under-16s/</guid>
<pubDate>Fri, 19 Jun 2026 15:48:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Amid UK government proposals for a ban, experts discuss what other activities might really serve children well</p><p>When a Lancashire schoolgirl was asked what she would do if the proposed social media ban for under-16s came into effect, her <a href="https://www.bbc.co.uk/news/videos/c5yzrp3vn8no">answer</a> hit a national nerve: “Stare at a wall,” she deadpanned.</p><p>The clip went viral, not least because it distilled a question many parents have been asking themselves about the consequences of the government’s <a href="https://www.theguardian.com/uk-news/video/2026/jun/15/keir-starmer-announces-social-media-ban-for-under-16s-in-uk-video">proposed social media ban</a>.</p> <a href="https://www.theguardian.com/media/2026/jun/19/social-media-alternatives-under-16s-uk-government-ban">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the FDA’s new real-world evidence guidance ends the era of structured-data-only submissions]]></title>
<description><![CDATA[On February 17, 2026, the FDA’s final guidance on the use of real-world evidence to support regulatory decision-making for medical devices became operational. It asks sponsors to demonstrate that their real-world data is relevant, reliable, complete and traceable, for every clinical fact rather t...]]></description>
<link>https://tsecurity.de/de/3609971/it-security-nachrichten/why-the-fdas-new-real-world-evidence-guidance-ends-the-era-of-structured-data-only-submissions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609971/it-security-nachrichten/why-the-fdas-new-real-world-evidence-guidance-ends-the-era-of-structured-data-only-submissions/</guid>
<pubDate>Fri, 19 Jun 2026 12:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>On February 17, 2026, the FDA’s <a href="https://www.fda.gov/regulatory-information/search-fda-guidance-documents/use-real-world-evidence-support-regulatory-decision-making-medical-devices" rel="nofollow">final guidance on the use of real-world evidence to support regulatory decision-making for medical devices</a> became operational. It asks sponsors to demonstrate that their real-world data is relevant, reliable, complete and traceable, for every clinical fact rather than each dataset as a whole. The first wave of submissions under the new rules is now landing at the agency, and a structural problem with how most secondary-use clinical data is built today is about to become visible.</p>



<p>The premise behind those pipelines is that structured electronic health record (EHR) fields plus claims data offer a defensible foundation for evidence. They are easier to extract and standardize, and map cleanly to common data models like OMOP. The implicit assumption is that what is missing from the structured fields is either marginal or available somewhere else. The peer-reviewed record says otherwise.</p>



<h2 class="wp-block-heading">The clinical signal that matters lives in text</h2>



<p>Across condition areas where regulatory submissions depend on completeness, structured fields capture a small fraction of what clinicians have documented.</p>



<p>Social determinants of health are the starkest case. A <a href="https://www.nature.com/articles/s41746-023-00970-0" rel="nofollow">2024 study in <em>npj Digital Medicine</em></a> compared natural language processing on clinical notes against ICD-10 Z-codes for the same patients: NLP identified adverse SDoH in 93.8% of patients, while the structured codes identified 2.0%. For a regulatory question about outcomes by housing, food or transportation security, structured data is not a partial view. It is absent.</p>



<p>Family history follows a similar shape. <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC4765557/" rel="nofollow">A 2015 study in the <em>AMIA Annual Symposium Proceedings</em></a> found specified family history in 58.7% of neurology admission notes against 5.2% in the structured record, a twelvefold gap. Any genetics-aware risk model that draws only from structured fields operates without most of its predictive signal.</p>



<p>In oncology, the data that drives staging, therapy and outcomes lives in pathology reports and clinic notes rather than discrete fields. <a href="https://www.jmir.org/2022/3/e27210" rel="nofollow">A 2022 study in the <em>Journal of Medical Internet Research</em></a> reported 93.5–97.6% accuracy for cancer site and histology extracted directly from free-text pathology reports. Without that extraction, the structured oncology record is, on its own, incomplete enough that cancer registry and external-control-arm work cannot be defended.</p>



<p>For diagnoses more generally, <a href="https://www.sciencedirect.com/science/article/pii/S1386505621000782" rel="nofollow">a 2021 audit in the <em>International Journal of Medical Informatics</em></a> found that nearly 40% of important inpatient diagnoses appeared only in free-text notes and never reached the structured problem list. <a href="https://www.johnsnowlabs.com/wp-content/uploads/2025/06/PHuSE_2025_MOSAIC-NLP_Poster.pdf" rel="nofollow">A 2025 study presented at the PHUSE/FDA Computational Science Symposium</a> reported that observed suicidality and self-harm events doubled once unstructured EHR data was added to the surveillance window. This is consistent with <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC5943451/" rel="nofollow">earlier work</a> showing that only about 3% of suicidal ideation events and 19% of suicide-attempt events documented in notes carry corresponding ICD codes. For pharmacovigilance and safety analyses, the gap is the difference between detecting a signal and missing it.</p>



<h2 class="wp-block-heading">And what is captured is noisier than it looks</h2>



<p>Treating the structured record as ground truth understates a second problem: the codes that are present are frequently wrong. <a href="https://pubmed.ncbi.nlm.nih.gov/29854158/" rel="nofollow">A 2017 simulation study in the <em>AMIA Annual Symposium Proceedings</em></a> found that just over half of entered diagnosis codes were appropriate for the clinical scenario, and about a quarter of the codes expected from the chart were omitted entirely. <a href="https://pubmed.ncbi.nlm.nih.gov/36618791/" rel="nofollow">A 2022 study in the <em>Annals of Translational Medicine</em></a> reported an average of 4.9 medication discrepancies per patient, with more than 90% of patients carrying at least one. And <a href="https://www.cdc.gov/mmwr/volumes/66/wr/mm6645a2.htm" rel="nofollow">the CDC has documented</a> that about one in five new prescriptions is never filled, and roughly half of those filled are taken incorrectly.</p>



<p>The structured layer is not only thin. It is also unreliable in ways that propagate silently into derived measures. This brings the discussion to the most uncomfortable finding.</p>



<h2 class="wp-block-heading">Completeness changes the answer, not just the coverage</h2>



<p><a href="https://www.ajmc.com/view/electronic-health-record-problem-lists-accurate-enough-for-risk-adjustment" rel="nofollow">A 2018 study in the <em>American Journal of Managed Care</em></a> computed <a href="https://pubmed.ncbi.nlm.nih.gov/3558716/" rel="nofollow">Charlson comorbidity scores</a> (a widely used mortality-prediction index) from two sources for the same patients: from free-text clinical notes and from the structured problem list. The version computed from the notes predicted long-term mortality. The version computed from the structured record did not. The math was identical. The data layer changed which conclusions were valid.</p>



<p>This is the pattern the new FDA guidance is responding to. The agency’s relevance-and-reliability framework cares less about volume than about accuracy. The clinical facts in a submission have to accurately represent what happened to the patient, and critical information cannot be systematically missing. A submission whose underlying measure is built on the structured-only Charlson is, by the agency’s own framework, not fit for the regulatory question it is being used to answer.</p>



<h2 class="wp-block-heading">What this means for the architecture, not just the dataset</h2>



<p>The implication runs deeper than “add NLP to your pipeline.” It changes the unit of work. Under the new guidance, the question is no longer “is this dataset complete enough?” but “is this fact about this patient accurate, and where did it come from?” Every clinical assertion in a real-world evidence submission has to be treatable as a claim: sourced, dated, contextualized, scored for confidence and reconcilable when sources disagree.</p>



<p>That has architectural consequences. It means ingesting and parsing every modality losslessly, including text, FHIR, HL7, DICOM and PDFs, without throwing away the original. It means extraction with healthcare-specific language models that handle negation, assertion status, temporality and clinical context. It means terminology mapping that survives audit. It means a reconciliation layer that knows what to do when the chart says 80 mg and the pharmacy feed says 40 mg and surfaces the conflict rather than picking silently.</p>



<p>None of that is exotic engineering. But it is incompatible with pipelines whose first design assumption was that structured fields would carry the load. Sponsors operating under the new guidance will need to rebuild that assumption from the ground up.</p>



<p>Capturing the right data is the easier part. Proving you captured it correctly, fact by fact, is the harder one. The new guidance treats both as requirements, not options.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Original Films to bring beloved children’s book ‘Little Santa’ to the screen]]></title>
<description><![CDATA[Apple Original Films today announced it has landed “Little Santa,” a new animated feature based on the popular and beloved children’s book…
The post Apple Original Films to bring beloved children’s book ‘Little Santa’ to the screen appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3608967/ios-mac-os/apple-original-films-to-bring-beloved-childrens-book-little-santa-to-the-screen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608967/ios-mac-os/apple-original-films-to-bring-beloved-childrens-book-little-santa-to-the-screen/</guid>
<pubDate>Thu, 18 Jun 2026 23:24:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple Original Films today announced it has landed “Little Santa,” a new animated feature based on the popular and beloved children’s book…</p>
<p>The post <a href="https://macdailynews.com/2026/06/18/apple-original-films-to-bring-beloved-childrens-book-little-santa-to-the-screen/">Apple Original Films to bring beloved children’s book ‘Little Santa’ to the screen</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Announces Major App Store Changes on iOS in Brazil]]></title>
<description><![CDATA[Apple is allowing iPhone developers in Brazil to distribute apps through authorized alternative marketplaces and use third-party payment systems following action by the country's competition regulator. "In other words, developers in Brazil will be able to circumvent the App Store and Apple's in-a...]]></description>
<link>https://tsecurity.de/de/3608740/it-security-nachrichten/apple-announces-major-app-store-changes-on-ios-in-brazil/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608740/it-security-nachrichten/apple-announces-major-app-store-changes-on-ios-in-brazil/</guid>
<pubDate>Thu, 18 Jun 2026 21:08:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is allowing iPhone developers in Brazil to distribute apps through authorized alternative marketplaces and use third-party payment systems following action by the country's competition regulator. "In other words, developers in Brazil will be able to circumvent the App Store and Apple's in-app purchase system, but there are still fees," reports MacRumors. Apple will collect commissions ranging from 5% on externally distributed apps to as much as 26% for some App Store transactions using its payment system. From the report: Alternative app marketplaces will have to be authorized by Apple and will need to meet ongoing requirements. For apps that are still distributed through the App Store, developers will be able to include an alternative payment processing method in their app and/or link users to a website to complete a transaction. These changes are available on iOS 26.5 and later, and they are the result of regulatory action from Brazil's competition regulator. Apple has added a new page on its website with additional details for developers in Brazil.
 
Apple said these changes introduce privacy and security risks for users, including children. The company has introduced safeguards to mitigate these risks, including a notarization process for iOS apps, an authorization process for app marketplaces, and limitations on external links and alternative payments for users under the age of 18. Apple has already allowed alternative app stores and/or third-party payment systems on iOS in the EU, Japan, and South Korea, and it will likely be forced to do so in the UK and Australia too, due to similar regulations in those countries.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Apple+Announces+Major+App+Store+Changes+on+iOS+in+Brazil%3A+https%3A%2F%2Fapple.slashdot.org%2Fstory%2F26%2F06%2F18%2F1811250%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fapple.slashdot.org%2Fstory%2F26%2F06%2F18%2F1811250%2Fapple-announces-major-app-store-changes-on-ios-in-brazil%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://apple.slashdot.org/story/26/06/18/1811250/apple-announces-major-app-store-changes-on-ios-in-brazil?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['I've been making Sonic games and been with Sonic longer than I've been with my own children' — Sonic Team head looks back on the franchise for its 35th anniversary]]></title>
<description><![CDATA[We chat to Sonic Team head Takashi Iizuka about 35 years of the platformer franchise.]]></description>
<link>https://tsecurity.de/de/3608317/it-nachrichten/ive-been-making-sonic-games-and-been-with-sonic-longer-than-ive-been-with-my-own-children-sonic-team-head-looks-back-on-the-franchise-for-its-35th-anniversary/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608317/it-nachrichten/ive-been-making-sonic-games-and-been-with-sonic-longer-than-ive-been-with-my-own-children-sonic-team-head-looks-back-on-the-franchise-for-its-35th-anniversary/</guid>
<pubDate>Thu, 18 Jun 2026 18:05:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We chat to Sonic Team head Takashi Iizuka about 35 years of the platformer franchise.]]></content:encoded>
</item>
<item>
<title><![CDATA[Glucose Tracking for Children Is Moving Into Apps and Smart Devices]]></title>
<description><![CDATA[Dexcom’s Stelo is the first over-the-counter continuous glucose monitor cleared for children. The FDA decision expands app-based glucose tracking to younger users, but schools, health care teams, and benefits leaders still need to account for device access, caregiver oversight, and coverage quest...]]></description>
<link>https://tsecurity.de/de/3608226/it-nachrichten/glucose-tracking-for-children-is-moving-into-apps-and-smart-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608226/it-nachrichten/glucose-tracking-for-children-is-moving-into-apps-and-smart-devices/</guid>
<pubDate>Thu, 18 Jun 2026 17:19:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dexcom’s Stelo is the first over-the-counter continuous glucose monitor cleared for children. The FDA decision expands app-based glucose tracking to younger users, but schools, health care teams, and benefits leaders still need to account for device access, caregiver oversight, and coverage questions.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-dexcom-stelo-otc-cgm-children/">Glucose Tracking for Children Is Moving Into Apps and Smart Devices</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to put a clear AI strategy into focus]]></title>
<description><![CDATA[Most experts and top IT executives agree that establishing an AI vision statement or guide is an important first step in developing an overall strategy for AI adoption in the enterprise. Developing such a statement can help companies better align their AI objectives with business goals, prioritiz...]]></description>
<link>https://tsecurity.de/de/3607305/it-security-nachrichten/how-to-put-a-clear-ai-strategy-into-focus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607305/it-security-nachrichten/how-to-put-a-clear-ai-strategy-into-focus/</guid>
<pubDate>Thu, 18 Jun 2026 12:08:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Most experts and top IT executives agree that establishing an AI vision statement or guide is an important first step in developing an overall strategy for AI adoption in the enterprise. Developing such a statement can help companies better align their AI objectives with business goals, prioritize investments in AI tools and internal development projects, and promote a shared understanding of why and how AI will be used within an organization.</p>



<p>Sounds like a no-brainer in terms of logical and responsible due diligence before diving headfirst into the AI pool, right? Unfortunately, while nearly 90% of companies plan to pour more money into their existing or planned AI investments over the next three years, Gartner found in a late 2023 survey that only 9% of these organizations have even basic AI vision statements in place that could help identify any potential problem areas or unknown shoals in a widening sea of AI innovation. The situation is not much better today, with only 14% of Global 2000 organizations claiming to have a documented AI strategy with clear goals in place, according to a <a href="https://www.hfsresearch.com/only-14-of-enterprises-have-a-clear-ai-strategy-altimetrik-and-hfs-research-find/" rel="nofollow">2026 HFS Research and Altimetrik survey</a>.</p>



<p>Without a vision, as outlined in a <a href="https://www.ai.se/sites/default/files/2023-09/aivision_eng-1.pdf" rel="nofollow">white paper</a> by an AI Vision Working Group in Sweden of people from the business community and public sector, an organization risks putting too little focus on the most valuable projects or, in the worst case, spending resources on the wrong projects. Save the Children CTO Ron Guerrier agrees, noting that it’s critical to establish an AI vision as a foundation for a well-defined AI strategy, not only for success, but to limit liabilities down the road.</p>



<p>“We live in hyper-competitive society, where shareholder value still drives a lot of what we think and do,” he says. “Envision a time when you’re sitting in a deposition and someone asks how confident you were in leveraging AI to make a final decision. If you feel like you can get past that audit or regulatory definition in two or three years, then that’s the barometer we can use to question ourselves because the technology has grown so fast that the legal world hasn’t caught up.”</p>



<h2 class="wp-block-heading">Keeping pace in the AI race</h2>



<p>There’s no one formula or template to establish an AI vision since every company and the internal dynamics that drive it are different. Add to this the expanding number of AI tools and services, as well as the constant pressure to quickly make use of these technologies to drive revenue, reduce costs, and remain competitive. “We’re at a huge inflection point,” says Satya Jayadev, former CIO and head of AI transformation at Skyworks Solutions, and now CIO at data storage developer Sandisk. “We’re looking at AI to help us with the bottom line and the top line. So, there’s a lot of pull and push that’s happening within the business.”</p>



<p>Developing an effective AI vision and strategy begins with analyzing the data and exploring what might be possible by applying AI tools, Jayadev says. But that approach becomes a lot more complicated for larger companies, and those involved in more challenging industries. Common action items associated with creating a basic AI vision framework include developing a structure that aligns AI goals with business priorities and establishing clear AI policies, including rules for data handling, ethical use, and risk mitigation.</p>



<p>Jayadev went a step further in creating his AI vision and adoption strategy by taking a three-phased approach, which can be applied to most any organization. The first concerned productivity, and what can you do with the technology now to reduce time, cut costs, and improve efficiency. At Skyworks, that included using Microsoft Copilot to streamline and speed up labor-intensive tasks like creating or summarizing emails and reports, or assisting with code generation.            </p>



<p>The second phase is differentiation. How can the technology be used to do things differently from competitors, and perhaps capture more market share or develop a faster and more efficient go-to-market strategy.</p>



<p>The third, and perhaps the one that’s still in the gestation stage since gen AI is still evolving, is disruption, and how the technology can be used to do something radically different in terms of design engineering and manufacturing. “How can we use it to create a new way of doing something, rather than a different way of doing it,” Jayadev says.</p>



<p>Not surprisingly, the task of developing an effective AI vision and charting a course through the disruption of that last phase falls squarely on the CIO as IT leader. This phase expands and amplifies transformational activities like thought leadership and establishing collaborative partnerships, and it adds driving a focused vision and leveraging the ecosystem to the mix.</p>



<p>“The entire organization has to be the change agent,” adds Jayadev, “and thought leadership is going to be the most important ingredient.”</p>



<h2 class="wp-block-heading">A force for better</h2>



<p>As AI evolves, it’s important to treat it as a force multiplier and not just a tool to reduce costs or headcount. It allows us to “start thinking about a faster go-to-market strategy, a faster operational strategy, and a more efficient, effective way of getting things done,” says Jayadev. The collateral impact of both IT and the entire organization acting as change agents might also create a shift in the hierarchical structures of the enterprise, and a restructuring in technology and business leadership.</p>



<p>“CIOs will hate me for saying it, but what they need to do now is transform,” says Guerrier. This transformation will involve more than just a title change as some CIOs have done. It’ll require adding an adjustment in mindset to focus more on data and less on fundamental transformation activities, like IT operations and modernizing legacy systems, if they expect to remain in the upper levels of the IT org chart.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australia’s Under-16 Social Media Ban Faces Loopholes as Teens Bypass Restrictions]]></title>
<description><![CDATA[Australia became the first country to introduce an under-16 social media ban, but the law is already showing cracks. The eSafety Commission, the government body tasked with enforcing the legislation, reports that seven in ten parents whose children already had social media accounts say their teen...]]></description>
<link>https://tsecurity.de/de/3606455/it-security-nachrichten/australias-under-16-social-media-ban-faces-loopholes-as-teens-bypass-restrictions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606455/it-security-nachrichten/australias-under-16-social-media-ban-faces-loopholes-as-teens-bypass-restrictions/</guid>
<pubDate>Thu, 18 Jun 2026 03:22:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Australia became the first country to introduce an under-16 social media ban, but the law is already showing cracks. The eSafety Commission, the government body tasked with enforcing the legislation, reports that seven in ten parents whose children already had social media accounts say their teens are still accessing age-restricted platforms after the ban took […]</p>
<p>The post <a href="https://privacysavvy.com/news/cybersecurity/australia-under-16-social-media-ban-loopholes/">Australia’s Under-16 Social Media Ban Faces Loopholes as Teens Bypass Restrictions</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UM-Flint Department of Public Safety Honored for Fostering Community Trust]]></title>
<description><![CDATA[The University of Michigan-Flint’s Department of Public Safety was named the Voices for Children Advocacy Center’s 2026 Service Organization of the Year.]]></description>
<link>https://tsecurity.de/de/3605549/it-security-nachrichten/um-flint-department-of-public-safety-honored-for-fostering-community-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605549/it-security-nachrichten/um-flint-department-of-public-safety-honored-for-fostering-community-trust/</guid>
<pubDate>Wed, 17 Jun 2026 18:52:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The University of Michigan-Flint’s <span>Department of Public Safety was named the Voices for Children Advocacy Center’s 2026 Service Organization of the Year.</span>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canada introduces privacy law with GDPR-like penalties for data breaches]]></title>
<description><![CDATA[The Canadian government has introduced Bill C-36, a major privacy reform package that would recognize privacy as a fundamental right, expand consumer control over personal information, strengthen protections for children's data, and create a new regulator with the power to impose penalties of up ...]]></description>
<link>https://tsecurity.de/de/3605280/it-security-nachrichten/canada-introduces-privacy-law-with-gdpr-like-penalties-for-data-breaches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605280/it-security-nachrichten/canada-introduces-privacy-law-with-gdpr-like-penalties-for-data-breaches/</guid>
<pubDate>Wed, 17 Jun 2026 17:24:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Canadian government has introduced Bill C-36, a major privacy reform package that would recognize privacy as a fundamental right, expand consumer control over personal information, strengthen protections for children's data, and create a new regulator with the power to impose penalties of up to 5% of a company's global revenue. Announced on June 15 …</p>
<p>The post <a href="https://cyberinsider.com/canada-introduces-privacy-law-with-gdpr-like-penalties-for-data-breaches/">Canada introduces privacy law with GDPR-like penalties for data breaches</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Toy Story 5, the problem really is these damn phones (and tablets)]]></title>
<description><![CDATA[The Toy Story franchise began with a story about a vintage doll feeling threatened by the arrival of an electronic action figure. Woody and Buzz's rivalry embodied a shift that was happening in the '90s as children's toys were becoming more technologically sophisticated, and while toys have gotte...]]></description>
<link>https://tsecurity.de/de/3605051/it-nachrichten/in-toy-story-5-the-problem-really-is-these-damn-phones-and-tablets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605051/it-nachrichten/in-toy-story-5-the-problem-really-is-these-damn-phones-and-tablets/</guid>
<pubDate>Wed, 17 Jun 2026 16:02:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Toy Story franchise began with a story about a vintage doll feeling threatened by the arrival of an electronic action figure. Woody and Buzz's rivalry embodied a shift that was happening in the '90s as children's toys were becoming more technologically sophisticated, and while toys have gotten even more tech-focused in the years since, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Selling sunshine from Seattle: Solius raises $23M to launch new at-home light-therapy device]]></title>
<description><![CDATA[Founded in 2013, Bainbridge Island, Wash.-based Solius Labs received FDA clearance for its $2,995 Solius Pro, a device which calculates and delivers a personalized dose of UVB light. Read More]]></description>
<link>https://tsecurity.de/de/3605006/it-nachrichten/selling-sunshine-from-seattle-solius-raises-23m-to-launch-new-at-home-light-therapy-device/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605006/it-nachrichten/selling-sunshine-from-seattle-solius-raises-23m-to-launch-new-at-home-light-therapy-device/</guid>
<pubDate>Wed, 17 Jun 2026 15:48:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="889" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/soliuspro1-1260x889.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/soliuspro1-1260x889.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/06/soliuspro1-768x542.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/06/soliuspro1-1536x1084.jpg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/06/soliuspro1.jpg 1859w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Founded in 2013, Bainbridge Island, Wash.-based Solius Labs received FDA clearance for its $2,995 Solius Pro, a device which calculates and delivers a personalized dose of UVB light. <a href="https://www.geekwire.com/2026/selling-sunshine-from-seattle-solius-raises-23m-to-launch-new-at-home-light-therapy-device/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Roblox needs to protect children, so its rollout of Roblox Kids and Roblox Select accounts is welcome]]></title>
<description><![CDATA[Child safety is of the utmost importance online, and Roblox has taken steps to ensure this with the introduction of new accounts for children.]]></description>
<link>https://tsecurity.de/de/3604875/it-nachrichten/roblox-needs-to-protect-children-so-its-rollout-of-roblox-kids-and-roblox-select-accounts-is-welcome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604875/it-nachrichten/roblox-needs-to-protect-children-so-its-rollout-of-roblox-kids-and-roblox-select-accounts-is-welcome/</guid>
<pubDate>Wed, 17 Jun 2026 15:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Child safety is of the utmost importance online, and Roblox has taken steps to ensure this with the introduction of new accounts for children.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ofcom Warns Over Enforcement Of Youth Social Media Ban]]></title>
<description><![CDATA[Media regulator says finding effective way to keep children under 16 off social platforms remains unknown territory This article has been indexed from Silicon UK Read the original article: Ofcom Warns Over Enforcement Of Youth Social Media Ban
Read more →
The post Ofcom Warns Over Enforcement Of ...]]></description>
<link>https://tsecurity.de/de/3603983/it-security-nachrichten/ofcom-warns-over-enforcement-of-youth-social-media-ban/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603983/it-security-nachrichten/ofcom-warns-over-enforcement-of-youth-social-media-ban/</guid>
<pubDate>Wed, 17 Jun 2026 10:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Media regulator says finding effective way to keep children under 16 off social platforms remains unknown territory This article has been indexed from Silicon UK Read the original article: Ofcom Warns Over Enforcement Of Youth Social Media Ban</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ofcom-warns-over-enforcement-of-youth-social-media-ban/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ofcom-warns-over-enforcement-of-youth-social-media-ban/">Ofcom Warns Over Enforcement Of Youth Social Media Ban</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fernando vom Rady Children's Hospital sagt, dass operatives Engagement der Schlüssel ...]]></title>
<description><![CDATA[Die Cybersicherheit im Gesundheitswesen hängt weniger von der Technologie ab als vielmehr davon, ob das Sicherheitsteam die tatsächlichen Abläufe im ...]]></description>
<link>https://tsecurity.de/de/3602909/it-security-nachrichten/fernando-vom-rady-childrens-hospital-sagt-dass-operatives-engagement-der-schluessel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602909/it-security-nachrichten/fernando-vom-rady-childrens-hospital-sagt-dass-operatives-engagement-der-schluessel/</guid>
<pubDate>Tue, 16 Jun 2026 20:39:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die <b>Cybersicherheit</b> im Gesundheitswesen hängt weniger von der Technologie ab als vielmehr davon, ob das Sicherheitsteam die tatsächlichen Abläufe im ...]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.2]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Added UMANS_WEBSEARCH_PROVIDER=native|exa support for routing Umans gateway-owned web search requests.

Fixed

A single MCP tool whose input schema can't be emitted as a valid strict tool schema for the active provider no longer fails the whole turn with HTTP 400. convertTo...]]></description>
<link>https://tsecurity.de/de/3602045/tools/v1602/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602045/tools/v1602/</guid>
<pubDate>Tue, 16 Jun 2026 15:54:19 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added <code>UMANS_WEBSEARCH_PROVIDER=native|exa</code> support for routing Umans gateway-owned web search requests.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>A single MCP tool whose input schema can't be emitted as a valid strict tool schema for the active provider no longer fails the whole turn with HTTP 400. <code>convertTools</code> (openai-responses) now validates each tool's emitted parameter schema for <code>enum</code>/<code>const</code>-vs-<code>type</code> contradictions that pass structural JSON-Schema validation but the provider rejects — e.g. a non-null <code>enum</code> on a <code>type: "null"</code> node, or an <code>enum</code> on an <code>array</code> node — and quarantines just the offending tool with a <code>logger.warn</code> naming the tool and schema path, keeping every other tool usable. Adds <code>findStrictToolSchemaViolation</code> to <code>@oh-my-pi/pi-ai/utils/schema</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2652" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2652/hovercard">#2652</a>)</li>
<li>Fixed OpenAI Responses-compatible streams from Ollama/local hosts dropping arguments for parallel tool calls whose deltas use <code>fc_&lt;call_id&gt;</code> item ids, which left earlier <code>ast_grep</code> calls with <code>{}</code> and failed validation. (<a href="https://github.com/can1357/oh-my-pi/issues/2715" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2715/hovercard">#2715</a>)</li>
<li>Fixed dialect transcript rendering so literal thinking envelopes are unwrapped before adding the dialect's own thinking tags, preventing nested <code>&lt;thinking&gt;</code> output in advisor raw dumps (<a href="https://github.com/can1357/oh-my-pi/issues/2700" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2700/hovercard">#2700</a>).</li>
<li>Fixed Anthropic-compatible Umans requests escaping client tool names and forwarding gateway web search headers so Kimi answers normally instead of returning raw gateway search results.</li>
<li>Fixed Google Gemini tool calls with <code>toolChoice: "auto"</code> serializing an explicit <code>toolConfig</code> AUTO mode, which can cause Gemini-3 models to leak raw planning JSON instead of executing tools. (<a href="https://github.com/can1357/oh-my-pi/issues/2776" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2776/hovercard">#2776</a>)</li>
<li>Fixed OpenAI-compatible Ollama completions that return empty <code>finish_reason:length</code> after filling <code>num_ctx</code> so they surface an actionable context-window error instead of an empty length stop. (<a href="https://github.com/can1357/oh-my-pi/issues/2774" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2774/hovercard">#2774</a>)</li>
<li>Fixed Codex browser login issuing credentials for the <code>opencode</code> OAuth originator while OMP requests identify as <code>pi</code>, which could make the first authenticated Codex request return 401 (<a href="https://github.com/can1357/oh-my-pi/issues/2696" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2696/hovercard">#2696</a>).</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed Kimi output caps for Umans AI Coding Plan and Venice so discovery metadata cannot use context-sized token ceilings as request caps.</li>
<li>Marked Umans Anthropic-compatible models as client-tool escaped so cached and bundled metadata do not expose <code>web_search</code> as a provider server tool.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>UMANS_WEBSEARCH_PROVIDER</code> environment variable to CLI help for Umans gateway web search backend selection.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The eager <code>task</code> (<code>task.eager: always</code>) and eager <code>todo</code> (<code>todo.eager: preferred</code>/<code>always</code>) hidden reminders now re-fire on the auto-continuation turn after a compaction (context-full / snapcompact / handoff / shake). Compaction summarizes away the first-message prelude, so the agent would otherwise silently lose the delegate-via-tasks / phased-todo guidance mid-work; the post-compaction todo nudge is reminder-only and never forces the <code>todo</code> tool onto the resumed turn.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed edit-tool block operations on Emacs Lisp files: <code>.el</code> and <code>.emacs</code> paths now resolve top-level forms for <code>SWAP.BLK</code>, <code>DEL.BLK</code>, and <code>INS.BLK.POST</code> instead of reporting an unsupported-language block-resolution error.</li>
<li>Fixed PDF reads leaking recoverable MuPDF WASM warnings into the terminal TUI by routing MuPDF output through the file logger before <code>markit-ai</code> loads it (<a href="https://github.com/can1357/oh-my-pi/issues/2766" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2766/hovercard">#2766</a>).</li>
<li>Fixed <code>/exit</code> and <code>/quit</code> waiting one shutdown timeout per hanging extension by running <code>session_shutdown</code> handlers within a shared shutdown window (<a href="https://github.com/can1357/oh-my-pi/issues/2736" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2736/hovercard">#2736</a>).</li>
<li>Fixed GitHub Copilot <code>.github/instructions/*.instructions.md</code> discovery by loading those files as rules that honor <code>applyTo</code> scoping, including always-apply <code>**</code> files and <code>rule://&lt;name&gt;</code> access for glob-scoped entries (<a href="https://github.com/can1357/oh-my-pi/issues/2731" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2731/hovercard">#2731</a>).</li>
<li>Fixed Windows bash-tool child processes defaulting interpreter pipe I/O to the ANSI codepage by adding UTF-8 encoding defaults when the inherited environment is unset (<a href="https://github.com/can1357/oh-my-pi/issues/2701" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2701/hovercard">#2701</a>).</li>
<li>Fixed <code>/advisor dump raw</code> so Opus 4.5 thinking content that already includes literal <code>&lt;thinking&gt;</code> tags is not rendered with nested thinking tags (<a href="https://github.com/can1357/oh-my-pi/issues/2700" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2700/hovercard">#2700</a>).</li>
<li>The <code>plugin-extensions-discovery</code> test suite no longer writes fixtures into — and <code>rm -rf</code>s the <code>node_modules</code> of — the developer's real <code>~/.omp/plugins</code>. Its <code>XDG_DATA_HOME</code> isolation was a no-op on Windows (XDG is gated to Linux/macOS) and was bypassed in XDG-migrated Linux/macOS environments, so a local run could delete installed plugins. The suite now isolates the whole config root via an <code>os.homedir()</code> mock plus cleared <code>XDG_*</code> vars, with a pre-write guard that fails if resolution escapes the temp home (<a href="https://github.com/can1357/oh-my-pi/issues/2721" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2721/hovercard">#2721</a>).</li>
<li>Installed plugins whose <code>extensions</code> manifest entry points at a directory of sub-extensions (the standard pi <code>extensions/&lt;name&gt;/index.ts</code> layout, e.g. <code>pi.extensions: ["./extensions"]</code>) are no longer rejected at install (<code>declared extension entry not found on disk</code>) or silently dropped at load. The plugin manifest resolver now resolves a directory the same way as the configured-directory (<code>-e</code>) extension loader: the directory's own <code>package.json</code> <code>omp</code>/<code>pi</code> <code>extensions</code> (authoritative — a missing declared entry is reported instead of falling back to a decoy <code>index</code>), then a direct <code>index.{ts,js,mjs,cjs}</code>, then a one-level scan of sub-extensions (<a href="https://github.com/can1357/oh-my-pi/issues/2713" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2713/hovercard">#2713</a>).</li>
<li>Fixed OpenRouter <code>@upstream</code> routing selectors whose upstream slug also appears in the model id, so <code>openrouter/...@deepseek:high</code> keeps <code>openRouterRouting.only</code> instead of being consumed by provider-scoped fuzzy matching (<a href="https://github.com/can1357/oh-my-pi/issues/2708" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2708/hovercard">#2708</a>).</li>
<li>Fixed <code>omp plugin list --json</code> omitting locally linked plugins that exist only in <code>omp-plugins.lock.json</code> and <code>node_modules</code> symlinks. (<a href="https://github.com/can1357/oh-my-pi/issues/2742" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2742/hovercard">#2742</a>)</li>
<li>Fixed task subagents to install their configured ordered model candidates as child-session retry fallback chains, so retryable provider failures can advance to the next subagent model instead of failing the worker (<a href="https://github.com/can1357/oh-my-pi/issues/2750" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2750/hovercard">#2750</a>).</li>
<li>Fixed empty reasonless aborted assistant turns to auto-retry without switching model fallback, so transient provider-side aborts after tool results do not end headless sessions (<a href="https://github.com/can1357/oh-my-pi/issues/2685" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2685/hovercard">#2685</a>).</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Fixed</h3>
<ul>
<li>Auto-repaired duplicated JSX/XML closing boundary lines at the end of single-line replacement expansions. (<a href="https://github.com/can1357/oh-my-pi/issues/2705" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2705/hovercard">#2705</a>)</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Added</h3>
<ul>
<li>Added Emacs Lisp (<code>.el</code>, <code>.emacs</code>, <code>emacs-lisp</code>/<code>elisp</code>) support to native tree-sitter language inference, enabling astGrep/astEdit, summarizeCode, and blockRangeAt on Emacs Lisp source.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed VS Code integrated terminal keypad digit CSI-u input being handled as navigation instead of text.</li>
<li>Fixed xterm-compatible terminals scrolling the native viewport to the bottom on prompt-editor keypresses by disabling <code>?1010</code>/<code>?1011</code> while the TUI owns the TTY and restoring the prior set modes on exit (<a href="https://github.com/can1357/oh-my-pi/issues/2732" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2732/hovercard">#2732</a>).</li>
<li>Fixed CMUX sessions being treated as direct terminals during resize/reset because they do not set <code>TMUX</code>/<code>STY</code>/<code>ZELLIJ</code> and may run with <code>TERM=dumb</code>; the renderer now treats CMUX workspace/surface env markers as multiplexer signals and preserves pane scrollback instead of emitting ED3 (<code>CSI 3 J</code>).</li>
<li>Fixed a self-sustaining resize-redraw storm in Warp: the non-multiplexer resize fast path borrows the alternate screen, and Warp re-reports a one-row-different size whenever the alt buffer is toggled, so each drag frame fed back a fresh resize event and the TUI flooded ED3 full repaints with stable geometry. Resize now repaints in place (no alt-screen borrow, no ED3 rewrap) on terminals that re-report size on alt-screen toggles, matching the multiplexer path. Overridable with <code>PI_TUI_RESIZE_IN_PLACE=1|0</code>.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): route prefixed Responses tool deltas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669710676" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2719" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2719/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2719">#2719</a></li>
<li>test(plugins): isolate discovery test from real ~/.omp on all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669729057" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2722" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2722/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2722">#2722</a></li>
<li>fix(coding-agent): load GitHub Copilot instruction rules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670507607" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2734" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2734/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2734">#2734</a></li>
<li>fix(tui): stop Warp resize feedback-loop redraw storm by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sorphwer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sorphwer">@sorphwer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671065904" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2741" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2741/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2741">#2741</a></li>
<li>fix(cli): speed up exit shutdown handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671164530" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2745" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2745/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2745">#2745</a></li>
<li>fix(cli): list linked local plugins by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671230064" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2746" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2746/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2746">#2746</a></li>
<li>fix(providers): handle Umans Kimi output caps and web search by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671571838" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2751" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2751/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2751">#2751</a></li>
<li>fix(agent): retry subagent model fallback chains by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671783707" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2753" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2753/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2753">#2753</a></li>
<li>fix(tui): detect CMUX as multiplexer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pathard1128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pathard1128">@pathard1128</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672246682" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2755" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2755/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2755">#2755</a></li>
<li>fix(coding-agent): route MuPDF warnings to logger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673746131" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2772" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2772/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2772">#2772</a></li>
<li>fix(ai): omit Google AUTO toolConfig by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4674509706" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2782" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2782/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2782">#2782</a></li>
<li>feat(ast): add Emacs Lisp tree-sitter support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryjm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryjm">@ryjm</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667318103" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2693" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2693/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2693">#2693</a></li>
<li>fix(ai): unwrap thinking envelopes in raw dumps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668789863" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2702" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2702/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2702">#2702</a></li>
<li>fix(tool): default Windows bash children to UTF-8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668993321" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2704" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2704/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2704">#2704</a></li>
<li>fix(hashline): drop duplicated JSX boundary echoes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669256053" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2709" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2709/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2709">#2709</a></li>
<li>fix(providers): preserve OpenRouter upstream routing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669299033" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2710" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2710/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2710">#2710</a></li>
<li>fix(openai-responses): quarantine invalid tool schemas instead of failing the whole turn (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665238895" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2652" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2652/hovercard" href="https://github.com/can1357/oh-my-pi/issues/2652">#2652</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669341536" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2711" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2711/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2711">#2711</a></li>
<li>fix(plugins): resolve directory extension manifest entries one level deep by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669526068" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2714" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2714/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2714">#2714</a></li>
<li>fix(tui): preserve scrollback while editing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670384480" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2733" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2733/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2733">#2733</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sorphwer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sorphwer">@sorphwer</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671065904" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2741" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2741/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2741">#2741</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pathard1128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pathard1128">@pathard1128</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672246682" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2755" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2755/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2755">#2755</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryjm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryjm">@ryjm</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667318103" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2693" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2693/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2693">#2693</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.1...v16.0.2"><tt>v16.0.1...v16.0.2</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK to Ban Under-16s From TikTok, Instagram, YouTube, and Other Social Media Platforms]]></title>
<description><![CDATA[UK Prime Minister Keir Starmer has announced that children under 16 will be banned from using a range of social media platforms, including Snapchat, TikTok, You Thank you for being a Ghacks reader. The post UK to Ban Under-16s From…
Read more →
The post UK to Ban Under-16s From TikTok, Instagram,...]]></description>
<link>https://tsecurity.de/de/3601655/it-security-nachrichten/uk-to-ban-under-16s-from-tiktok-instagram-youtube-and-other-social-media-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601655/it-security-nachrichten/uk-to-ban-under-16s-from-tiktok-instagram-youtube-and-other-social-media-platforms/</guid>
<pubDate>Tue, 16 Jun 2026 13:38:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UK Prime Minister Keir Starmer has announced that children under 16 will be banned from using a range of social media platforms, including Snapchat, TikTok, You Thank you for being a Ghacks reader. The post UK to Ban Under-16s From…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/uk-to-ban-under-16s-from-tiktok-instagram-youtube-and-other-social-media-platforms/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/uk-to-ban-under-16s-from-tiktok-instagram-youtube-and-other-social-media-platforms/">UK to Ban Under-16s From TikTok, Instagram, YouTube, and Other Social Media Platforms</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Florida lawsuit accuses TikTok of violating state’s child social media ban]]></title>
<description><![CDATA[State’s attorney general alleges TikTok exposed children to harmful sexual content and addictive featuresFlorida became the latest state to sue TikTok on Monday after the attorney general accused the company of violating a state law that limits social media access for teenagers.In a press confere...]]></description>
<link>https://tsecurity.de/de/3600945/it-nachrichten/florida-lawsuit-accuses-tiktok-of-violating-states-child-social-media-ban/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600945/it-nachrichten/florida-lawsuit-accuses-tiktok-of-violating-states-child-social-media-ban/</guid>
<pubDate>Tue, 16 Jun 2026 09:31:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>State’s attorney general alleges TikTok exposed children to harmful sexual content and addictive features</p><p>Florida became the latest state to sue TikTok on Monday after the attorney general<a href="https://www.myfloridalegal.com/newsrelease/ag-james-uthmeier-launches-lawsuit-against-tiktok-deceiving-parents-about-safety-its"> accused</a> the company of violating a state law that limits social media access for teenagers.</p><p>In a press conference, Republican James Uthmeier said TikTok exposed children to harmful sexual content and addictive features, such as unlimited scrolling and push notifications. “It’s designed to keep kids stuck on those screens for hours,” Uthemeier said at a press conference. “Our evidence suggests that so many kids are on TikTok for upwards of six, seven, eight or more hours a day. We are going to get our kids their lives back.”</p> <a href="https://www.theguardian.com/us-news/2026/jun/15/florida-sues-tiktok-teen-social-media-access-law">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Social Media Ban for Under-16s Could Take Effect by Spring 2027]]></title>
<description><![CDATA[The UK government has announced plans to introduce a UK social media ban for under-16s, preventing children from accessing major platforms such as TikTok, Instagram, Snapchat, Facebook, YouTube and X under a sweeping package of online safety reforms. The measures, expected to be brought before Pa...]]></description>
<link>https://tsecurity.de/de/3600798/it-security-nachrichten/uk-social-media-ban-for-under-16s-could-take-effect-by-spring-2027/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600798/it-security-nachrichten/uk-social-media-ban-for-under-16s-could-take-effect-by-spring-2027/</guid>
<pubDate>Tue, 16 Jun 2026 08:12:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="UK social media ban" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban.webp 1536w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban.webp 1536w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/UK-social-media-ban-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="UK Social Media Ban for Under-16s Could Take Effect by Spring 2027 1"></p>The UK government has announced plans to introduce a <a href="https://thecyberexpress.com/uk-government-social-media-ban-for-children/" target="_blank" rel="noopener">UK social media ban for under-16s</a>, preventing children from accessing major platforms such as <a href="https://thecyberexpress.com/tiktok-addictive-design-breaches/" target="_blank" rel="noopener">TikTok</a>, <a href="https://thecyberexpress.com/instagram-teen-accounts-for-young-users/" target="_blank" rel="noopener">Instagram</a>, Snapchat, Facebook, <a href="https://thecyberexpress.com/compromised-youtube-accounts-infostealer-malware/" target="_blank" rel="noopener">YouTube</a> and <a href="https://thecyberexpress.com/e120m-digital-services-act-penalty/" target="_blank" rel="noopener">X</a> under a sweeping package of online safety reforms. The measures, expected to be brought before Parliament later this year and enforced from Spring 2027, would make Britain one of the toughest countries in the world when it comes to regulating children's access to social media.

The proposal is part of a wider government effort to strengthen <a href="https://thecyberexpress.com/ofcom-online-child-safety-rules/" target="_blank" rel="noopener">online child safety </a>and address growing concerns about the impact of social media algorithms, harmful content and excessive screen time on young users.

Prime Minister Keir Starmer described the move as a "line in the sand," arguing that technology companies have failed to do enough to protect children online.

"Parents want to keep their kids safe and happy, but the online world has made that harder than ever," Starmer <a href="https://www.gov.uk/government/news/social-media-to-be-banned-for-under-16s-in-landmark-government-move-to-givekids-their-childhood-back" target="_blank" rel="nofollow noopener">said</a>. "That's why we're going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back."

<img class="aligncenter wp-image-112721 size-full" src="https://thecyberexpress.com/wp-content/uploads/UK-Social-Media-Ban-for-Under-16s-e1781589739408.webp" alt="UK Social Media Ban for Under-16s" width="600" height="400">
<h3><strong>UK Social Media Ban for Under-16s to Cover Major Platforms</strong></h3>
The proposed UK social media ban for under-16s will apply to user-to-user platforms that allow users to interact and share content through algorithm-driven feeds. Platforms expected to fall under the restrictions include TikTok, Instagram, <a href="https://thecyberexpress.com/dsa-child-protection-investigation/" target="_blank" rel="noopener">Snapchat</a>, <a href="https://thecyberexpress.com/web-stories/my-facebook-account-hacked-how-to-recover/" target="_blank" rel="noopener">Facebook</a>, YouTube and X.

Messaging services such as <a href="https://thecyberexpress.com/whatsapp-fixes-vulnerabilities-allowing-hackers-full-control-of-the-app/" target="_blank" rel="noopener">WhatsApp</a> and Signal are not expected to be included.

Alongside the ban, the government plans to introduce new restrictions on features considered particularly risky for young users. These include livestreaming functions and communication between children and strangers across a wider range of digital services, including some <a href="https://thecyberexpress.com/why-are-kids-becoming-hackers-cybercrime/" target="_blank" rel="noopener">gaming platforms</a>.

The government is also considering additional safeguards, including overnight access limits and measures designed to interrupt infinite scrolling for users under 18.
<h3><strong>AI Chatbots Also Under Scrutiny</strong></h3>
The reforms extend beyond social media platforms.

Under the proposed rules, AI-powered "romantic companion" <a href="https://thecyberexpress.com/ai-chatbots-recommending-illegal-casinos/" target="_blank" rel="noopener">chatbots</a> that simulate intimate or sexual relationships will be required to enforce a minimum age of 18. Similar intimate AI functions will also face restrictions for users under the age of 18.

Officials say the broader approach reflects how children increasingly encounter online <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28711">risks</a> across multiple digital services rather than solely through social media platforms.
<h3><strong>Global Momentum Builds Behind Social Media Age Restrictions</strong></h3>
Britain's announcement comes amid growing international support for tighter <a href="https://thecyberexpress.com/uk-online-age-checks-are-failing/" target="_blank" rel="noopener">social media age restrictions</a>.

Earlier this year,<a href="https://thecyberexpress.com/spain-ban-social-media-platforms-kids/" target="_blank" rel="noopener"> Spain announced</a> plans to prohibit social media access for children under 16. Prime Minister Pedro Sanchez described the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28712">internet</a> as a "digital Wild West" and said stronger protections were needed to shield young people from online harm.

France has also <a href="https://thecyberexpress.com/social-media-ban-for-children-france/" target="_blank" rel="noopener">moved in a similar direction</a>. In February, French lawmakers approved legislation banning children under 15 from accessing social media platforms. The measure is expected to take effect at the start of the next school year.

French President Emmanuel Macron strongly backed the proposal, stating that children's development should not be dictated by algorithms designed to maximize engagement.

The developments have fueled debate over whether age-based restrictions could become a standard approach to child online protection across Europe and beyond.
<h3><strong>Australia's Experience Highlights Enforcement Challenges</strong></h3>
While support for restrictions is growing, Australia's experience shows that enforcement remains a major challenge.

The <a href="https://thecyberexpress.com/australia-ban-on-social-media-ban-for-kids/" target="_blank" rel="noopener">Australia social media ban</a>, introduced under Prime Minister Anthony Albanese, requires platforms to block users under 16 or face fines of up to AU$32 million.

However, recent research suggests <a href="https://thecyberexpress.com/australia-social-media-ban-faces-question/" target="_blank" rel="noopener">many children continue to access restricted platforms</a> despite the rules.

A study conducted by the Molly Rose Foundation and YouthInsight found that more than 60% of children aged 12 to 15 who previously used social media still had access to at least one account. The survey of 1,050 young people showed that 53% of former TikTok users, 53% of YouTube users and 52% of Instagram users remained active after the restrictions were introduced.

Researchers also found evidence that some children created new accounts after the ban came into effect, raising questions about the effectiveness of current age verification systems.
<h3><strong>Age Assurance Measures Key to Enforcement</strong></h3>
To improve compliance, the UK government plans to introduce stronger age assurance measures and has tasked <a href="https://thecyberexpress.com/ofcom-online-child-safety-rules/" target="_blank" rel="noopener">Ofcom</a> with conducting a rapid review of age-verification technologies.

The regulator will also review its enforcement capabilities, while ministers have pledged additional funding to support implementation of both the proposed regulations and existing provisions under the <a href="https://thecyberexpress.com/online-safety-act-age-verification/" target="_blank" rel="noopener">Online Safety Act</a>.

The <a class="wpil_keyword_link" href="https://cyble.com/announcement/" target="_blank" rel="noopener" title="announcement" data-wpil-keyword-link="linked" data-wpil-monitor-id="28710">announcement</a> follows a national consultation that attracted more than 116,000 responses from parents, children and experts. According to government figures, nine in ten parents support a ban on social media access for children under 16.

If approved, the reforms will mark one of the most significant changes to Britain's digital safety framework and could further accelerate a global shift toward stricter regulation of children's online experiences.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Ordered to Pay Nearly $10 Million in Brazil Over Loot Boxes Accessible to Minors]]></title>
<description><![CDATA[A Brazilian court has ordered Apple and several other major gaming and tech companies to pay nearly $60 million in damages over loot boxes in games accessible to minors, with Apple alone ordered to pay about $9.8 million.



Times Brasil reported that the 1st Court for Children and Youth of Brazi...]]></description>
<link>https://tsecurity.de/de/3600579/ios-mac-os/apple-ordered-to-pay-nearly-10-million-in-brazil-over-loot-boxes-accessible-to-minors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600579/ios-mac-os/apple-ordered-to-pay-nearly-10-million-in-brazil-over-loot-boxes-accessible-to-minors/</guid>
<pubDate>Tue, 16 Jun 2026 05:39:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Brazilian court has ordered Apple and several other major gaming and tech companies to pay nearly $60 million in damages over loot boxes in games accessible to minors, with Apple alone ordered to pay about $9.8 million.



Times Brasil reported that the 1st Court for Children and Youth of Brazil’s Federal District ordered the companies to pay R$298 million, or about $58.7 million, in collective moral damages after finding that loot boxes expose children and teenagers to gambling-like mechanics.



According to the ruling, loot boxes can encourage compulsive behavior because players spend money without knowing exactly what reward they will receive. The court said Brazil already protects minors through its Constitution, Child and Adolescent Statute, and Consumer Protection Code, even without a later law focused only on loot boxes.



Apple, Microsoft, and Tencent were each ordered to pay R$50 million, which equals about $9.8 million. Google, Sony, Electronic Arts, Riot Games, Ubisoft, Valve, Konami, and Nintendo received smaller penalties ranging from about $7.8 million to $1 million.



The damages will go to the Federal District’s Fund for the Rights of Children and Adolescents. The court also said minors who bought, opened, or accessed loot boxes can seek individual compensation, but each claimant must prove their link to the practice and show the harm suffered.



The companies must also change how loot boxes work in Brazil. The court ordered refund systems for unauthorized purchases by minors, stronger age checks, clearer warnings about random rewards, and full disclosure of the odds for each item.]]></content:encoded>
</item>
<item>
<title><![CDATA[The FDA Just Cleared the First OTC Continuous Glucose Monitor for Children]]></title>
<description><![CDATA[Stelo can now be marketed for children 2 years of age and older who do not use insulin.]]></description>
<link>https://tsecurity.de/de/3600168/it-nachrichten/the-fda-just-cleared-the-first-otc-continuous-glucose-monitor-for-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600168/it-nachrichten/the-fda-just-cleared-the-first-otc-continuous-glucose-monitor-for-children/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stelo can now be marketed for children 2 years of age and older who do not use insulin.]]></content:encoded>
</item>
<item>
<title><![CDATA[The under-16 social media ban marks the end of the open UK internet]]></title>
<description><![CDATA[We've got the Online Safety Act in the UK, and now we're about to have new rules "to protect children online" - although it mostly affects social media.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3600145/linux-tipps/the-under-16-social-media-ban-marks-the-end-of-the-open-uk-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600145/linux-tipps/the-under-16-social-media-ban-marks-the-end-of-the-open-uk-internet/</guid>
<pubDate>Mon, 15 Jun 2026 22:15:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We've got the Online Safety Act in the UK, and now we're about to have new rules "to protect children online" - although it mostly affects social media.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/2030787706id29220gol.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/the-under-16-social-media-ban-marks-the-end-of-the-open-uk-internet/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Britain Unveils Sweeping Ban On Social Media For Under-16s]]></title>
<description><![CDATA[Longtime Slashdot reader schwit1 shares a report from NBC News: British Prime Minister Keir Starmer has announced a sweeping ban on social media use for those under 16, joining other countries around the world seeking to protect children online. "It's a big step for our country," Starmer said in ...]]></description>
<link>https://tsecurity.de/de/3599954/it-security-nachrichten/britain-unveils-sweeping-ban-on-social-media-for-under-16s/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599954/it-security-nachrichten/britain-unveils-sweeping-ban-on-social-media-for-under-16s/</guid>
<pubDate>Mon, 15 Jun 2026 20:14:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Longtime Slashdot reader schwit1 shares a report from NBC News: British Prime Minister Keir Starmer has announced a sweeping ban on social media use for those under 16, joining other countries around the world seeking to protect children online. "It's a big step for our country," Starmer said in a recorded video message released Monday. "Social media is making our children unhappy and unsafe, and as a parent, as much as a Prime Minister, I just can't let that go on anymore," he added.
 
The ban will include social platforms like Snapchat, TikTok, YouTube, Instagram, Facebook and X, while there is no intention for messaging services like WhatsApp and Signal to be included, the government said in a release. [...] Starmer's government called Monday's announcement a "landmark" move, saying the new measures would be brought to Parliament before Christmas, with protections expected to come into force next spring. Beyond the blanket social media ban, the restrictions will also include blocks on functions such as livestreaming and stranger communication with children for under-16s, it added. "It's not an easy thing to do. I'll be honest about that," Starmer said. "We haven't rushed into it. We've looked carefully at the evidence, and we'll have to adapt our approach as technology changes, learn from other countries which are taking similar steps."
 
He went on to say that it will face resistance from some of the most powerful companies in the world. "But we will take them on, and we will win, because the need for action could not be any clearer."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Britain+Unveils+Sweeping+Ban+On+Social+Media+For+Under-16s%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F15%2F1653226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F15%2F1653226%2Fbritain-unveils-sweeping-ban-on-social-media-for-under-16s%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/15/1653226/britain-unveils-sweeping-ban-on-social-media-for-under-16s?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[These are the countries moving to ban social media for children]]></title>
<description><![CDATA[Australia was the first country to issue a ban in late 2025, aiming to reduce the pressures and risks that young users may face on social media, including cyberbullying, social media addiction, and exposure to predators.]]></description>
<link>https://tsecurity.de/de/3599890/it-nachrichten/these-are-the-countries-moving-to-ban-social-media-for-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599890/it-nachrichten/these-are-the-countries-moving-to-ban-social-media-for-children/</guid>
<pubDate>Mon, 15 Jun 2026 19:50:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Australia was the first country to issue a ban in late 2025, aiming to reduce the pressures and risks that young users may face on social media, including cyberbullying, social media addiction, and exposure to predators.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nigel Farage says UK's teen social media ban is 'unlikely to work' — but will VPNs really help children get around the restrictions?]]></title>
<description><![CDATA[Building on the Australian model, the British Prime Minister has just announced a social media ban for under-16s. But some commentators believe these measures are bound to fail.]]></description>
<link>https://tsecurity.de/de/3599280/it-nachrichten/nigel-farage-says-uks-teen-social-media-ban-is-unlikely-to-work-but-will-vpns-really-help-children-get-around-the-restrictions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599280/it-nachrichten/nigel-farage-says-uks-teen-social-media-ban-is-unlikely-to-work-but-will-vpns-really-help-children-get-around-the-restrictions/</guid>
<pubDate>Mon, 15 Jun 2026 15:33:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Building on the Australian model, the British Prime Minister has just announced a social media ban for under-16s. But some commentators believe these measures are bound to fail.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK latest to ban social media for under-16s]]></title>
<description><![CDATA['Children will be given back their childhoods', the UK government said in a statement.
Read more: UK latest to ban social media for under-16s]]></description>
<link>https://tsecurity.de/de/3599036/it-nachrichten/uk-latest-to-ban-social-media-for-under-16s/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599036/it-nachrichten/uk-latest-to-ban-social-media-for-under-16s/</guid>
<pubDate>Mon, 15 Jun 2026 14:17:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>'Children will be given back their childhoods', the UK government said in a statement.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/uk-to-ban-social-media-for-under-16s-in-bid-to-give-kids-back-their-childhood">UK latest to ban social media for under-16s</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are Many College Students Losing the Ability to Read?]]></title>
<description><![CDATA[Futurism reports:

in a new essay for The Chronicle Higher Education, university-level literature and writing instructor Tyler Jagt recalls how not a single one of his students could get through an assigned 20-page article, something that he had read "without complaint" as an undergraduate a deca...]]></description>
<link>https://tsecurity.de/de/3598981/it-security-nachrichten/are-many-college-students-losing-the-ability-to-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598981/it-security-nachrichten/are-many-college-students-losing-the-ability-to-read/</guid>
<pubDate>Mon, 15 Jun 2026 13:53:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Futurism reports:

in a new essay for The Chronicle Higher Education, university-level literature and writing instructor Tyler Jagt recalls how not a single one of his students could get through an assigned 20-page article, something that he had read "without complaint" as an undergraduate a decade ago. 

One student confessed that the reason they didn't finish was that they kept losing track of what the paper was about. And there's no doubt that they're not alone. Jagt cites the 2024 National Assessment of Educational Progress reading assessment results released last year. It showed that 12th grade reading scores were at the lowest level since the assessment began in 1992. Nearly a third of those 12th graders scored below the assessment's "basic" level in reading, meaning they likely "cannot draw general conclusions based on concepts presented explicitly in a text." Younger children aren't better off: a recent report from the Annie E. Casey Foundation found that 70 percent of fourth graders, or around two million kids, can't read at a proficient level. 

"What I am seeing in my classroom is no longer a hunch," Jagt writes. "There is a measurable, generational collapse in sustained reading and writing, and the academy is responding to it with improvisation and exhaustion rather than the structural overhaul it requires...." Jagt cites an MIT study that found users who used ChatGPT during cognitive tasks like writing essays showed lower brain activity in areas associated with creativity compared to students who only used a traditional Google Search or didn't lookup information at all. An astonishing 83 percent of the AI users couldn't quote a single line from the essays they had just written, and capstoning the alarm, the brain activity in the AI users didn't return to normal when they were later asked to write without AI... 

On our pernicious pocket devices, Jagt touted a 2017 study that found that simply having a smartphone physically nearby — even if it's face down or turned off — reduced available cognitive capacity and impaired cognitive functioning. "So when a student tells me they 'kept losing track' of a 20-page article, I have to acknowledge that they may be describing a measurable neurological condition," Jagt wrote. "The neural pathways that support sustained attention are built by use, and they atrophy without it. Your body is a use-it-or-lose-it system, and the brain is no exception."
 

Sunday an "Ask Reddit" question went viral — drawing over 11,000 upvotes — for its question to any teachers reading Reddit. "Is the 'Gen Alpha can't read (write, or do math ext)' crisis real? If so how bad is it?" Some responses...

 
"The run of the mill non-honors kids have gotten really bad," posted one high school teacher. "Very low tolerance for working hard, very short attention span, very short stamina for active listening... It's the group that is the most worrying because a decade ago, I'd estimate that maybe 10-20% of kids at a school are like this, and now it's probably 40-50% of each graduating class... Then there's of course the bottom 10-20% kids (excluding the special ed/severe/moderate learning disability kids). This is what the viral videos are about and it's not an exaggeration. They can't read, write, or do very basic math like multiplication or division as a 17 year old."

"This is the first year the MAJORITY of my class cheated on their first essays...." posted one high school English teacher. "It was also the first year a kid yelled 'We don't care about your fucking books, Miss!' while I was in front of the class presenting books they might be interested in for their book reviews... Almost all of them cheated on the book review they had to write."


Thanks to long-time Slashdot reader schwit1 for sharing the article.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Are+Many+College+Students+Losing+the+Ability+to+Read%3F%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F14%2F2227254%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F14%2F2227254%2Fare-many-college-students-losing-the-ability-to-read%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/14/2227254/are-many-college-students-losing-the-ability-to-read?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Britain Announces Social Media Ban for Children]]></title>
<description><![CDATA[Prime Minister Keir Starmer said his government planned to bar children under 16 from social media, following policies in Australia and elsewhere.]]></description>
<link>https://tsecurity.de/de/3598936/it-nachrichten/britain-announces-social-media-ban-for-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598936/it-nachrichten/britain-announces-social-media-ban-for-children/</guid>
<pubDate>Mon, 15 Jun 2026 13:33:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Prime Minister Keir Starmer said his government planned to bar children under 16 from social media, following policies in Australia and elsewhere.]]></content:encoded>
</item>
<item>
<title><![CDATA[What to Know About Planned Social Media Bans Around the World]]></title>
<description><![CDATA[Britain said it would ban social media access for children under 16 starting in 2027, joining several other countries introducing similar measures.]]></description>
<link>https://tsecurity.de/de/3598928/it-nachrichten/what-to-know-about-planned-social-media-bans-around-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598928/it-nachrichten/what-to-know-about-planned-social-media-bans-around-the-world/</guid>
<pubDate>Mon, 15 Jun 2026 13:33:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Britain said it would ban social media access for children under 16 starting in 2027, joining several other countries introducing similar measures.]]></content:encoded>
</item>
<item>
<title><![CDATA[Social media firms hit back as Starmer announces ban for under-16s in UK]]></title>
<description><![CDATA[Meta, YouTube and Snapchat say ban, which would stop children using their platforms, will drive them to ‘less safe services’UK politics live – latest updatesHow will the ban work?UK parents: how do you feel about the ban?Britain’s plans to ban social media for under-16s will push teenagers toward...]]></description>
<link>https://tsecurity.de/de/3598881/it-nachrichten/social-media-firms-hit-back-as-starmer-announces-ban-for-under-16s-in-uk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598881/it-nachrichten/social-media-firms-hit-back-as-starmer-announces-ban-for-under-16s-in-uk/</guid>
<pubDate>Mon, 15 Jun 2026 13:17:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Meta, YouTube and Snapchat say ban, which would stop children using their platforms, will drive them to ‘less safe services’</p><ul><li><p><a href="https://www.theguardian.com/politics/live/2026/jun/15/keir-starmer-social-media-ban-under-16s-tik-tok-instagram-snapchat-twitter-x-meta-uk-politics-latest-news-updates">UK politics live – latest updates</a></p></li><li><p><a href="https://www.theguardian.com/uk-news/2026/jun/15/uk-under-16s-social-media-ban-how-will-it-work">How will the ban work?</a></p></li><li><p><a href="https://www.theguardian.com/world/2026/jun/10/parents-uk-how-feel-about-potential-under-16s-social-media-ban">UK parents: how do you feel about the ban?</a></p></li></ul><p>Britain’s plans to ban social media for under-16s will push teenagers towards more harmful platforms, the world’s biggest technology companies have warned as ministers push to enact the new restrictions by next spring.</p><p>Meta, YouTube and Snapchat have all criticised the ban, which was announced by Keir Starmer on Monday and would stop younger teenagers from using their services.</p> <a href="https://www.theguardian.com/media/2026/jun/15/social-media-ban-uk-under-16-starmer">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Ritter Sport Won’t Quit Supplying Russians at War]]></title>
<description><![CDATA[Ritter Sport announced it had two reasons for staying in Russia. Jobs and children. Jobs first. The CEO in 2024 said leaving would cost two hundred posts at Waldenbuch, and a family firm stands by its workers. Then in April 2026 the company ousted him and cut nearly two hundred posts, its first l...]]></description>
<link>https://tsecurity.de/de/3598643/it-security-nachrichten/why-ritter-sport-wont-quit-supplying-russians-at-war/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598643/it-security-nachrichten/why-ritter-sport-wont-quit-supplying-russians-at-war/</guid>
<pubDate>Mon, 15 Jun 2026 11:38:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ritter Sport announced it had two reasons for staying in Russia. Jobs and children. Jobs first. The CEO in 2024 said leaving would cost two hundred posts at Waldenbuch, and a family firm stands by its workers. Then in April 2026 the company ousted him and cut nearly two hundred posts, its first layoffs in … <a href="https://www.flyingpenguin.com/why-ritter-sport-wont-quit-supplying-russians-at-war/" class="more-link">Continue reading <span class="screen-reader-text">Why Ritter Sport Won’t Quit Supplying Russians at War</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The UK Places a Sweeping Ban on Social Media for Kids Under 16]]></title>
<description><![CDATA[The UK government is introducing a ban on social media for children and a minimum age for some chatbots in an attempt to shield young people from dangerous corners of the web.]]></description>
<link>https://tsecurity.de/de/3598602/it-nachrichten/the-uk-places-a-sweeping-ban-on-social-media-for-kids-under-16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598602/it-nachrichten/the-uk-places-a-sweeping-ban-on-social-media-for-kids-under-16/</guid>
<pubDate>Mon, 15 Jun 2026 11:16:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK government is introducing a ban on social media for children and a minimum age for some chatbots in an attempt to shield young people from dangerous corners of the web.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK will ban social media for children under 16]]></title>
<description><![CDATA[The UK is following Australia by banning young people under 16 from TikTok, Instagram and other social media platforms.]]></description>
<link>https://tsecurity.de/de/3598550/it-nachrichten/uk-will-ban-social-media-for-children-under-16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598550/it-nachrichten/uk-will-ban-social-media-for-children-under-16/</guid>
<pubDate>Mon, 15 Jun 2026 11:02:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK is following Australia by banning young people under 16 from TikTok, Instagram and other social media platforms.]]></content:encoded>
</item>
<item>
<title><![CDATA[Under-16 social media ban announced by UK government]]></title>
<description><![CDATA[The UK is the latest country to follow Australia in implementing a total social media ban for children under 16, Prime Minister Keir Starmer has announced. The ban, which could take effect from early next year, will be joined by wider measures that will also prevent children from talking to stran...]]></description>
<link>https://tsecurity.de/de/3598517/it-nachrichten/under-16-social-media-ban-announced-by-uk-government/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598517/it-nachrichten/under-16-social-media-ban-announced-by-uk-government/</guid>
<pubDate>Mon, 15 Jun 2026 10:47:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK is the latest country to follow Australia in implementing a total social media ban for children under 16, Prime Minister Keir Starmer has announced. The ban, which could take effect from early next year, will be joined by wider measures that will also prevent children from talking to strangers in online games, livestreaming, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Google found liable for bad AI Overview results. Let’s play Truth Or Consequences]]></title>
<description><![CDATA[Hush. children, what’s that sound? Has the flood gates’ key been found?]]></description>
<link>https://tsecurity.de/de/3598485/it-nachrichten/google-found-liable-for-bad-ai-overview-results-lets-play-truth-or-consequences/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598485/it-nachrichten/google-found-liable-for-bad-ai-overview-results-lets-play-truth-or-consequences/</guid>
<pubDate>Mon, 15 Jun 2026 10:31:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hush. children, what’s that sound? Has the flood gates’ key been found?]]></content:encoded>
</item>
<item>
<title><![CDATA[Starmer confirms social media ban for under-16s, saying this is a ‘big moment for our country’ – UK politics live]]></title>
<description><![CDATA[Prime minister defends going for full ban, saying social media is making children unhappy and unsafeStarmer acknowledges some teenagers will get round these restrictons. But that does not make the rules pointless, he says.Will it mean that no child ever looks at social media again? No.But look, t...]]></description>
<link>https://tsecurity.de/de/3598419/it-nachrichten/starmer-confirms-social-media-ban-for-under-16s-saying-this-is-a-big-moment-for-our-country-uk-politics-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598419/it-nachrichten/starmer-confirms-social-media-ban-for-under-16s-saying-this-is-a-big-moment-for-our-country-uk-politics-live/</guid>
<pubDate>Mon, 15 Jun 2026 09:47:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Prime minister defends going for full ban, saying social media is making children unhappy and unsafe</p><p><strong>Starmer</strong> acknowledges some teenagers will get round these restrictons. But that does not make the rules pointless, he says.</p><p>Will it mean that no child ever looks at social media again? No.</p><p>But look, this might shock you, but it doesn’t shock parents of teenagers; they get around other laws to.</p><p>Some technology companies want us to think that social media is unchangeable, part of an almost natural order.</p><p>But we have to resist that kind of learned helplessness. We have agency, we can change it, and we will.</p> <a href="https://www.theguardian.com/politics/live/2026/jun/15/keir-starmer-social-media-ban-under-16s-tik-tok-instagram-snapchat-twitter-x-meta-uk-politics-latest-news-updates">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Scientists See Little Evidence for Claims Smartphones Are Rewiring Kids' Brains]]></title>
<description><![CDATA[UK's Members of Parliament (MP) were "looking for proof that smartphones and social media are rotting children's brains," writes The Register — but they got "a less satisfying answer from neuroscientists on Wednesday: nobody can really prove it."

 Appearing before the Science, Innovation and Tec...]]></description>
<link>https://tsecurity.de/de/3597659/it-security-nachrichten/uk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597659/it-security-nachrichten/uk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains/</guid>
<pubDate>Sun, 14 Jun 2026 23:49:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UK's Members of Parliament (MP) were "looking for proof that smartphones and social media are rotting children's brains," writes The Register — but they got "a less satisfying answer from neuroscientists on Wednesday: nobody can really prove it."

 Appearing before the Science, Innovation and Technology Committee this week, three researchers spent much of the session explaining that concern and evidence are not quite the same thing. Asked what evidence exists on the impact of digital devices on infants and young children, Professor Denis Mareschal, director of the Centre for Brain and Cognitive Development at Birkbeck, replied: "There is very little, if any, causal research in the early years. Almost everything is correlational." 

MPs kept coming back to the question — and the experts kept coming back to the same answer. When questioned about social media's impact on adolescents, Professor Sarah-Jayne Blakemore of the University of Cambridge was equally cautious. "What evidence do we have of the impact of digital devices or social media on the adolescent brain?" she asked. "Almost nothing. There are a few small studies, but they haven't been replicated, and they're purely correlational...." 

MPs also wanted to know whether neuroscience could settle one of the liveliest arguments in the debate: how old a child should be before they're allowed onto social media. "What neuroscience can't do is pinpoint a precise age," Blakemore said. "The individual differences in brain development are vast...." If there was a takeaway from the hearing, it was that concern about digital childhood is running well ahead of the evidence needed to settle the argument.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=UK+Scientists+See+Little+Evidence+for+Claims+Smartphones+Are+Rewiring+Kids'+Brains%3A+https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F06%2F14%2F2132212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F06%2F14%2F2132212%2Fuk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://mobile.slashdot.org/story/26/06/14/2132212/uk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK may ban social media for children under 16]]></title>
<description><![CDATA[The U.K. seems to be following Australia's lead in banning a wide swath of social media for teens.]]></description>
<link>https://tsecurity.de/de/3597597/ai-nachrichten/uk-may-ban-social-media-for-children-under-16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597597/ai-nachrichten/uk-may-ban-social-media-for-children-under-16/</guid>
<pubDate>Sun, 14 Jun 2026 22:18:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The U.K. seems to be following Australia's lead in banning a wide swath of social media for teens.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laduora Duo 4-in-1 Red Light Therapy Scalp and Hair Care Device Review: Custom Goals]]></title>
<description><![CDATA[This handheld device combines red light therapy, microcurrents, sonic vibration, warmth, and a serum to support healthy hair growth.]]></description>
<link>https://tsecurity.de/de/3596860/it-nachrichten/laduora-duo-4-in-1-red-light-therapy-scalp-and-hair-care-device-review-custom-goals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596860/it-nachrichten/laduora-duo-4-in-1-red-light-therapy-scalp-and-hair-care-device-review-custom-goals/</guid>
<pubDate>Sun, 14 Jun 2026 11:47:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This handheld device combines red light therapy, microcurrents, sonic vibration, warmth, and a serum to support healthy hair growth.]]></content:encoded>
</item>
<item>
<title><![CDATA[Scientists pour cold water on claims phones are rewiring kids' brains]]></title>
<description><![CDATA[MPs told that while concerns over handsets and social media grows, evidence they're changing children's brains is limited]]></description>
<link>https://tsecurity.de/de/3596689/it-nachrichten/scientists-pour-cold-water-on-claims-phones-are-rewiring-kids-brains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596689/it-nachrichten/scientists-pour-cold-water-on-claims-phones-are-rewiring-kids-brains/</guid>
<pubDate>Sun, 14 Jun 2026 09:32:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MPs told that while concerns over handsets and social media grows, evidence they're changing children's brains is limited]]></content:encoded>
</item>
<item>
<title><![CDATA[Vim Classic 8.3 Launched as an AI-Free Vim Fork]]></title>
<description><![CDATA[This month saw the release of Vim Classic 8.3, the first stable version of a new long-term support fork of Vim maintained without generative AI tools. Linuxiac reports:

The release is based on Vim 8.2.0148 and includes selected bug fixes and patches backported from later upstream Vim releases. V...]]></description>
<link>https://tsecurity.de/de/3596120/it-security-nachrichten/vim-classic-83-launched-as-an-ai-free-vim-fork/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596120/it-security-nachrichten/vim-classic-83-launched-as-an-ai-free-vim-fork/</guid>
<pubDate>Sat, 13 Jun 2026 21:52:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This month saw the release of Vim Classic 8.3, the first stable version of a new long-term support fork of Vim maintained without generative AI tools. Linuxiac reports:

The release is based on Vim 8.2.0148 and includes selected bug fixes and patches backported from later upstream Vim releases. Vim Classic was first announced by [SourceHut's CEO/founder] Drew DeVault in March 2026 after he objected to LLM-assisted development in Vim and Neovim. In his announcement, DeVault said he no longer wanted to use software developed with LLM assistance and introduced Vim Classic as a fork for users who want to continue using Vim without that involvement... Vim Classic follows Vim's charityware model and continues to direct users toward Bram Moolenaar's long-running support for children in Uganda. The release is distributed as a signed source tarball from SourceHut, while future important announcements are expected through the project's mailing list. 

"Vim is important to me..." DeVault wrote in March. (DeVault even tattooed "hjkl" on his right arm.) "[A]lmost every word I have ever committed to posterity, through this blog, in my code, all of the docs I've written, emails I've sent, and more, almost all of it has passed through Vim." 

But DeVault wrote that he also cares about AI's impact on air pollution, fresh water supplies, global supply chains, and the working conditions of miners in African companies:
And at a moment when the climate demands immediate action to reduce our footprint on this planet, the AI boom is driving data centers to consume a full 1.5% of the world's total energy production in order to eliminate jobs and replace them with a robot that lies... All this to enrich the few, centralize power, reduce competition, and underwrite an enormous bubble that, once it bursts, will ruin the lives of millions of the world's poor and marginalized classes. 

I don't think it's cute that someone vibe coded "battleship" in VimScript. I think it's more important that we stop collectively pretending that we don't understand how awful all of this is. I don't want to use software which has slop in it. I do what I can to avoid it, and sadly even Vim now comes under scrutiny in that effort as both Vim and NeoVim are relying on LLMs to develop the software... To keep my conscience clear, and continue to enjoy the relationship I have with this amazing piece of software, I have forked Vim... 

Since forking from this base, I have backported a handful of patches, most of which address CVEs discovered after this release, but others which address minor bug fixes. I also penned a handful of original patches which bring the codebase from this time up to snuff for building it on newer toolchains... 
I invite you to use Vim Classic, if you feel the same way as me, and to maintain it with me, contributing the patches you need to support your own use cases.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Vim+Classic+8.3+Launched+as+an+AI-Free+Vim+Fork%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F13%2F0524209%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F13%2F0524209%2Fvim-classic-83-launched-as-an-ai-free-vim-fork%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/13/0524209/vim-classic-83-launched-as-an-ai-free-vim-fork?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 vs iOS 26: Every Change You’ll Notice Instantly]]></title>
<description><![CDATA[Apple has previewed iOS 27 at WWDC 2026, and the update builds directly on the big changes introduced with iOS 26. While iOS 26 introduced the Liquid Glass design, redesigned system apps, smarter Reminders, new CarPlay features, and an expansion of Apple Intelligence, iOS 27 focuses on making the...]]></description>
<link>https://tsecurity.de/de/3595681/ios-mac-os/ios-27-vs-ios-26-every-change-youll-notice-instantly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595681/ios-mac-os/ios-27-vs-ios-26-every-change-youll-notice-instantly/</guid>
<pubDate>Sat, 13 Jun 2026 15:23:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has previewed iOS 27 at WWDC 2026, and the update builds directly on the big changes introduced with iOS 26. While iOS 26 introduced the Liquid Glass design, redesigned system apps, smarter Reminders, new CarPlay features, and an expansion of Apple Intelligence, iOS 27 focuses on making the iPhone feel faster, clearer, and more intelligent in daily use. 



Apple says iOS 27 brings the next generation of Apple Intelligence, a new Siri AI experience, stronger parental controls, and performance improvements across its platforms.



iOS 27 vs iOS 26: Quick Comparison



AreaiOS 26iOS 27DesignIntroduced Liquid Glass across iPhoneRefines Liquid Glass for better clarity and usabilitySiriStandard Siri with Apple Intelligence supportNew Siri AI with screen awareness, personal context, and web answersPerformanceFaster and more responsive than older iOS versionsFurther speed and reliability improvementsPhotosNew layout, spatial scenes, better controlsAI-powered editing improvements, including Spatial ReframingSafariModernized browsing experienceSmarter tab handling and Apple Intelligence featuresParental controlsAge-based child setup and safety toolsMore powerful Screen Time and child safety controlsCompatibilitySupports iPhone 11 and newer models listed by AppleExpected to support many iOS 26 devices, with AI limits on older models



1. Siri AI Is the Biggest Instant Change







The most noticeable iOS 27 upgrade is Siri AI. Apple describes it as a new Siri experience that understands what is on your screen, uses personal context across apps, performs deeper app actions, and gives answers using web information when needed.



In iOS 26, Siri improved through Apple Intelligence, but iOS 27 turns Siri into a more active assistant. For example, Siri AI can understand a photo, search your messages or emails for relevant details, and help complete tasks across apps.



Apple also says Siri AI includes a dedicated Siri app where users can revisit past conversations, with iCloud syncing across Apple devices.



2. Liquid Glass Looks More Practical in iOS 27







iOS 26 introduced Liquid Glass, Apple’s new system-wide design language. It changed buttons, menus, app layouts, the Lock Screen, and several built-in apps.



With iOS 27, Apple is refining that design rather than replacing it. The update focuses on readability, responsiveness, and cleaner interaction across iPhone apps. This matters because many users noticed iOS 26 immediately because of its visual style, while iOS 27 feels more like a usability polish for that same design direction.



3. Photos Gets Smarter Editing Tools







Photos changed heavily in iOS 26 with a simpler two-tab layout, updated controls, and spatial scene support. Apple’s iOS 26 guide says Photos uses Library and Collections as the main tabs, while also letting users turn favorite photos into spatial scenes. 



In iOS 27, Apple Intelligence adds Spatial Reframing, which helps improve a photo’s composition after capture. This is one of the changes users will notice quickly because it affects a daily app rather than a hidden system setting.



4. Safari, Messages, and Mail Get More AI Help







iOS 27 spreads Apple Intelligence across apps that people use every day, including Safari, Messages, and Mail. Apple says the new intelligence features help with browsing across multiple tabs, communication, image editing, and creative tools like Image Playground.



Compared with iOS 26, this makes the system feel more connected because AI features appear inside normal workflows instead of staying limited to a few separate tools.



5. Parental Controls and Screen Time Improve







iOS 26 already improved Family features by helping parents move children to Child Accounts more easily and enabling age-appropriate protections. Apple also added safety improvements across Communication Limits, Communication Safety, and the App Store.







iOS 27 goes further with stronger parental controls and major Screen Time updates. Apple says parents get more control over what children can see, who they can contact, and when they can use apps.



6. Performance Is a Bigger Focus This Year







iOS 26 made supported iPhones faster and more responsive, according to Apple’s iPhone guide.



iOS 27 continues that direction with improvements aimed at speed, reliability, and day-to-day responsiveness. This is especially important for users on older supported iPhones, where small changes in app launches, scrolling, keyboard response, and photo loading become easy to notice.



iOS 27 vs iOS 26: Should You Upgrade?



Most users should upgrade to iOS 27 once the stable version is available because it improves the core iOS 26 experience with smarter Siri, better Apple Intelligence features, refined visuals, stronger child safety tools, and better performance.



However, early beta users should expect bugs because iOS 27 is still in testing. Also, some Siri AI and Apple Intelligence features depend on device model, language, and region. Apple confirms that Siri AI starts in beta later this year for supported devices set to English, while availability varies by region.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Why would you put a toxic product into the hands of a young child?’: director turned activist Beeban Kidron on why big tech needs its ‘tobacco moment’]]></title>
<description><![CDATA[In her work as an online safety campaigner, the baroness and Bridget Jones director has seen things she can never unsee – and she’s furious at the tech overlords doing nothing to stop the abuseThrough the open windows behind Beeban Kidron drifts the unmistakable sound of children playing. Her nor...]]></description>
<link>https://tsecurity.de/de/3595449/ai-nachrichten/why-would-you-put-a-toxic-product-into-the-hands-of-a-young-child-director-turned-activist-beeban-kidron-on-why-big-tech-needs-its-tobacco-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595449/ai-nachrichten/why-would-you-put-a-toxic-product-into-the-hands-of-a-young-child-director-turned-activist-beeban-kidron-on-why-big-tech-needs-its-tobacco-moment/</guid>
<pubDate>Sat, 13 Jun 2026 13:03:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In her work as an online safety campaigner, the baroness and Bridget Jones director has seen things she can never unsee – and she’s furious at the tech overlords doing nothing to stop the abuse</p><p>Through the open windows behind Beeban Kidron drifts the unmistakable sound of children playing. Her north ­London office is sandwiched between a school and a nursery, and the occasional playground shriek functions as an aural reminder of what we’re here to discuss: the safety and happiness of young people, growing up in an age of screens.</p><p>Though our conversation takes some dark turns, only once does the film director turned crossbench peer and online safety campaigner for children lose her composure. “I have seen a lot of things I’d rather not see,” she says, slowly. “But the worst thing was not the most extreme. It was watching a child’s face as she realised that the person who she thought was her friend wasn’t her friend; that the sex acts she’d been doing weren’t for her friend; and that there may have been other people in the room.</p> <a href="https://www.theguardian.com/film/2026/jun/13/beeban-kidron-interview-baroness-big-tech-online-child-abuse">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pioneering UK Nerve Lab harnesses AI to map effect of children’s screen time]]></title>
<description><![CDATA[Other projects include developing tools to help visually impaired people navigate video games  Parents are constantly being told to limit their children’s screen time. But when it comes to deciphering which films or TV shows are best suited to developing minds, the guidance remains largely one-si...]]></description>
<link>https://tsecurity.de/de/3595447/ai-nachrichten/pioneering-uk-nerve-lab-harnesses-ai-to-map-effect-of-childrens-screen-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595447/ai-nachrichten/pioneering-uk-nerve-lab-harnesses-ai-to-map-effect-of-childrens-screen-time/</guid>
<pubDate>Sat, 13 Jun 2026 13:03:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Other projects include developing tools to help visually impaired people navigate video games </p><p> </p><p>Parents are constantly being told to limit their children’s screen time. But when it comes to deciphering which films or TV shows are best suited to developing minds,<strong> </strong>the guidance remains largely one-size-fits-all. A relatively slow-paced programme such as Bluey offers a very different viewing experience to a fast-moving action series such as PAW Patrol, yet both are broadly considered suitable for young children.</p><p>This challenge is growing as the type of content children are exposed to evolves. “Today’s young viewers are increasingly engaging with short-form, fast-paced, highly captivating content, often created by splicing and rearranging existing episodic content into quickly digestible snippets or compilations,” said Prof Tim Smith, director of University of the Arts London’s Nerve Lab. “This evolution is not only changing how content is produced and distributed, but may also affect children’s attention, comprehension and emotional response.”</p> <a href="https://www.theguardian.com/society/2026/jun/13/nerve-lab-uk-ai-brain-scanning-tech-childrens-screen-time">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK parents support an under-16 social media ban – but what do their children think?]]></title>
<description><![CDATA[These young people recognise dangers of ‘addictive’ social media but have differing views on a total crackdownNine in 10 parents in the UK support an under-16 social media ban, but the feeling among the children it would affect is more mixed. Or at least it is for a group of 10 preteens and teena...]]></description>
<link>https://tsecurity.de/de/3595058/it-nachrichten/uk-parents-support-an-under-16-social-media-ban-but-what-do-their-children-think/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595058/it-nachrichten/uk-parents-support-an-under-16-social-media-ban-but-what-do-their-children-think/</guid>
<pubDate>Sat, 13 Jun 2026 08:16:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>These young people recognise dangers of ‘addictive’ social media but have differing views on a total crackdown</p><p>Nine in 10 parents in the UK support an under-16 social media ban, but the feeling among the children it would affect is more mixed. Or at least it is for a group of 10 preteens and teenagers who talked to the Guardian at a location in west London this week.</p><p>The 12- to 16-year-olds were well versed in the debate, with a set of views ranging from mandatory time limits to tougher controls and a full ban for under-16s. All those options have been <a href="https://www.theguardian.com/uk-news/2026/may/05/how-uk-may-restrict-social-media-under-16s-time-limits-curfews-ban">under consideration</a> in a government consultation on children’s online safety that is due to deliver an outcome next week, with an under-16 age limit expected for “high-risk” platforms, and restrictions on features such as livestreaming for others.</p> <a href="https://www.theguardian.com/uk-news/2026/jun/13/parents-teenagers-children-under-16-social-media-ban-tiktok-instagram">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[On Eve of SpaceX IPO, Protesters Roast Grok With Giant Elon Musk Inflatable]]></title>
<description><![CDATA[Activists say the high-profile IPO shifts attention and responsibility away from sexualized images of children that Grok generated, which spread on social media.]]></description>
<link>https://tsecurity.de/de/3594316/it-nachrichten/on-eve-of-spacex-ipo-protesters-roast-grok-with-giant-elon-musk-inflatable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594316/it-nachrichten/on-eve-of-spacex-ipo-protesters-roast-grok-with-giant-elon-musk-inflatable/</guid>
<pubDate>Fri, 12 Jun 2026 20:33:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Activists say the high-profile IPO shifts attention and responsibility away from sexualized images of children that Grok generated, which spread on social media.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,16ms -->